Invalidity dossier
US 9934379
Methods, systems, and computer readable media for detecting a compromised computing host
Current assignee: University of North Carolina at Chapel Hill
Added 9/30/2026, 5:50:51 PM
Active provider: DeepSeek · deepseek-v4-flash
Auto-generating section 1 of 2: Extensions…
Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.
Patent summary
Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.
I'll search for this specific patent number across USPTO and litigation sources.
Let me run more targeted searches for litigation and USPTO records.
Let me do one final targeted check for any litigation or Federal Circuit activity involving this specific patent.
US Patent 9,934,379 — Summary
A note on scope/uncertainty up front: I was unable to locate any litigation, USPTO post-grant proceeding (IPR/PGR), or Court of Appeals for the Federal Circuit (CAFC) docket from 2016–2026 involving U.S. Patent No. 9,934,379. Searches of CAFC 2026 docket material returned only unrelated matters (e.g., Netlist v. Micron), and targeted litigation searches returned nothing tied to this patent number or application 14/773,660. I state explicitly that I cannot confirm any assertion or appeal activity — the absence of results is not proof that none exists, but there is no evidence of any. The bibliographic and claim information below is drawn from the authoritative full text provided, corroborated by search results (Justia, PlaineSite assignment records, UNC/PCT records).
Bibliographic data
| Field | Value |
|---|---|
| Patent number | US 9,934,379 B2 |
| Title | Methods, systems, and computer readable media for detecting a compromised computing host |
| Application no. | 14/773,660 (U.S. national-stage entry of PCT/US2014/020683; national-stage entry date Sept. 8, 2015) |
| Filing date | March 5, 2014 (international filing date; PCT filed same date) |
| Priority | U.S. Provisional 61/772,905, filed March 5, 2013 |
| Pre-grant publication | US 2016/0026796 A1, published January 28, 2016 |
| Issue date | April 3, 2018 |
| Assignee | The University of North Carolina at Chapel Hill (Chapel Hill, NC) — assignment recorded April 14, 2014 (Reel 32665/681) |
| Inventors | Fabian Monrose (Chapel Hill, NC); Teryl Taylor (Carrboro, NC); Srinivas Krishnan (Berkeley, CA); John McHugh (Saluda, NC) |
| PCT publication | WO 2014/138205 A2 / A3 |
| Examiners | Primary: Thanhnga B. Truong; Assistant: Gregory Lane |
| Government interest | Made with NSF support under Grant No. OCI-1127361 |
| Claims | 22 total; independent claims 1 (method), 12 (system), 22 (computer readable medium) |
| Legal status | Expired – Fee Related; adjusted expiration March 15, 2034 |
(Note: Justia lists a 28-claim set under the pre-grant publication US 2016/0026796; that is the pre-grant claim set. The granted patent has 22 claims, and the independent claims were narrowed relative to the published version — e.g., the increment/decrement and threshold-within-a-time-period limitations were added to claim 1 in the granted set.)
Abstract (verbatim)
Methods, systems, and computer readable media for detecting a compromised computing host are disclosed. According to one method, the method includes receiving one or more domain name system (DNS) non-existent domain (NX) messages associated with a computing host. The method also includes determining, using a host score associated with one or more unique DNS zones or domain names included in the one or more DNS NX messages, whether the computing host is compromised. The method further includes performing, in response to determining that the computing host is compromised, a mitigation action.
Plain-language overview of the independent claims
Claim 1 — Method. You collect DNS "non-existent domain" (NX) responses (i.e., failed lookups) that belong to a particular host, within a time window. Using a running "host score" tied to how many unique DNS zones/domain names appear in those NX messages, you decide whether that host is compromised. The score is adjusted up or down depending on whether a given zone/domain has been seen before in the NX messages: +1 for a never-before-seen zone, −1 for a repeat zone. The compromise decision is made when the score reaches or exceeds a threshold within the time period. If the host is deemed compromised, you take a mitigation action. The core intuition: a normal user hits a few familiar failing domains, while an infected bot scanning for its command-and-control server generates many novel random domains.
Claim 12 — System. The same technique embodied in hardware/software: a processor plus a Compromised Host Detection (CHD) module (software executable by the processor) configured to receive the DNS NX messages, compute/adjust the host score by the +1 unique / −1 non-unique rule, decide compromise when the score meets or exceeds the threshold within the time period, and perform a mitigation action.
Claim 22 — Non-transitory computer readable medium. A CRM storing instructions that, when executed, cause a computer to carry out the identical steps (receive NX messages within a time period → score by unique/non-unique zones → threshold decision within the time period → mitigation).
