Invalidity dossier

US 8613083

Method for batching events for transmission by software agent

Current assignee: Micro Focus LLC

Added 9/26/2026, 2:32:50 AM

At a glanceNo PTAB challengesNo litigation on fileSoftware Technology & Computing Systems (T)

Active provider: DeepSeek · deepseek-v4-flash

Auto-generating section 1 of 2: Extensions…

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

I'll ground this on the authoritative patent text provided, and check for any litigation/docket activity.

I have the patent text but it is truncated before the claims section. Let me try to retrieve the actual claim language.

US 8,613,083 B1 — Summary

Note on date discrepancy first: your prompt says the current date is April 26, 2026, while my working date is September 28, 2026. This matters for one line of the status data below (the patent's adjusted expiration is 2026‑07‑24), so I flag it rather than silently pick one.

Note on scope of my sources: I worked from the full patent text supplied to me (authoritative), plus targeted web searches. Two caveats up front: (1) the text I was given is truncated in the middle of the Detailed Description and does not include the claims section, so my claim discussion is inference-based and flagged as such; (2) I found no litigation or Federal Circuit activity naming 8,613,083.

Bibliographic data

Field Value
Patent number US 8,613,083 B1
Title Method for batching events for transmission by software agent
Inventors Hugh S. Njemanze (Los Altos, CA); Hector Aguilar-Macias (Sunnyvale, CA); Christian Friedrich Beedgen (San Jose, CA)
Assignee as printed on the face Hewlett-Packard Development Company, L.P., Houston, TX
Application no. 11/740,203
Filed April 25, 2007
Issued December 17, 2013
Priority date December 2, 2002
Prior-art / priority basis Continuation of Ser. No. 10/308,585, filed Dec. 2, 2002, now US 7,219,239 (same title)
Status Expired – Fee Related; adjusted expiration 2026-07-24
Classifications H04L63/0209, H04L63/0218, H04L63/1408, H04L63/1416
Assignee chain (per Google Patents / USPTO assignment records) ArcSight, Inc. → ArcSight, LLC → Hewlett-Packard Development Co. L.P. → Hewlett Packard Enterprise Development LP → EntIT Software LLC → Micro Focus LLC (listed current assignee)

The record shows a series of reassignments (2010 ArcSight merger; 2012 certificate of conversion and assignment to HP; 2015 to HPE; 2017 to EntIT Software LLC; 2019 name change to Micro Focus LLC; JPMorgan security interests in 2017 released in 2023). Google Patents states its listed assignees may be inaccurate and that it performs no legal analysis — treat the above as recorded data, not a title opinion.

Abstract (verbatim)

"In one embodiment, the present invention provides for receiving security events from a network device by a distributed software agent of a network security system, determining a priority of each received security event, and storing the security events in a plurality of prioritized event buffers based on the determined priorities for a period of time determined by a timer. Upon expiration of the timer, a batch of security events for transport to a security event manager of the network security system can be created by including security events in the batch in order of priority until the batch is full."

Plain-language overview

The patent sits in the ArcSight-style multi-tier security architecture (agents → agent manager/manager → consoles). Its particular subject matter is the batching step performed inside a distributed software agent before event data is shipped to a central manager.

The problem: sending each security event to the manager individually carries per-message overhead (transport protocol and inter-system communication overhead). The disclosed solution has three moving parts:

  1. Priority determination — each received security event carries a normalized severity/priority field. The described scale has five values: very-high, high, medium, low, and unknown. A "priority scanner" sorts incoming events accordingly.
  2. Prioritized buffers + timer/counter gate — events are placed into a set of buffers, one per priority level (e.g., buffers 260A–E in FIG. 11). The buffers "can be delineated logically, and need not be physically separate in memory." A gate — implemented as a timer or a counter — controls when a batch is assembled. The spec gives a 20-minute timer example and a 100-event example for the non-prioritized variant; the aggregator description elsewhere uses a 5-minute timer or 30-event counter.
  3. Priority-ordered batch fill — when the gate fires, a fixed-size batch is created by drawing events "from high to low priority event buffers until the event batch is full." So high-priority events are preferentially included; low-priority events may be starved or deliberately excluded during peak periods.

Several optional refinements are described: the batch size and batching frequency are both configurable; low-priority buffers can be skipped during peak traffic; events that sit in a buffer longer than a threshold time or number of batches are moved to a higher-priority buffer to increase the likelihood of transmission, without changing the events' actual priority (only their "batching priority" changes); and higher-priority batches may be transmitted more frequently than lower-priority ones. Batches are sent as HTTP requests, though any wired or wireless transport is contemplated.

Context worth noting: the same agent pipeline also does normalization (parser + map + translator, including severity-scale translation), aggregation (collapsing like events with a count field and dropping time fields from the comparison), and DNS resolution, with batching downstream of aggregation. The batching component is modular and can be enabled/disabled by editing the agent's ASCII configuration file, and agents can be reconfigured remotely via the manager's heartbeat/response channel (FIGS. 14–15).

Independent claims — with an explicit uncertainty flag

I do not have the literal claim language. The text supplied to me ends within the Detailed Description (at the discussion of the four-level normalized severity scale) and does not reproduce the "What is claimed is" section. My searches did not surface the claim set either. So the following is an inference, not a quotation.

Based on the SUMMARY OF THE INVENTION, which in this family tracks the claimed subject matter almost verbatim, and on the abstract, the sole independent claim (almost certainly claim 1, most likely a method claim) very likely recites the combination of:

  • receiving security events from a network device by a distributed software agent of a network security system;
  • determining a priority of each received security event;
  • storing the events in a plurality of prioritized event buffers based on the determined priorities, for a period of time determined by a timer; and
  • upon expiration of the timer, creating a batch of security events for transport to a security event manager, by including security events in the batch in order of priority until the batch is full.

There may be additional independent claims in other statutory classes (a system/apparatus claim and/or a machine-readable-medium claim) typical of this patent family, but I cannot confirm their existence or wording. I also cannot state the total claim count. If you need exact claim text, pull it from the USPTO PatentCenter/Patent Public Search full-text for 8,613,083, or from the granted PDF at https://patentimages.storage.googleapis.com/55/62/b9/948b5b2589b6c8/US8613083.pdf. My claim-language summary should not be relied on for a validity or infringement analysis until verified against that source.

Litigation and CAFC docket check — negative result

Searches of the sort of databases and sources that surface patent litigation (RPX Insight, PACER Monitor aggregations, Stanford NPE litigation dataset, IAM coverage) for 8,613,083 specifically returned nothing. What those searches did surface was unrelated Micro Focus/EntIT litigation, which I am explicitly not attributing to this patent:

  • Wapp Tech Limited Partnership v. Micro Focus International PLC, 4:18-cv-00469 (E.D. Tex.) — three mobile-app-development patents; a jury verdict against Micro Focus (reported April 2025 at ~$172.5M) with Micro Focus stating an intent to appeal. The patents-in-suit identified in the coverage are not 8,613,083.
  • Errol v. Micro Focus (2018, D. Del.), involving US 6,484,166 and 6,484,167.
  • Trust & Verify Data Protection LLC v. Micro Focus LLC, 1:20-cv-00529 (W.D. Tex.), closed 2020.
  • Lone Star Document Management, LLC v. Micro Focus (US) Group, Inc., 1:26-cv-01306 (W.D. Tex.), filed 2026 — different patents.
  • An Ex parte appeal (Appeal 2019-003107) involving Micro Focus LLC as real party in interest — unrelated application, unrelated subject matter.

Separately, and more directly relevant to the '083 family: the parent patent, US 7,219,239, appears in the citation record of numerous later patents, and the Arcsight/HP family shows up in litigation generally, but I found no case or 2026 Federal Circuit docket in which US 8,613,083 is a patent-in-suit. I cannot rule out a recently filed or non-indexed action or a sealed proceeding — I simply have no evidence of one, and I would rather say that than infer one. Note also that the patent's adjusted expiration date of 2026-07-24 falls inside the current year, which would limit the practical window for new infringement claims on this particular patent even if term-extended event activity continued.

Sources

If you want, I can now pull the exact claim set from USPTO Patent Public Search (or the granted PDF) and give you a true element-by-element independent claim breakdown rather than the inferred one above.

Generated 9/28/2026, 4:24:25 PM

Cases on file (0)

Specific litigation cases in our database that name US patent 8613083. The free-form analysis below may also discuss cases beyond this list.

No cases on file mention this patent. Upload a CSV or add a case manually in Admin → Manage litigation cases.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

I'll search for litigation involving US patent 8613083.

Let me try more targeted searches on litigation databases.

Let me search more specific litigation databases.

Litigation Search: U.S. Patent No. 8,613,083

Bottom line: I was unable to identify any litigation (or any PTAB proceeding) involving U.S. Patent No. 8,613,083. Based on the searches I was able to run, there is no publicly indexed case — district court, Federal Circuit, ITC, or PTAB — in which this specific patent number appears as an asserted or challenged patent. I want to be explicit that this is a negative finding based on limited searching, not a certified "no litigation exists" conclusion (see caveats below).

What I searched

  • General web queries combining the exact number ("8613083" / "8,613,083") with "litigation," "lawsuit," "infringement," "complaint," "docket."
  • Queries pairing the number with the likely plaintiffs/owners on the face of the patent: ArcSight, Hewlett Packard / HPE, Entit Software, Micro Focus.
  • Queries aimed at the Unified Patents litigation/PTAB portal and at CourtListener/Justia-style docket aggregators.

Every hit returned was either an unrelated patent number (e.g., EP 0 260 633, US 5,191,573, US 8,243,593, US 8,549,310, US 8,613,083's neighbors in other families) or generic patent-litigation commentary. I found no case caption, case number, docket, or complaint naming the '083 patent.

Why this result is plausible for this particular patent

Several features of the '083 patent make a low litigation profile unsurprising, though none of them proves no suit exists:

  • It is a continuation, not the "lead" patent. Per the specification you provided, the '083 patent is "a continuation of U.S. patent application Ser. No. 10/308,585, filed on Dec. 2, 2002, now U.S. Pat. No. 7,219,239." If the ArcSight event-batching family were ever asserted, the earlier, broader '239 patent would more likely have been the asserted vehicle; the '083 would typically appear only as a companion patent.
  • It is expired. The Google Patents legal-status data supplied shows "Expired – Fee Related," with an adjusted expiration of 2026-07-24. A patent that has lapsed for failure to pay maintenance fees is rarely the subject of new infringement assertions (retroactive damages for the pre-expiration period remain theoretically possible, but this materially reduces the likelihood of active litigation today).
  • The patent has never been held by a classic non-practicing entity. The recorded chain is Hewlett Packard Development Co. LP → ARCSIGHT, INC. → ARCSIGHT, LLC → HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P. → HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP → ENTIT SOFTWARE LLC → MICRO FOCUS LLC (with JPMorgan security interests recorded and released). This is an operating-company/product-line chain, not an NPE chain, which is consistent with no known assertion campaign.

Ownership/party information (relevant if a case ever surfaces)

If litigation does exist that my search missed, the likely record plaintiff/patent owner would be drawn from this assignment chain (all per the Google Patents record for US8613083B1):

Date Assignee
2007-04-25 Hewlett Packard Development Co. LP (original assignee of record)
2010-12-23 ARCSIGHT, INC. (merger)
2012-11-16 ARCSIGHT, LLC (certificate of conversion)
2012-11-16 HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
2015-11-09 HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
2017-06-09 ENTIT SOFTWARE LLC
2019-08-08 MICRO FOCUS LLC (change of name)
2017-10-11 JPMORGAN CHASE BANK, N.A. (security interest — released 2023-02-02)

Inventor information (also from the record): Hugh S. Njemanze; Hector Aguilar-Macias; Christian Friedrich Beedgen. Application No. 11/740,203; filed 2007-04-25; priority date 2002-12-02.

Important caveats — please read before relying on this

  1. Tool limitation, not a clean bill. My search session was capped before I could directly query the Unified Patents litigation case list (https://portal.unifiedpatents.com/litigation/caselist), CourtListener/RE…CAP docket search, or PACER. Those are exactly the sources that would give a definitive answer. My negative finding reflects queries that did not return the number, not a confirmed empty docket.
  2. Aggregators are incomplete for this patent type. Web-indexed litigation aggregators skew toward NPE suits and well-publicized campaigns. A defensive counterclaim, a declaratory-judgment action, a case that settled at the pleading stage, or a sealed/early-stage filing could involve the '083 patent and simply never surface in open web search.
  3. PTAB is not "litigation" but is adjacent. I also did not find any IPR/PGR/CBM proceeding against the '083 patent. If your question includes administrative validity challenges, a direct PTAB/PatentCenter search should be run to confirm.
  4. Family vs. patent. I searched the exact number 8613083. I did not exhaustively search the related family members (e.g., U.S. Pat. No. 7,219,239, and any sibling continuations). A suit over the ArcSight batching family could name a sibling patent and not the '083.

Recommended next steps to reach a definitive answer

To close this out with confidence, I would (a) run the exact number through the Unified Patents litigation dashboard and its PTAB analytics; (b) run an exact-string docket search in CourtListener/RECAP and Docket Navigator/Lex Machina for 8,613,083; and (c) check the USPTO PatentCenter "Litigation" / assignment and reexamination tabs for the '083. If you can lift the tool limits, I'm happy to run those directly and report case-by-case details (plaintiff, defendant, jurisdiction, case number, filing date, status).

If the answer you need is binary: on the evidence available to me, no litigation is known involving U.S. Patent No. 8,613,083. I cannot rule it out, and I have flagged exactly where I could not verify.

Generated 9/28/2026, 4:24:21 PM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

I'll first attempt to surface any AIA trial proceedings via web search, then reconcile against the structured ODP block (which reports no proceedings).

Let me run a few more targeted searches to be thorough — including on the patent owner and the parent patent, and any IPR naming ArcSight SIEM patents.

One more diligence pass — checking the Unified Patents/PTAB portals and any proceeding naming the inventors or Micro Focus SIEM patents.

PTAB / AIA Trial Analysis — U.S. Patent No. 8,613,083 B1

"Method for batching events for transmission by software agent" — Njemanze, Aguilar-Macias, Beedgen — App. 11/740,203 — Priority 2002-12-02 — Issued 2013-12-17


Proceedings overview

Zero (0) AIA trial proceedings are on file against US 8,613,083. The structured USPTO Open Data Portal (ODP) block supplied for this analysis is authoritative and reports no AIA trial proceedings as of its most recent ingest; my independent web searches returned no IPR, PGR, or CBM petition naming this patent, so the structured "none" is corroborated rather than contradicted (breakdown: active 0 / claims invalidated 0 / claims sustained 0 / settled 0 / institution denied 0).

Bottom-line defensive posture for a defendant: the patent is neither hardened nor weakened by any PTAB record — it is simply untouched administratively. That cuts both ways. There is no FWD or institution decision you can point to as invalidating art, and no § 315(e) estoppel record to exploit. Conversely, the absence of any challenge is consistent with a patent that nobody has bothered to assert (see the Litigation and Assignment sections of this analysis: no case found, chain runs ArcSight → HP → HPE → Entit Software → Micro Focus LLC, and the patent is recorded as Expired – Fee Related, adjusted expiration 2026-07-24). The practical reading is: the strongest defensive facts here are expiry and non-assertion, not a PTAB outcome. If a demand letter cites this patent, your first response is not "the claims were canceled in IPR" (they were not) but "the patent lapsed and the term has run."

⚠️ Two corrections/conflicts with adjacent sections, flagged per the operating rules: (1) I identified no contradiction with the previously generated Litigation and Assignment sections — both also returned negative litigation findings, and the "no PTAB activity" result is consistent with them. (2) A prior section noted that an Ex parte appeal (Appeal 2019-003107) lists Micro Focus LLC as real party in interest. I confirmed the source of that: it is an ex parte appeal in application 15/095,230 (service-design/deployment subject matter, Technology Center 2100), and it is not an AIA trial and not this patent. Do not let that docket number migrate into a PTAB proceeding list for the '083 patent.


Proceedings

None on file

No proceeding numbers exist to report. Per the constraints — "Do not invent proceeding numbers" — I am not supplying placeholder or approximated numbers. If a proceeding surfaces later, treat any identifier that does not come from the ODP block or a PTAB E2E docket as suspect until verified.


Search diligence and the noise problem (why "no results" is a real finding here, not a search failure)

The number 8,613,083 is collision-prone in open-web search, and every "hit" I obtained was a different patent. Recording this so the negative finding is auditable:

Hit What it actually is Relevance to '083
RainDance Techs., Inc. v. 10X Genomics, Inc., No. 1:15-cv-00152-RGA (D. Del., Markman 2017-01-26) Claim construction for US 8,889,083 (Ismagilov microfluidics patents) None — different patent, different field
CourtListener RECAP, D. Del. 56643 Expert report on US 8,889,083 (Bio-Rad/10X droplet microfluidics) None
IPR2021-00100 (Docket Alarm) Petition involving US 8,304,193 and other microfluidics patents None
EP 0 260 633 A1 Waveguide filter None

I did not find any petition, institution decision, FWD, or termination naming US 8,613,083, and I did not find any AIA proceeding naming its parent, US 7,219,239, or the same-inventor/same-assignee ArcSight siblings (US 7,376,969; US 7,333,999; US 7,260,844). I also found no Unified Patents challenge to this patent.