Notable dependent-claim features (for context)
- Sequential hypothesis testing to make the compromise determination (claims 6, 16), including parameters based on network characteristics, delay, user base, resource utilization, etc. (claims 7, 17).
- Use of a lock-free data structure for analyzing header/payload portions and processing multiple streams in parallel (claims 8–9, 18–19).
- Specific mitigation actions: reporting the host, logging host/domain info, discarding, logging, or rerouting messages (claims 10, 20).
- Implementation on a DAG card, GPU, or general-purpose processor (claims 11, 21).
- Detection "prior to the computing host communicating with a malicious entity or command server" (claim 3).
Technical backdrop (from the specification)
The patent is a research-derived disclosure (UNC; NSF-funded) that applies Wald's sequential probability ratio test to DNS NX traffic. It filters out benign/whitelisted traffic (including a Zipf-based filter of the top ~100 zones), tracks per-host unique-zone observations, and classifies hosts at line speed using lock-free, multi-core processing. The family includes related academic work ("Crossing the Threshold: Detecting Network Malfeasance via Sequential Hypothesis Testing," 2013) and citations to Yadav/Reddy DNS-failure botnet work and portscan/worm sequential-detection literature.
Bottom line
US 9,934,379 is a UNC–Chapel Hill-owned, now-expired (fee-related) patent covering DNS-NX-based compromised-host detection using a running uniqueness score and a threshold test, with method, system, and CRM claims. No litigation, IPR, or CAFC 2026 docket activity for this patent could be found, and I therefore cannot confirm that it was ever asserted.
Generated 9/30/2026, 5:51:14 PM
Cases on file (0)
Specific litigation cases in our database that name US patent 9934379. The free-form analysis below may also discuss cases beyond this list.
No cases on file mention this patent. Upload a CSV or add a case manually in Admin → Manage litigation cases.
Litigation summary
Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.
I'll search litigation-specific sources for US 9,934,379.
Let me run additional targeted checks on litigation databases.
Let me do final checks on the Stanford NPE database and docket sources.
Litigation Search Report — U.S. Patent No. 9,934,379
Query date: April 26, 2026
Patent: U.S. Patent No. 9,934,379 B2 ("Methods, systems, and computer readable media for detecting a compromised computing host")
Assignee of record: The University of North Carolina at Chapel Hill
Bottom line
No litigation involving U.S. Patent No. 9,934,379 could be identified. To the best of available evidence, the patent has never been asserted in any U.S. district court, the ITC, or the Federal Circuit, and it has not been the subject of any USPTO post-grant proceeding (IPR/PGR/CBM).
I want to be precise about what this means: the result is "no litigation found," not "litigation provably does not exist." Absence of hits is not affirmative proof of non-assertion, but every targeted source checked returned nothing tied to this patent number.
Required fields
Because no case exists to report, the requested matrix is intentionally empty:
| Plaintiff(s) | Defendant(s) | Jurisdiction | Case number | Filing date | Outcome/status |
|---|---|---|---|---|---|
| None identified | None identified | — | — | — | — |
Sources checked and what they returned
| Source category | Result |
|---|---|
| Stanford NPE Litigation Database (npe.law.stanford.edu) | No entry for 9,934,379. (Searches of this database returned only unrelated patents, e.g., 7,599,439.) |
| Unified Patents litigation/PTAB portal | No case list, IPR, or PGR referencing 9,934,379. |
| PTAB / USPTO PatentCenter proceedings | No post-grant proceeding involving this patent. All PTAB petition hits retrieved were for other patents (e.g., 9,843,786; 8,234,705; 8,726,389; 9,321,386; 10,202,266) with no mention of 9,934,379. |
| CAFC / PACER-oriented dockets (CourtListener, Docket Alarm) | No complaint or appeal naming 9,934,379 or application 14/773,660. |
| Assignment records (PlainSite, USPTO) | Only the inventor→UNC assignment (Reel 32665/681, recorded Apr. 14, 2014). No assignments to an NPE/litigation vehicle — a notable negative signal, since asserted university patents are commonly transferred or exclusively licensed before suit. |
| General web / litigation-news searches for "9,934,379" | Only patent-profile and assignment records (Justia, PatentLeaderboard, PlainSite). No complaint, docket, or news item. |
I applied the instructed discipline of matching the exact number 9,934,379 and excluding look-alikes. The near-misses that surfaced (9,934, 379-style numbers, 9,843,786, 9,621,421, etc.) were discarded as irrelevant.