Two adjacent facts are worth knowing, and both bolster the "no PTAB activity" conclusion rather than undermining it:

  1. The ArcSight system — not the patent — is being used as prior art, and in district court, not at the PTAB. In Webroot Inc. v. AO Kaspersky Lab, No. 6:22-cv-00243 (W.D. Tex.), CrowdStrike sought documents and source code for the ArcSight prior-art system in connection with invalidity contentions against the '045 and '224 patents; the court's 2023-09-20 order granted the document request and denied the source-code request without prejudice. (Order) This shows the ArcSight SIEM lineage functions as invalidating art against others, from inside the Open Text/Micro Focus portfolio — not as a target of PTAB challenges.
  2. The '083 family is cited in foreign prosecution. EP 2204010 B1 states: "Document US 7219239 discloses a system with which security events are stored in event buffers. Upon expiration of a timer, an event is prioritized and sent out. In effect, security events are batched." (EP 2204010 B1) The parent is used as a § 102-type reference abroad; it has never been tested in an AIA trial at home.

Strategic summary

Claim status — CANCELED: none. SUSTAINED: none. UNTESTED: all. Because no petition was ever filed, every claim of US 8,613,083 remains as issued by the USPTO on 2013-12-17 — no claim has been canceled, confirmed, or construed by the Board. I cannot give you a claim-by-claim table, and I explicitly decline to: (a) I do not have the issued claim text (the authoritative copy supplied to me is truncated before the "What is claimed is" section — the same gap flagged in the Prior-Art section), and (b) even with claim text, no FWD exists to map outcomes onto. Fabricating a "claims 1–5 canceled" narrative here would be exactly the failure mode the constraints warn against.

Estoppel landscape — no PTAB-derived bars apply, which is a mixed bag. Because there were no AIA trials, 35 U.S.C. § 315(e)(2) estoppel does not attach to anyone. There is no petitioner, and therefore no petitioner-privy class barred from re-raising grounds in a district court or ITC proceeding. Operationally:

  • All prior-art grounds remain fully available to you in litigation or in a de novo IPR petition. Nothing has been "reasonably could have raised"-ed away.
  • But the IPR door may be effectively closed by time and status, not by estoppel. Two independent gates: (i) the patent is recorded Expired – Fee Related with an adjusted expiration of 2026-07-24, so the remaining damages window is narrow or nil; and (ii) the one-year § 315(b) bar runs from service of a complaint, so if you have been served, the clock is already ticking. An expired patent can still be the subject of an IPR (the Board will institute where a petitioner shows a reasonable likelihood as to at least one claim, though mootness/discretion arguments get raised), but the cost-benefit rarely justifies it.
  • The most promising art noted in the prior-art section never got a PTAB test. If you do litigate rather than petition, the long-pendency intrusion-detection references with realistic § 102(e) footing against the 2002-12-02 priority date — Schneier (US 7,159,237 / US 2007/0162973) and Porras (US 6,704,874, priority 2000-10-16) — are the ones to chart first. That is a litigation strategy, not a PTAB one, given the expiry posture.

Pattern signals. (1) No repeat-petitioner pattern — there is no petitioner at all, so no serial-IPR or follow-on-petition dynamics to analyze. (2) No aggressive PTAB-appeal posture by the patent owner — no FWD means no appeal, and the only Micro Focus-linked Board matter I found is the unrelated ex parte appeal 2019-003107 (app. 15/095,230). (3) No defensive aggregator in the chain. The Assignment section is right that the chain terminates at a change of name to Micro Focus LLC (2019-08-08) after the JPMorgan liens were released on 2023-02-02; there is no RPX, Unified Patents, AST, LOT, or OIN link. The corollary matters for this task: Unified Patents' typical role — filing a prophylactic IPR to knock out a troll's patent — never happened, because there was no assertion campaign to trigger one. The patent is being held, not fought over.


Recommended next steps

If you are a defendant and a demand letter or complaint cites US 8,613,083:

  1. Lead with expiry and non-assertion, not with PTAB invalidation. There is no FWD to link to — linking to one would be a factual error. Confirm the maintenance-fee lapse and the adjusted expiration date on USPTO PatentCenter for 11/740,203 and make that showing first.
  2. If you nonetheless want an administrative challenge, verify before you file. Run the exact string through PTAB E2E / PTAB Decisions (https://ptab.uspto.gov) and the USPTO Patent Public Search full-text, and confirm there is no recently-filed petition the ODP ingest may have missed. Then calendar the § 315(b) one-year bar from the date you were served.
  3. Secure the actual claim text before building anything. Pull the granted claims from the US8613083 PDF or PatentCenter. Both this section and the Prior-Art section are operating without claim language — that gap should be closed before any § 102/§ 103 chart, any invalidity contention, or any IPR petition is drafted.
  4. For a litigation-track invalidity theory, start with Schneier (US 7,159,237) and Porras (US 6,704,874), and cross-check the Webroot v. AO Kaspersky ArcSight prior-art production record (No. 6:22-cv-00243, W.D. Tex.) — the ArcSight system source and documentation produced there is the closest thing to a real-world corpus of prior art in this technology space.

If you are the patent owner (Micro Focus LLC / Open Text lineage): you face no surviving IPR challenge and no § 315(e) estoppel, but the adjusted expiration of 2026-07-24 and the "Expired – Fee Related" status are the controlling facts for any enforcement decision.

Controlling caveat: my negative finding rests on (a) the structured ODP block supplied in this prompt (authoritative) and (b) web searches, several of which I had to truncate after hitting a tool limit. I could not directly query the Unified Patents litigation/PTAB portal, PTAB E2E end-to-end, or a Docket Navigator/Lex Machina PTAB docket within budget. A sealed, very recently filed, or not-yet-ingested petition is the one thing this analysis cannot exclude. On the evidence available, no AIA trial proceeding exists against US 8,613,083 — I state the negative plainly and mark exactly where verification is still owed.

Generated 9/28/2026, 4:31:26 PM

Ownership chain (10)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. ? · recorded 2010-12-23 · Merger

    Priam Acquisition CorporationArcSight, Inc.

    acquisition

  2. ? · recorded 2012-11-16 · Certificate of Conversion

    ArcSight, Inc.ArcSight, Inc.

    internal reorg

  3. ? · recorded 2012-11-16 · Assignment

    ArcSight, Inc.Hewlett-Packard Development Company, L.P.

    internal reorg

  4. ? · recorded 2015-11-09 · Assignment

    Hewlett-Packard Development Company, L.P.Hewlett Packard Enterprise Development LP

    internal reorg

  5. 2017-04-05 · recorded 2017-10-11 · reel 042746/0130 · Assignment

    Hewlett Packard Enterprise Development LPEntIT Software LLC

    internal reorg

  6. ? · recorded 2017-10-11 · reel 044183/0577 · Security Agreement

    EntIT Software LLC and ARCSIGHT, LLCJPMorgan Chase Bank, N.A.

    securitization

  7. ? · recorded 2017-10-11 · reel 044183/0718 · Security Agreement

    ENTIT SOFTWARE LLC, ARCSIGHT, LLC, ATTACHMATE CORPORATION, BORLAND SOFTWARE CORPORATION, MICRO FOCUS (US), INC., MICRO FOCUS SOFTWARE, INC., NETIQ CORPORATION, SERENA SOFTWARE, INC.JPMorgan Chase Bank, N.A.

    securitization

  8. ? · recorded 2019-08-08 · Change of Name

    EntIT Software LLCMicro Focus LLC

    change of name only

  9. ? · recorded 2023-02-02 · reel 044183/0718 · Release

    JPMorgan Chase Bank, N.A.Micro Focus LLC (f/k/a EntIT Software LLC) and affiliates (ARCSIGHT, LLC, ATTACHMATE CORPORATION, BORLAND SOFTWARE CORPORATION, MICRO FOCUS (US), INC., MICRO FOCUS SOFTWARE, INC., NETIQ CORPORATION, SERENA SOFTWARE, INC.)

    securitization

  10. ? · recorded 2023-02-02 · reel 044183/0577 · Release

    JPMorgan Chase Bank, N.A.Micro Focus LLC (f/k/a EntIT Software LLC) and affiliates (ARCSIGHT, LLC, ATTACHMATE CORPORATION, BORLAND SOFTWARE CORPORATION, MICRO FOCUS (US), INC., MICRO FOCUS SOFTWARE, INC., NETIQ CORPORATION, SERENA SOFTWARE, INC.)

    securitization

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

I'll reconstruct the assignment record. Let me pull the recorded assignment data, reels/frames, and correspondents.

Let me hunt for the specific reel/frame numbers and recording correspondents.

Good — I have one reel/frame. Let me chase the others and the recording correspondents.

Assignment & Ownership Reconstruction — US 8,613,083 B1

Scope/provenance note. The authoritative patent text supplied to me reproduces the Google Patents legal-events table (dated, typed conveyances) and — importantly — the two security-interest release reel/frame identifiers. I supplemented with targeted web searches. I could not open the USPTO Assignment Center record itself (the tool limit was reached before I could enumerate reel/frame + correspondent for each link). I therefore report three reel/frames that are evidenced below and mark every unanswered field as not retrieved rather than guessing. Recording correspondents — the specific thing you asked me to capture most carefully — were not retrievable for this patent in this session; see the caveat in §3.


Inventors

Inventor City of record Employer at filing (2007-04-25) Basis
Hugh S. Njemanze Los Altos, CA ArcSight, Inc. — founder and CTO Same-assignee/same-family filings (e.g., US 7,376,969; US 7,333,999, "Expression editor") and the ArcSight-origin filing of the 2002 parent Ser. No. 10/308,585
Hector Aguilar-Macias Sunnyvale, CA ArcSight, Inc. — engineer/developer Co-inventor on US 2007/0260931 "Merging multi-line log entries," same assignee (ArcSight)
Christian Friedrich Beedgen San Jose, CA ArcSight, Inc. — engineer/architect ArcSight-origin filings; later co-founded Sumo Logic (2010, i.e., outside the 12-month window)

Pattern calls:

  • Unusual-departure pattern: NOT PRESENT / not determinable. I found no evidence of all inventors leaving the original assignee within 12 months of the 2007-04-25 filing. The three inventors were ArcSight personnel, and ArcSight was an operating security-software company at filing — the classic profile of a company invention, not an inventor-held patent being shopped. I did not verify employment end dates from primary records, so treat "not present" as an absence of evidence rather than a confirmed negative.
  • No inventor-assignment anomalies. There is no recorded inventor-to-inventor or inventor-to-third-party conveyance. The only expected first link is inventors → ArcSight, Inc. (see timeline; reel/frame not retrieved).

Original assignee

Two different things are commonly called "the original assignee," and they diverge here:

  • Applicant/owner at filing (2007-04-25): ArcSight, Inc. The '083 application is a continuation of Ser. No. 10/308,585 (filed 2002-12-02, now US 7,219,239), an ArcSight-origin case. The patent issued after the 2012 assignment to HP, which is why databases conflate the two.
  • Assignee printed on the issued patent (2013-12-17): Hewlett-Packard Development Company, L.P., Houston, TX — consistent with your earlier "Patent summary" section.

Product line / business: ArcSight's core product was the ArcSight SIEM stack — ArcSight ESM (Enterprise Security Manager), the ArcSight Logger, and the distributed ArcSight SmartConnectors/Agents that collect, normalize, aggregate, batch, and forward security events to the ArcSight Manager. The disclosed subject matter (a distributed agent with a batch component that priority-buffers events and ships them on a timer to a security event manager) maps onto the SmartConnector/Agent → Manager data path. So yes: the original assignee's family shipped products embodying the claimed architecture, and that product line is still sold, which matters for the verdict.

Current status:

  • ArcSight, Inc. → acquired by HP (2010), converted to ArcSight, LLC (2012), assigned to HP (2012) — acquired/dissolved as an independent entity.
  • The brand/product line persists: HPE (2015) → EntIT Software LLC (2017) → renamed Micro Focus LLC (2019) → Micro Focus was acquired by OpenText (completed 2023-01-31). The ArcSight product line is now sold under OpenText Cybersecurity. Assignee of record remains Micro Focus LLC; the ultimate parent is OpenText Corporation (NASDAQ: OTEX).
  • No bankruptcy. Micro Focus experienced a severe share decline (2018–2019) and restructuring, but there was no Chapter 7/11 estate and no patent fire-sale of this patent. The 2023 change of control was an acquisition, not an insolvency sale.

Assignment timeline

There are recorded assignments (contrary to the "no records" case). Chronological reconstruction:

  • Executed: not retrieved / recorded 2010-12-23 — Reel not retrieved

    • Conveyance: Merger
    • Assignor: Priam Acquisition Corporation
    • Assignee: ArcSight, Inc.
    • Correspondent: not retrieved
    • Context: Internal acquisition mechanics — HP's merger subsidiary (Priam) merged into ArcSight, Inc., leaving ArcSight, Inc. as the surviving, HP-owned entity. (This is the HP acquisition of ArcSight; ArcSight remained the record owner post-merger.)
  • Executed: not retrieved / recorded 2012-11-16 — Reel not retrieved

    • Conveyance: Certificate of Conversion
    • Assignor: ArcSight, Inc.
    • Assignee: ArcSight, LLC
    • Correspondent: not retrieved
    • Context: Internal corporate reorg — Delaware corporation converted to a Delaware LLC within the HP family.
  • Executed: not retrieved / recorded 2012-11-16 — Reel not retrieved

    • Conveyance: Assignment of Assignor's Interest
    • Assignor: ArcSight, LLC
    • Assignee: Hewlett-Packard Development Company, L.P.
    • Correspondent: not retrieved
    • Context: Internal reorg — consolidation of the ArcSight assets into HP's development/IP-holding entity (this is the assignment that puts HP on the issued face).
  • Executed: not retrieved / recorded 2015-11-09 — Reel not retrieved

    • Conveyance: Assignment of Assignor's Interest
    • Assignor: Hewlett-Packard Development Company, L.P.
    • Assignee: Hewlett Packard Enterprise Development LP
    • Correspondent: not retrieved
    • Context: Internal reorg — the 2015 HP split; the enterprise-side assets moved to HPE Development LP.
  • Executed 2017-04-05 (per INPADOC/Espacenet legal status) / recorded 2017-10-11 (INPADOC update; Google lists the event at 2017-06-09 — see discrepancy note) — Reel 042746/0130 ✅ evidenced

    • Conveyance: Assignment of Assignor's Interest ("NEW OWNER … ASSIGNMENT OF ASSIGNORS INTEREST")
    • Assignor: Hewlett Packard Enterprise Development LP
    • Assignee: EntIT Software LLC (California)
    • Correspondent: not retrieved
    • Context: Internal reorg / carve-out — HPE's software business was reorganized into EntIT Software LLC in advance of the Micro Focus combination. This is the only link in the chain whose reel/frame I could independently confirm (042746/0130, per Espacenet INPADOC for the EntIT/HPE assignment).
  • Executed: not retrieved / recorded 2017-10-11 — Reels 044183/0577 and 044183/0718 ✅ evidenced (from the patent's own legal-events data)

    • Conveyance: Security Agreement (security interest)
    • Assignor (debtor/pledgor): EntIT Software LLC and ARCSIGHT, LLC (first recording); and a broader group — ENTIT SOFTWARE LLC, ARCSIGHT, LLC, ATTACHMATE CORPORATION, BORLAND SOFTWARE CORPORATION, MICRO FOCUS (US), INC., MICRO FOCUS SOFTWARE, INC., NETIQ CORPORATION, SERENA SOFTWARE, INC. (second recording)
    • Assignee (secured party): JPMORGAN CHASE BANK, N.A.
    • Correspondent: not retrieved
    • Context: Securitization — a blanket IP security interest granted as collateral for the Micro Focus/EntIT group's financing, not a transfer of ownership. Two reel/frames were recorded.
  • Executed: not retrieved / recorded 2019-08-08 (Google Patents; state registrations show the name change formally effective 2020-11-30 / 2020-12-02 — see discrepancy note) — Reel not retrieved

    • Conveyance: Change of Name
    • Assignor: EntIT Software LLC
    • Assignee: Micro Focus LLC
    • Correspondent: not retrieved
    • Context: Change of name only — no change in beneficial ownership.
  • Executed: not retrieved / recorded 2023-02-02 — Reels 044183/0718 and 044183/0577 ✅ evidenced (releases of the two 2017 security interests)

    • Conveyance: Release of Security Interest
    • Assignor (secured party releasing): JPMORGAN CHASE BANK, N.A.
    • Assignee (released debtors): Micro Focus LLC (f/k/a EntIT Software LLC) and affiliates (ARCSIGHT, LLC, ATTACHMATE CORPORATION, BORLAND SOFTWARE CORPORATION, MICRO FOCUS (US), INC., MICRO FOCUS SOFTWARE, INC., NETIQ CORPORATION, SERENA SOFTWARE, INC.)
    • Correspondent: not retrieved
    • Context: Collateral release — the 2017 JPMorgan security interests were discharged, consistent with the OpenText acquisition of Micro Focus (completed 2023-01-31) refinancing/releasing the legacy debt package.

The missing first link. The standard inventors → ArcSight, Inc. assignment (executed ~2007) is almost certainly recorded, but I could not retrieve its reel/frame. Do not treat the timeline as complete without it.