Corroborating context (builds on, and confirms, the prior section)
The earlier-generated summary already reported no litigation, no IPR, and no CAFC activity. My independent re-run confirms and does not contradict that finding; there is no discrepancy to flag. Three points reinforce the conclusion:
Owner profile. The patent is held by UNC–Chapel Hill and was NSF-funded (Grant No. OCI-1127361). Research-university patents that are never asserted frequently remain within the institution rather than being funneled to assertion entities — consistent with the clean assignment chain observed here.
Lifecycle status. The patent is Expired – Fee Related, with an adjusted expiration of March 15, 2034. Lapse for non-payment of maintenance fees is itself a strong economic signal that the owner saw no enforcement value in the asset. Note that the sibling PCT application WO 2014/138205 A2/A3 is marked "not_active — Ceased"; that is a prosecution/lapse status, not litigation, and should not be miscoded as a legal proceeding.
Timing. The patent issued April 3, 2018. More than eight years have elapsed with no assertion, meaning any damages window would also be narrowing — further reducing the likelihood of future suit.
Caveats a client should understand
- PACER is not free-text searchable by patent number across all districts without a paid or aggregated subscription. A litigation could theoretically exist in a district whose docket is not captured by the free aggregators I could reach. If this is a freedom-to-operate or diligence matter, I recommend a paid PACER/Docket Navigator or Lex Machina run (searches by patent number 9,934,379 and by assignee "University of North Carolina" / inventors Monrose, Taylor, Krishnan, McHugh) to close that residual gap.
- Licensing without litigation is invisible to these sources. UNC may have granted non-exclusive or research licenses that would not surface in any litigation database. That would not constitute "litigation" and is outside the scope of this request, but it is relevant to any commercialization analysis.
- I did not locate any ITC Section 337 investigation, foreign (UPC/EPO) counterpart action, or state-court action involving this patent. The European counterpart, if any, was not identified.
Certification
Based on the sources searched on April 26, 2026, there is no known litigation — past or pending — involving U.S. Patent No. 9,934,379. If you require a litigation-grade clearance opinion, the residual PACER/Lex Machina gap noted above should be closed before relying on this as a negative clearance.
Generated 9/30/2026, 6:01:59 PM
Proceedings on file (0)
All PTAB activity →AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.
No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.
PTAB challenges
AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.
I'll verify the canonical (empty) structured list against public PTAB/CAFC sources before drafting.
No IPR hits surfaced for this patent number. Let me run a few more targeted queries to be sure I'm not missing a proceeding filed under a different formulation.
Let me confirm the fee-lapse status and rule out ex parte reexamination or any recently-filed proceeding.
Proceedings overview
Total AIA trial proceedings on U.S. Patent No. 9,934,379: zero (0 active / 0 claims invalidated / 0 claims sustained / 0 settled / 0 institution denied). The canonical USPTO Open Data Portal list supplied in this brief is empty, and my independent public-source checks found no IPR, PGR, or CBM ever filed against this patent — which means a defendant facing assertion is not looking at a PTAB-hardened or PTAB-narrowed patent. The defensive posture is therefore unusual and, on the current record, strong for a different reason than PTAB outcome: no AIA estoppel exists (§ 315(e)(2) is never triggered), the full prior-art universe remains available in district court, and the patent is recorded as Expired – Fee Related, which is a more consequential fact than any FWD would have been. Verify that last point before relying on it — see caveats.
Proceeding-by-proceeding detail
None to report. No proceeding number can be listed without fabricating one, and I will not do so. Rather than leave the section empty, here is the negative-search record:
| Source | Query applied | Result |
|---|---|---|
| USPTO ODP (canonical, per this brief) | Patent 9,934,379, AIA trials | No proceedings returned |
| PTAB PTACTS petition documents | exact 9,934,379, 9934379 |
No petition, POPR, or institution paper for this patent |
| PTAB institution-decision roundups (e.g., NYIPLA PTAB committee compilations, 2026) | proceeding lists | No 9,934,379 entry; all IPR2025-* / IPR2026-* hits unrelated |
| CourtListener / Docket Alarm (CAFC) | patent number + App. No. 14/773,660 | No appeal naming this patent |
| Unified Patents / defensive aggregator portal | patent number, "compromised computing host" | No challenge identified — no aggregator in the chain |
Claim-level outcomes: none exist. No claim of 9,934,379 has been canceled, confirmed, or disclaimed via AIA trial. Independent claims 1 (method), 12 (system), and 22 (CRM) — and all dependents 2–11 and 13–21 — are UNTESTED at the PTAB.