Timeline diagram

timeline
    title Ownership of US 8613083
    2007 : Filed by ArcSight Inc
    2010 : HP merger sub merges into ArcSight Inc
    2012 : ArcSight Inc converts to ArcSight LLC
         : Assigned to HP Development Co LP
    2013 : Patent issued
    2015 : Assigned to HPE Development LP
    2017 : Assigned to EntIT Software LLC
         : JPMorgan security interest recorded
    2019 : Name change to Micro Focus LLC
    2023 : Security interest released
         : Micro Focus acquired by OpenText

NPE / troll-pattern signals

  1. Shell-entity transfer — NOT PRESENT. Every recorded transferee is an operating company or a corporate-reorg vehicle inside a large software enterprise: ArcSight, Inc. → ArcSight, LLC (certificate of conversion) → Hewlett-Packard Development Co. L.P. → HPE Development LP → EntIT Software LLC → Micro Focus LLC. No "IP / Patents / Licensing / Holdings / Ventures" suffix entity appears anywhere in the chain, and EntIT Software LLC was a large multi-thousand-employee software operating company (Attachmate, NetIQ, Borland, Serena, ArcSight, Micro Focus product lines were all inside it), not a single-purpose licensing shell. Contrast with the shell-entity tell in the record I actually retrieved for other cases (e.g., "ZOMM, LLC," Reel 033066/0453 — an operating LLC, but a single-product one). Nothing comparable here.

  2. Known asserter in the chain — NOT PRESENT. I checked the chain against the NPE list you supplied (Acacia, Marathon, Intellectual Ventures, IPNav, Wi-LAN, Mosaid/Conversant, Vringo, Pendrell, Innovatio, MPHJ, Lumen View, Round Rock, Document Generation Corp, Spangenberg entities). None appears. Note the Intellectual Ventures hit returned by search for the related family (US RE47,443, Intellectual Ventures I LLC) is a citation relationship, not an ownership link to '083 — do not confuse the two.

  3. Repeat correspondent across the chain — UNCLEAR / NOT RETRIEVED. This is the signal I was specifically asked to capture and could not. I have no recorded correspondent name, firm, or address for any of the '083 reel/frame entries. I will not supply a name from inference. To close this: query https://assignmentcenter.uspto.gov/ (or https://assignment.uspto.gov/patent/index.html) by patent number 8,613,083, open each reel/frame, and read the "correspondent" field. The one data point I encountered in another matter — HP's Intellectual Property Administration, 3404 E. Harmony Road, Mail Stop 35, Fort Collins, CO — came from an unrelated Apple/Uniloc filing history and must not be attributed to this patent.

  4. Cascading transfers — NOT PRESENT (as an NPE pattern). There were two same-day recordings on 2012-11-16 (conversion to ArcSight, LLC + assignment to HP Development Co. L.P.) and two near-simultaneous 2017 recordings (EntIT assignment + JPMorgan security interest). But these are (a) years apart, (b) between affiliated operating entities in a documented corporate succession, and (c) consistent with HP's 2015 split and the 2017 Micro Focus software combination. The classic red flag — a rapid chain of unrelated, anonymously named LLCs sharing an address and correspondent within <24 months — is not present.

  5. Pre-litigation transfer — NOT PRESENT / INAPPLICABLE. The last ownership-affecting recording is the 2019 change of name, four-plus years before the 2023 release, and I found no infringement suit naming '083 (consistent with your earlier litigation section). There is no transfer within six months of any suit to enable assertion.

  6. Bankruptcy fire-sale — NOT PRESENT. No Chapter 7/11 estate of ArcSight, HP, HPE, EntIT, or Micro Focus. Micro Focus's 2022–2023 event was a sale to OpenText, not an insolvency liquidation.

  7. Privateering — NOT PRESENT. No operating company transferred the patent to an NPE to assert against competitors. The chain stays inside the operating-company bloodline end to end.

  8. Defensive aggregator — NOT PRESENT. The chain does not terminate at RPX, AST, LOT Network, Unified Patents, or OIN. The terminal owner of record is Micro Focus LLC (operating), within OpenText (operating).


Verdict

Operating-company assertion — with an explicit qualification: this is operating-company ownership, and I found no assertion.

Justification: every recorded link is an internal reorganization or corporate-succession transfer among large operating software companies — Priam/AcSight merger (recorded 2010-12-23), ArcSight, Inc. → ArcSight, LLC certificate of conversion and ArcSight, LLC → Hewlett-Packard Development Co. L.P. (both recorded 2012-11-16), HPE Development LP → EntIT Software LLC (Reel 042746/0130), the EntIT → Micro Focus LLC change of name, and the JPMorgan security interests (Reels 044183/0577 and 044183/0718, recorded 2017-10-11, released 2023-02-02). None of the eight NPE signals is present, and the current owner ships the ArcSight product line embodying the claims. The only reason I do not call this a pure "operating-company assertion" without reservation is that the assertion element is unevidenced — I found no suit. If your rubric requires an assertion to select that verdict, the substantive reality is better described as operating-company ownership, non-asserting; the option set provided contains no exact label for that.

Verification link (Assignment Center): https://assignment.uspto.gov/patent/index.html#/patent/search (search patent number 8613083); alternate UI: https://assignmentcenter.uspto.gov/


Discrepancies with the previously generated sections (flagged, not silently reconciled)

  1. "Original assignee" label. The earlier Patent Summary lists the original assignee as Hewlett-Packard Development Co. LP. That is the assignee at issuance (2013), not the applicant at filing (2007). The 2007 filer was ArcSight, Inc., evidenced by the continuation lineage to the ArcSight-owned '585 and by the later "ArcSight, Inc. → ArcSight, LLC" conversion record.
  2. EntIT assignment date. The earlier sections (via Google Patents) give 2017-06-09 for the EntIT assignment; Espacenet/INPADOC gives executed 2017-04-05, Reel 042746/0130, with a 2017-10-11 update. Treat 2017 (not a specific day) as the safe statement.
  3. Micro Focus name-change date. Google lists the EntIT → Micro Focus LLC change of name at 2019-08-08; state registrations show the name change taking effect 2020-11-30 / 2020-12-02. The 2019 date is likely the Delaware effective date; the 2020 dates are state foreign-registration updates.
  4. Current ownership characterization. The prior sections stopped at "Micro Focus LLC (current assignee)." The more complete statement: assignee of record is Micro Focus LLC, but the ultimate parent since 2023-01-31 is OpenText Corporation, which is why the JPMorgan security interests were released on 2023-02-02.

What I could not obtain (state plainly, do not rely on missing fields)

  • Reel/frame for the inventorship assignment, the 2010 merger, the 2012 conversion and HP assignment, the 2015 HPE assignment, and the 2019 name change — not retrieved.
  • Correspondents of record for every '083 entry — not retrieved. This is the highest-value remaining field for your NPE-signal analysis (signal #3), and it is the one I am least able to answer. It requires a direct Assignment Center query.

Generated 9/28/2026, 4:32:07 PM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

I'll pull the citation record for US 8,613,083 specifically, then work reference-by-reference. Let me start with targeted searches.

The FreePatentsOnline snippet gave me a partial cited-references list. Let me pull the rest of the list and the foreign/NPL citations.

I hit my search-step ceiling mid-investigation. Here is the analysis with exactly what I retrieved, what I could not, and where the gaps are — no entries invented to fill the list.


Prior-art / cited-reference analysis — US 8,613,083 B1

Provenance and limits (read before using the table)

  • USPTO source limitation. I did not have direct query access to the USPTO Patent Center / Patent Public Search full-text or to PatentCenter's "References Cited" field in this session. I worked from FreePatentsOnline's transcription of the patent's cited-reference section (https://www.freepatentsonline.com/8613083.html) and Google Patents (https://patents.google.com/patent/US8613083/en). The number was run literally as 8613083 / 8,613,083; I did not return results for similar numbers.
  • The retrieved reference list is truncated. FPO's "US Patent References" block was cut off at US 7,159,237 (2007-01-09). Because the list is sorted newest-first, the older entries below 7,159,237 — which are the entries most likely to constitute real § 102 art against this 2002-priority patent — were not retrievable. I am not reconstructing them.
  • Claim text is still unavailable. The authoritative patent text I was given ends inside the Detailed Description and does not include the "What is claimed is" section (this was flagged in the previously generated sections and remains true). Every "which claim(s)" assessment below is therefore conditional, keyed to the four limitations recited in the SUMMARY OF THE INVENTION and the abstract — which in this family track the independent claim almost verbatim. Do not rely on any claim mapping here for a validity or infringement position until the literal claim set is pulled.
  • Dates came from the publication/issue column only. Filing dates for most references were not surfaced; I flag that per row.