⚠️ Look-alike disambiguation (read this before you brief anyone)
A large share of the noise my searches surfaced belongs to different patents whose numbers or titles resemble this one. Two of these have real, extensive PTAB histories and could easily be mis-sheeted into a file:
| Reference | What it actually is | Why it is not this patent |
|---|---|---|
| U.S. 9,844,379 (Ethicon) | Endoscopic surgical stapling tool; IPR2020-00050 / -00051; FWD holding claims obvious; CAFC affirmed over a Newman dissent | Different number (9,844,379), different patent, different owner, different field |
| U.S. 10,331,379 | Memory controller timing (IPR2024-01236) | Different number |
| WO 99/34379 | 1999 French-language publication appearing in EPO search reports | Not a US patent; different century |
| U.S. 9,934,379 (this patent) | DNS-NX compromised-host detection, UNC–Chapel Hill | The one you care about — no PTAB history |
If a vendor or monitoring service has "alerted" you to IPR activity on the "379 patent," ask for the eight-digit number.
Strategic summary
Claim status. All 22 granted claims of 9,934,379 are UNSUSTAINED and UNTESTED — not because they survived challenge, but because they were never challenged. There is no FWD to point to, no certificate cancelling claims, and no IPR-narrowed claim set. Any infringement theory the patent owner might assert runs against the as-granted claims, including the narrowed independent claims 1/12/22 as issued on 2018-04-03 (the increment/decrement and "within the time period" threshold limitations that distinguish the granted claims from pre-grant publication US 2016/0026796).
Estoppel landscape. Because no IPR, PGR, or CBM was ever instituted, § 315(e)(2) estoppel never attached to anyone. This is the single most favorable structural fact for a defendant: there is no petitioner-induced limit on the prior art, no "raised or reasonably could have raised" bar, and no risk that your best § 102/§ 103 combination was already spent by someone else's petition. Any prior art you can locate — including the 14 references cited on the face of the patent (Palo Alto Networks' US 8,555,388 Heuristic botnet detection; Perdisci's US 2010/0037314; Verisign's US 2012/0047173; Narus's US 8,260,914; Microsoft's US 2011/0154359 Hash partitioning streamed data; Tibco's US 2012/0131285 Lockless spin buffer) and the substantial non-patent literature the applicant itself cited (Antonakakis 2010/2011/2012; Yadav & Reddy 2010/2011 on DNS-failure botnet detection; Jung/Paxson 2004 on sequential hypothesis testing for portscans; Wald 1947; Valois 1994 on lock-free queues) — is fully available to you. Note the practitioner's irony: the applicant's own "Crossing the Threshold" IDS material and the Yadav DNS-failure work are the closest technical neighbors, and none of it has been run through an adversarial PTAB proceeding.
Pattern signals. No repeat petitioner (there is no petitioner at all). No patent-owner appeal strategy, since there is nothing to appeal. No defensive aggregator involvement — notable, because Unified Patents and similar entities routinely target network-security and DNS-classification patents in exactly this CPC space (G06F21/56, H04L63/1441, H04L2463/144). The absence of a Unified challenge is itself consistent with an asset nobody considered worth the filing fee.
The dominant fact: the patent has lapsed. The official status is Expired – Fee Related, which in USPTO parlance means lapse for non-payment of a maintenance fee (§ 41(b) / § 41(c) territory) rather than ordinary end-of-term expiry. This matters more than any PTAB statistic:
- No prospective infringement. A lapsed patent cannot support ongoing or future infringement; injunctive relief is off the table, and no license is needed to practice the claimed method now.
- Past damages are the only exposure, and only for infringement occurring (a) before lapse and (b) within the six-year lookback of 35 U.S.C. § 286 — but a pre-suit notice/complaint is also required for pre-suit damages on a method claim (§ 287), which is a further, often fatal, hurdle where there is no marking.
- Revival is the only way back. Under § 41(c), a lapse is revivable only on a petition showing unintentional (or, outside the statutory window, unavoidable) delay. I have not verified whether UNC filed such a petition, and you must check this — PatentCenter "Patent Status" / "Maintenance Fee" and the assignment/transaction documents are the place to confirm. If the revival window has closed, the asset is permanently dead and any demand letter citing it is hollow.
Reconciliation flag with prior sections. Two points of internal tension, surfaced rather than silently incorporated:
- Record date mismatch. The prior summary and litigation sections are dated 2026-04-26; today's date is 2026-09-30. The findings agree (no litigation, no IPR, no appeals), so there is no substantive contradiction — but the litigation section's certification is now ~5 months stale. Given that a lapsed patent can be revived at any time within the statutory window, the staleness is material to the revival question, not cosmetic.
- Status vs. term mismatch. The bibliographic table lists both "Expired – Fee Related" and "adjusted expiration March 15, 2034." These are not contradictory on their face (the 2034 date is the nominal PTA-adjusted term; the status reflects an earlier lapse for non-payment), but they cannot both describe an enforceable patent. Google's own disclaimer applies: the legal status is an assumption, not a legal conclusion. Do not brief the 2034 date as though the patent were live.
Recommended next steps
For a defendant currently facing assertion or a demand letter:
- Verify the lapse first, before doing anything else. Pull the maintenance-fee history on USPTO PatentCenter for 14/773,660 and confirm (a) which maintenance fee was missed, (b) whether a § 41(c) revival petition was filed, and (c) whether the patent has been reinstated. If the patent is lapsed and unreinstated, the correct response to a demand letter is a short letter identifying the lapse and demanding withdrawal — with prejudice and covered by Rule 11 — rather than an invalidity or non-infringement analysis.
- If it has been revived, or if only past damages are in play, you have an unusually clean slate: no § 315(e)(2) estoppel, no FWD findings to overcome, and the full prior-art set untouched. The patentee's own cited art (Jung/Paxson 2004 sequential hypothesis testing; Yadav & Reddy 2010/2011 DNS-failure botnet detection; Antonakakis et al. 2010–2012) is fair game and was never adversarially tested.
- Consider whether a challenge is even worthwhile. Because an IPR can be filed against an expired patent (no amendment option, and the Board can still cancel claims), an IPR remains technically available — but its only value is future-facing estoppel/clarity for other patents in the family or a related portfolio, or defensive publication value. On a lapsed patent with no damages exposure, the cost-benefit usually favors doing nothing. Conversely, if the patent is live and being asserted, an IPR filed now would carry no General Plastic / § 314(a) Fintiv baggage from prior petitions, because there are none — but the post-Revno discretionary-denial environment (precedential as of 2025-11-03) still requires a clean parallel-litigation story.
- Rule out the family. The sibling PCT WO 2014/138205 A2/A3 is itself marked "not_active — Ceased." If the assertion is portfolio-wide, confirm whether any continuation, divisional, or foreign counterpart (EP, if nationalized) is live. Note explicitly: a "ceased" PCT status is a prosecution/lapse status and must not be coded as litigation or as a PTAB outcome.
Bottom line for the file: There is no PTAB proceeding to brief. The patent has never been challenged at the Board, so it is neither validated nor invalidated by anything the Board has done. The live question is not "what did the PTAB hold?" but "has UNC revived a lapsed patent?" — and that is a PatentCenter maintenance-fee answer, not a PTAB E2E answer. Search the canonical dockets here: USPTO PTAB E2E and CourtListener — both return nothing for 9,934,379, which is the finding.
Generated 9/30/2026, 6:02:31 PM
Ownership chain (1)
Asserters network →Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.
2014-03-31 · recorded 2014-04-14 · reel 32665/0681 · Assignment
Monrose, Fabian; Taylor, Teryl; Krishnan, Srinivas; McHugh, JohnThe University of North Carolina at Chapel Hill
inventor-to-institution
Assignment history
Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.
I'll verify the assignment chain against USPTO records and cross-reference sources before drafting.
Let me pull the full assignment record and check for any additional recordings.
Assignment & Ownership Chain — U.S. Patent No. 9,934,379 B2
Patent: Methods, systems, and computer readable media for detecting a compromised computing host
App. No.: 14/773,660 (U.S. national stage of PCT/US2014/020683) • Issued: 2018-04-03
Verification anchor: USPTO Assignment Center / Assignments on the Web, patent no. 9,934,379 → https://assignment.uspto.gov/patent/index.html#/patent/search/results?q=9934379 (indexed mirror of the same underlying Reel/Frame records at https://www.plainsite.org/patents/assignment.html?id=[8160840](/patent/8160840))
Inventors
| Inventor | Correspondence address of record (as printed on the patent) | Employer at time of filing (best determination) |
|---|---|---|
| Fabian Monrose | Chapel Hill, NC | University of North Carolina at Chapel Hill — Dept. of Computer Science (faculty) |
| Teryl Taylor | Carrboro, NC | UNC Chapel Hill — graduate researcher (Dept. of Computer Science) |
| Srinivas Krishnan | Berkeley, CA | UNC Chapel Hill PhD alumnus; by the 2014 filing his correspondence address is Berkeley, CA (consistent with a post-UNC research affiliation, e.g., ICSI), while the underlying work is UNC-labelled