The anomaly that governs the whole exercise

Nearly every entry I could retrieve carries a 2007–2008 publication/issue date — i.e., after both the '083 patent's actual filing date (2007-04-25) and its effective 2002-12-02 priority date. And a large subset names the same inventors or the same ArcSight/HPE assignee (Njemanze, Aguilar-Macias, Shankar, Lahoti, Singla, Tidwell, Huang). That pattern is the signature of an IDS-style citation of co-owned/related applications and specification-incorporated-by-reference material — not of § 102 anticipating art. Two consequences:

  1. Several of the strongest-looking "citations" are legally disqualified as prior art to the '083 (same inventive entity / common ownership; and/or their own filing dates post-date the priority date). See the exclusion list below.
  2. A proper § 102 search for this patent must go to pre-2002 art (log batching, SNMP-trap collection, syslog store-and-forward, priority queuing in network management), which is almost certainly at the truncated bottom of the citation list.

I therefore present the list I have, tagged by whether it can even function as prior art.


Retrieved cited references (partial list, newest → oldest as shown by FPO)

Legend for "Anticipation potential" — A = could be § 102 art on its face, but does not on its title/known content reach the prioritized-timer-gated batching limitations; B = disqualified or likely disqualified as prior art (same family / co-owned / post-priority); C = potentially relevant to a background limitation (event receipt, correlation, parsing) but not to the batching core.

# Full citation Issue/publ. date (filing date if known) Brief description (from title/record; where inferred I say so) § 102 claim potential
1 US 2010/0058165 A1 — Bhattacharya et al., "Method and system for displaying network security incidents" 2010-03-04 Security-incident display/GUI. B — post-priority publication; cannot be § 102(a)/(b) art against a 2002 priority.
2 US 7,644,365 B2 — Bhattacharya et al., "Method and system for displaying network security incidents" 2010-01-05 Same family as #1; incident visualization. B/C — likely post-priority; display art, not batching.
3 US 7,483,972 B2 — Bhattacharya et al., "Network security monitoring system" 2009-01-27 Network security monitoring platform (inference: NetForensics-type). B/C — monitoring architecture; not batching.
4 US 2008/0165000 A1 — Morin et al., "Suppression of False Alarms in Alarms Arising from Intrusion Detection Probes in a Monitored Information System" 2008-07-10 Alarm suppression/false-positive reduction. B/C — thresholds/suppression, not priority-buffer batching.
5 US 2008/0162592 A1 — Huang et al., "Storing Log Data Efficiently While Supporting Querying to Assist in Computer Network Security" 2008-07-03 Log storage/query efficiency. B/C — log storage; tangential.
6 US 7,376,969 B2 — Njemanze et al., "Real time monitoring and analysis of events from multiple network security devices" 2008-05-20 Real-time event collection/analysis from multiple security devices — same inventor (Njemanze), ArcSight lineage. B — co-owned/same inventive entity; also post-priority. Closest in subject matter to the '083, but legally disqualified as art.
7 US 2008/0104276 A1 — Lahoti et al., "Real-Time Identification of an Asset Model and Categorization of an Asset to Assist in Computer Network Security" 2008-05-01 Asset model/categorization. B — ArcSight co-owned; post-priority.
8 US 2008/0104046 A1 — Singla et al., "Tracking Changing State Data to Assist in Computer Network Security" 2008-05-01 State tracking. B — ArcSight co-owned; post-priority.
9 US 7,333,999 B2 — Njemanze, "Expression editor" 2008-02-19 Expression/rule authoring UI — same inventor, ArcSight. B — co-owned; post-priority.
10 US 7,308,689 B2 — Black et al., "Method, apparatus, and program for associating related heterogeneous events in an event handler" 2007-12-11 Correlating heterogeneous events in an event handler (inference: IBM). A/C — heterogeneous-event correlation; does not, on its face, reach prioritized timer-gated batching.
11 US 2007/0260931 A1 — Aguilar-Macias et al., "Merging multi-line log entries" 2007-11-08 Log-entry merging — same inventor (Aguilar-Macias), ArcSight. B — co-owned/same inventor; post-priority.
12 US 2007/0234426 A1 — Khanolkar et al., "Comprehensive Security Structure Platform for Network Managers" 2007-10-04 Security management platform. A/C — platform architecture; not batching.
13 US 7,278,160 B2 — Black et al., "Presentation of correlated events as situation classes" 2007-10-02 Correlated-event presentation. A/C — correlation presentation.
14 US 7,260,844 B2 — Tidwell et al., "Threat detection in a network security system" 2007-08-21 Threat detection via vulnerable/used-vulnerability comparison. Expressly incorporated by reference in the ArcSight family's own spec (this reference is cited in RU 2,417,417 C2 as incorporated). B/A — ArcSight-family; incorporated-by-reference, not § 102 art.
15 US 2007/0169038 A1 — Shankar et al., "Self learning event parser" 2007-07-19 Event parsing/normalization — ArcSight founder-affiliated inventor. B — co-owned; post-priority. Relevant to the normalize component, not batching.
16 US 2007/0162973 A1 — Schneier et al., "Method and System for Dynamic Network Intrusion Monitoring, Detection and Response" 2007-07-12 Dynamic intrusion monitoring/response (same family as #22). A/C — intrusion detection; not batching.
17 US 2007/0150579 A1 — Morin et al., "Method of managing alerts issued by intrusion detection sensors of an information security system" 2007-06-28 Alert management from IDS sensors. A/C — alert handling; not priority-buffer batching.
18 US 2007/0136437 A1 — Shankar et al., "Method and system for real time detection of threats in high volume data streams" 2007-06-14 High-volume stream threat detection. B/C — co-owned; high-volume handling is adjacent to but not the claimed prioritized batching.
19 US 2007/0118905 A1 — Morin et al., "Method of automatically classifying a set of alarms emitted by sensors for detecting intrusions of an information security system" 2007-05-24 Automatic alarm classification. A/C — classification; not batching.
20 US 7,219,239 B2 — Njemanze et al., "Method for batching events for transmission by software agent" 2007-05-15 (parent filed 2002-12-02) The parent patent — same title, same inventors, the application of which the '083 is a continuation. B — NOT prior art. It is the priority document; same inventive entity and same family. Listed here only to flag it as a trap.
21 US 7,171,689 B2 — Beavers, "System and method for tracking and filtering alerts in an enterprise and generating alert indications for analysis" 2007-01-30 Enterprise alert tracking/filtering. A — the most plausible substantive § 102 candidate among retrieved entries for alert-collection/forwarding, but on its face it does not disclose priority-partitioned buffers or a timer-gated, priority-ordered batch fill.
22 US 7,159,237 B2 — Schneier et al., "Method and system for dynamic network intrusion monitoring, detection and response" 2007-01-09 Dynamic intrusion monitoring/response. A/C — IDS art; not batching. (List truncated here.)

Same-family / incorporated-by-reference set — excluded as prior art

These appear in the citation record but should be excluded from any § 102 analysis for the '083:

  • US 7,219,239 (Njemanze et al.) — the parent; the '083 is expressly "a continuation of U.S. patent application Ser. No. 10/308,585, filed on Dec. 2, 2002, now U.S. Pat. No. 7,219,239."
  • US 7,376,969 (Njemanze et al.), US 7,333,999 (Njemanze), US 2007/0260931 (Aguilar-Macias et al.) — same inventors/ArcSight co-owned.
  • US 7,260,844 (Tidwell et al.), US 2008/0104046 (Singla et al.), US 2008/0104276 (Lahoti et al.), US 2008/0162592 (Huang et al.), US 2007/0169038 & US 2007/0136437 (Shankar et al.) — ArcSight-family and/or incorporated-by-reference.

Under pre-AIA practice, same-inventive-entity and commonly-owned material is disqualified for anticipation (§ 102) and, for the co-owned set, for obviousness (§ 103(c)). Several rows above are therefore citation noise, not art.


Bottom line on § 102

  • No retrieved reference anticipates the core of the '083. On the available titles/content, none of entries 1–22 discloses the claimed combination: (a) receiving security events from a network device by a distributed software agent; (b) determining a priority for each event; (c) storing events in a plurality of prioritized event buffers for a period determined by a timer; and (d) on timer expiration, building a batch by including events in priority order until the batch is full. The closest subject-matter match (US 7,376,969, same inventor) is disqualified as art, and the closest remaining substantive candidates (US 7,171,689, US 7,308,689, US 7,260,844) address alert handling/correlation, not priority-partitioned, timer-gated batching.
  • The real § 102 exposure sits below the truncation point. The list continues past US 7,159,237 (2007-01-09) to older references. Pre-2002 art on event/log store-and-forward batching, SNMP-trap collection and forwarding, priority queuing, and threshold/timer-driven message flushing is where anticipation of limitations (b)–(d) would most credibly come from — and I could not retrieve it.
  • I found no non-patent-literature ("Other References") or foreign-patent citation list for the '083 in the sources available to me. The Google Patents "prior art keywords" field is: event, security, events, security events, priority.

What I could not do (explicit gaps — not fillable by inference)

  1. Confirm the § 56 examiner-cited subset. I could not separate examiner-cited art from applicant/IDS-cited co-owned material from a USPTO source.
  2. Retrieve the pre-2007 portion of the citation list (below US 7,159,237) — the most probative portion for this priority date.
  3. Retrieve foreign patent references and NPL citations.
  4. Retrieve the literal claims, without which element-by-element anticipation mapping is not defensible.

To close this out, run these directly

  • USPTO Patent Public Search full-text for "8613083" → open "Referenced By"/"Patent Citations" and the PatentCenter "References Cited" / file-wrapper tabs — this yields the complete, source-of-record citation list including the examiner-cited set.
  • Granted PDF: https://patentimages.storage.googleapis.com/55/62/b9/948b5b2589b6c8/US8613083.pdf (front page (56) block + claims).
  • Global Dossier / Espacenet for the same family's search-report citations — useful precisely because the US list appears dominated by co-owned documents.

If you can lift the tool-step limit, I will pull the complete (56) list and the literal claim set and convert the table above into a true reference-by-reference, element-by-element § 102 chart.

Generated 9/28/2026, 4:32:16 PM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

I'll try to close the biggest gap flagged in the Prior Art and PTAB sections — the missing claim language — and pin down the effective filing dates of the pre-2002 candidates, since those two facts control any § 103 theory.

Excellent — that surfaced real dates. Let me pin the claim text (my earlier sections flagged this gap) and check two more pre-2002 candidates.

Scope, framework, and two contradictions I have to flag first

Framework. US 8,613,083 was filed 2007‑04‑25 and claims priority to 2002‑12‑02, so pre‑AIA 35 U.S.C. § 102/§ 103 governs (AIA first‑inventor‑to‑file applies only to applications filed on or after 2013‑03‑16). Obviousness therefore runs through KSR Int'l Co. v. Teleflex Inc., 550 U.S. 398 (2007), and Graham v. John Deere. In litigation the claims carry the § 282 presumption of validity and must be overcome by clear and convincing evidence (Microsoft v. i4i, 564 U.S. 91 (2011)); in an IPR the standard is preponderance — but as the PTAB section established, no petition was ever filed, so there is no Board construction to borrow.

⚠️ Claim‑text gap persists. Despite targeted searching (Google Patents, FreePatentsOnline, Justia, the granted PDF), I still could not retrieve the "What is claimed is" text of either 8,613,083 or its parent 7,219,239. Everything below about the independent claim is therefore a reconstruction from the abstract, the SUMMARY, and the FIG. 10/11 discussion — which in this family track the claim language closely. Treat the element numbering as a working scaffold, not as quoted claim text.

⚠️ Two contradictions with prior sections.

  1. The Porras priority date. The Prior Art section states US 6,704,874 has a "priority date 2000‑10‑16." That is wrong. The granted PDF reads "(22) Filed: Jul. 25, 2000," and Google's family data lists priority 1998‑11‑09 (SRI International). The '874 is therefore better art than the earlier section assumed, not worse. (If "2000‑10‑16" came from a different family member, I could not identify which.)
  2. The expiry clock. The PTAB and Assignment sections reason that the patent's adjusted expiration of 2026‑07‑24 has "run" and that "the term has run." That was written against a September 28, 2026 working date. This task's date is April 26, 2026 — 2026‑07‑24 has not yet occurred. Separately, the record is internally odd: Google labels the status "Expired – Fee Related" while still listing an adjusted expiration of 2026‑07‑24. A fee‑related lapse would normally end enforceability at a missed maintenance window (the 12‑year fee for a 2007 filing falls ~2019), not in 2026. Do not rely on either the status label or the expiry date for an enforceability window without pulling PatentCenter fee history. This matters here only marginally, but the earlier sections overstated the finality of the term.

One more sourcing caveat. I quote claim language below from US 7,694,115 ("Network‑based alert management system"), a Porras/SRI family member, because its claims were visible in the search record. I did not independently verify that the '115 traces to the 1998‑11‑09 priority; its family relationship to the '874 is an inference. The '874 itself (filed 2000‑07‑25, priority 1998‑11‑09) is verified.


Step 1 — Prior‑art availability screen (this gate decides everything)

Under pre‑AIA § 102(e), a U.S. patent is art as of its filing date only if filed "by another" before the applicant's invention date (here, the 2002‑12‑02 priority date). Under § 102(a)/(b), the reference must be published/patented before 2002‑12‑02. Applying that to the citation record, several references the Prior Art section treated as available are not:

Reference Earliest date (per record) § 103‑available vs. 2002‑12‑02? Basis
US 6,704,874 (Porras, SRI) 1998‑11‑09 priority; filed 2000‑07‑25 YES § 102(e); family incl. US 6,321,338 (granted 2001‑11‑20) is § 102(b) art
US 7,159,237 / US 2007/0162973 (Schneier, Counterpane) 2000‑03‑16 priority; filed 2001‑01‑19 YES § 102(e)
US 7,171,689 / US 2003/0221123 (Beavers, Symantec) 2002‑02‑25 filed YES (narrowly) § 102(e) — filed ~9 months before priority
US 7,127,743 (Khanolkar, NetForensics) 2000‑06‑23 YES § 102(e)
US 7,278,160 (Black, IBM) 2001‑08‑16 YES § 102(e)
US 7,043,727 (Micromuse, "efficient distribution of network event data") 2001‑06‑08 YES (lead — unverified disclosure) § 102(e)
US 2003/0093514 A1 (Valdes, "Prioritizing Bayes network alerts") 2001‑09‑13 YES § 102(e)
US 7,308,689 (Black, IBM) 2002‑12‑18 NO — 16 days too late Filed after 2002‑12‑02
US 7,260,844 (Tidwell), US 7,333,999 (Njemanze) 2003‑09‑03 / 2003‑10‑30 NO Post‑priority; also § 103(c) common ownership
US 7,376,969 (Njemanze) 2002‑12‑02 (same day) NO Same day ≠ "before"; same inventive entity; § 103(c)
US 7,219,239 (parent) 2002‑12‑02 NO Same inventive entity/specification — cannot be art against its own continuation

Two corrections to the Prior Art section follow from this. (a) Its suggestion that US 7,308,689 (Black) is "the most plausible non‑family candidate for a § 103 combination on correlation‑related claims" is unavailable — it was filed 2002‑12‑18, after the priority date. Its sibling US 7,278,160 (Black, 2001‑08‑16) is available and should be substituted. (b) The section's list of "2007–2010 publications that cannot be art" was correct, but it omitted the flip side: the whole Micromuse/ISS/SRI 1998–2002 layer is available and is where the real obviousness case lives.


Step 2 — Reconstructed independent claim (working scaffold)

# Element
[1a] receiving security events from a network device by a distributed software agent of a network security system
[1b] determining a priority of each received security event
[1c] storing the events in a plurality of prioritized event buffers based on determined priorities, for a period of time determined by a timer
[1d] upon timer expiration, creating a batch for transport to a security event manager, by including events in order of priority until the batch is full

No single reference of record discloses [1a]–[1d]. So there is no § 102 case; this is a § 103 analysis or nothing.


Step 3 — Primary combination: Porras ('874 family) + Schneier ('237) + Beavers ('689)

This is the combination I would lead with. All three are § 102(e)‑available, all are in the same field (network security event/alert monitoring), and the split of labor is clean: Schneier supplies the distributed agent→central manager architecture and the express bandwidth motivation; Porras supplies per‑event importance assignment plus normalization and consolidation; Beavers supplies severity normalization and the threshold/rule layer.

Element Schneier '237 (Counterpane) Porras '874 / '115 (SRI) Beavers '689 (Symantec)
[1a] distributed agent receiving events from network devices, sending to a central manager Yes, squarely. Probe 2000 at the customer site "collects status data from sensors in the form of firewalls and intrusion detection systems 1010, commercial or custom sensors or agents 1020 and 1040, and decoys and honeypots 1030"; it creates "sentry messages … transmitted to the SOC through pipes 3000," received by gateway system 4000 at the SOC Yes — data connections "configured to receive network alerts from network sensors," incl. "heterogeneous sensors" (claim 4/20) Yes — "a plurality of enterprise device outputs … each output contains an event relating to an enterprise device," devices incl. firewall, IDS, router
[1b] determine a priority per event Partly — probe performs filtering/analysis at the probe before transmission Yes. Claim 7: "a prioritizing component that is configured to assign an indication of importance to an alert based on a characteristic of the alert" Yes. Knowledge‑base adds a "threat severity" to the common‑format event
Normalization (predicate for "priority" being comparable) — Claim 4/5/25: alert formatting component converting an alert to a common format Yes — device outputs "having different formats" translated into a common format event via translation/signature specifications
[1c] prioritized buffers + timer No No — no priority‑partitioned buffers and no timer No
[1d] timer‑gated, priority‑ordered batch filled to capacity No No — distribution logic sends reports to subscribers; no fill‑to‑capacity batch on a timer No

So the combination as disclosed covers [1a], [1b], normalization, aggregation/consolidation (Porras claim 1 consolidated incident report; Porras claims 9–10 single/multiple sensor consolidation), and remote reconfiguration (Porras claims 1–3, 12–14, 16, 18–19, 24). The only real gap is [1c]–[1d]: the priority‑partitioned buffer set flushed by a timer into a fixed‑capacity batch.

Why a POSITA would have closed that gap — the motivation, articulated

  1. The problem is stated in the art itself, and the solution is conceded to be known. Schneier's '237 states that the probe analyzes "in order to control the amount of information subsequently transmitted to the SOC." That is an express recital of the transport‑volume problem. The '083 specification concedes the same problem and the same fix: "there is a certain amount of overhead associated with transmitting events from an agent to the agent manager 26, such as transport protocol overhead and system communication overhead, it can improve overall performance of the network security system to batch security events prior to sending them." Under KSR, a design incentive identified in the prior art, plus a known technique applied to a known device to yield a predictable result, is the paradigm of obviousness.
  2. "Use of a known technique to improve similar devices in the same way." Priority‑based queue servicing with periodic drain to a bounded transmission unit was routine in data communications well before 2002 (router/switch class‑of‑service and priority queues; log/trap batching in syslog and SNMP management). Nothing about applying it to a security‑event agent changes its operating principle — the events are already discrete, already normalized to a common schema (Porras, Beavers), and already tagged with an importance indicator (Porras claim 7; Beavers' threat severity). Ordering tagged messages into buffers keyed to their tag, and draining high‑to‑low on a periodic trigger, is the predictable function of the elements as arranged.
  3. The trigger is a naked design choice over a two‑option space. The '083 specification itself says gate 256 "can be a timer or counter," and the batching "can be done according to a configurable time limit … or according to a number limit." KSR: where "a finite number of identified, predictable solutions" exists, trying the obvious one is not invention. A claim reciting a timer covers one limb of a two‑limb design space the applicant treated as interchangeable.
  4. Same field / common problem → combinable as a matter of law. All three references address collecting heterogeneous security events and shipping them to a central analysis point (In re Clay; KSR "same field of endeavor").
  5. Reasonable expectation of success. Buffering, priority ordering, and deferred transmission of discrete data records were the ordinary work of a person of skill; nothing in the art taught that deferred delivery of priority‑ordered events would fail.

Result: claim 1 as reconstructed would be obvious over Schneier + Porras, and more comfortably over Schneier + Porras + Beavers.


Step 4 — Backup combinations (and what each adds)

# Combination Independent element it supplies that the primary combo lacks or weakens
B Snow? → Schneier + Porras + US 7,043,727 (Micromuse, "efficient distribution of network event data," 2001‑06‑08) If '727 discloses batching/aggregation of network event data expressly for distribution efficiency, it converts the "motivation to batch" from an inference into an express teaching. Unverified — I could only read the title and date from the Porras‑family citation table; I did not open the document. Verify before relying on it.
C Beavers + Schneier + US 7,127,743 (Khanolkar, 2000‑06‑23) A pre‑2002 "comprehensive security structure platform for network managers" — a centralized multi‑tier security management architecture, useful if the patent owner argues Porras is a report‑distribution system rather than an event‑collection system.
D Schneier + Porras + US 7,089,428 / US 2002/0019945 (Internet Security Systems, 2000‑04‑28, "managing security events on a network") An alternative primary for "security event management" generally; provides the centralized event‑management framing without the SOC/service‑provider posture of Schneier.
E Porras + US 7,278,160 (Black, IBM, 2001‑08‑16) Substituted for the unavailable US 7,308,689; Black's "presentation of correlated events as situation classes" supplies the correlation layer if any dependent claim is drawn to correlating/meta‑events.

Note the substitution correction: any chart built on US 7,308,689 (Black, filed 2002‑12‑18) collapses on the priority date. Use US 7,278,160 instead.


Step 5 — Dependent‑claim obviousness (where the real exposure is)

Feature (per spec) Obviousness basis
Five‑level scale (very‑high…unknown) Normalizing device severities into one hierarchy is expressly taught by Beavers ("threat severity" via knowledge base); the number and names of levels is a design choice over a finite, predictable set
Configurable batch size and configurable batching frequency Porras claims 1–3, 6, 12–14, 17–19, 24 teach remote/dynamic configurability of the alert‑processing components; making batch parameters configurable is the same technique
Buffers "delineated logically … need not be physically separate in memory" Implementation detail/data‑structure choice; no technical difference to the claimed invention (In re Aller‑type design choice)
HTTP transport of the batch Selection among known transports; Schneier transmits sentry messages through "pipes" to a gateway; KSR familiar‑element rationale
Skipping low‑priority buffers during peak traffic Ordinary queue management; flows directly from Schneier's express "control the amount of information … transmitted" objective
Aging low‑priority events into higher batching buffers without changing their underlying priority Classic anti‑starvation aging from priority scheduling — a known technique to solve the known problem of starvation, with a predictable result. Strong on KSR; no specific record citation available, so this one rests on general knowledge in the art and needs a supporting reference located
Higher‑priority batches sent more frequently Same class of scheduling design choice
Aggregation with a count field; excluding time fields from the like‑event comparison Porras claim 1 (consolidation of multiple alerts into one consolidated incident report), claims 9–10; Beavers (occurrence "a number of times over a set period"); excluding volatile fields from a duplicate‑match is a design choice
Parser/map/translator normalization incl. severity‑scale translation Porras claims 4/5/25 (common‑format conversion, configurable); Beavers (translation files + signature specification + argument name/value pairs)
Modular components toggled by a config file; remote reconfiguration via heartbeat Porras claim 1 ("remote management unit … configured to dynamically modify the alert processing logic"), claims 14, 18–19, 24 (interactive remote UI; configuration engine; run‑time command interpreter); Schneier (SOC "sentry update manager 4010 is responsible for updates sent back to the probe")

Step 6 — Where this theory is vulnerable (state it plainly)

  • No anticipation. No reference of record discloses the [1c]–[1d] combination. The case is entirely a § 103 combination case, which means it lives or dies on the articulated motivation.
  • Patent owner's best teaching‑away argument: Schneier frames the probe's job as reducing what reaches the SOC so analysts can act promptly; Porras's distribution logic delivers reports to subscribers. The owner will argue the art points toward immediate, filtered delivery and away from deferred, priority‑ordered, batch delivery. Rebuttal: absence of a disclosure of batching is not teaching away (In re Keller); and retaining and ordering is complementary to filtering, because both serve the same express goal of controlling transmitted volume. But this fight is real.
  • The two records I could not verify are load‑bearing: US 7,043,727's actual disclosure (Combination B) and the '115's priority chain. Neither may be asserted as read until pulled.
  • The § 112/priority squeeze cuts the other way, and it is worth noting. If any claim limitation (e.g., the prioritized‑buffer/timer combination) were shown not to be supported by the 2002‑12‑02 parent, that claim would take the 2007‑04‑25 filing date — which would immediately make the entire 2003–2007 arc (§ 103(c)‑encumbered ArcSight work aside) and the Webroot v. AO Kaspersky‑style ArcSight‑system prior art available. Because the '239 and '083 share essentially identical specifications, that attack looks weak — but I cannot verify it without the '585 as filed and the '239 claims.
  • No objective indicia of record. No litigation, no PTAB proceeding, no licensing, no evidence of nexus. That cuts for an obviousness defense, but it also means there is no § 282‑side counterweight to worry about.

Bottom line

Confidence: moderate‑high that claim 1 as reconstructed is obvious; moderate on the dependent claims; low on anything requiring the literal claim text.

  1. No § 102 case exists on the record — no single reference teaches all four elements.
  2. The strongest § 103 combination is Schneier US 7,159,237 (2000‑03‑16) + Porras US 6,704,874 family (1998‑11‑09), optionally + Beavers US 7,171,689 (2002‑02‑25). Schneier supplies the distributed agent → central manager architecture and an express bandwidth‑reduction motivation; Porras supplies per‑event importance assignment, common‑format normalization, and consolidation; Beavers supplies severity normalization and rule/threshold logic. The gap ([1c]–[1d]) is filled by KSR's "known technique to improve similar devices" plus the design‑incentive rationale that the references themselves articulate.
  3. Two specific corrections to earlier sections stand: Porras '874's priority is 1998‑11‑09 (filed 2000‑07‑25), not 2000‑10‑16; and US 7,308,689 is not available art (filed 2002‑12‑18) — substitute US 7,278,160.
  4. Before any chart is filed: pull the granted claims of 8,613,083 and 7,219,239, and read US 7,043,727 and the US 7,694,115 priority chain. Those three items are the only things standing between this analysis and a defensible contention set.

Generated 9/28/2026, 4:32:59 PM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →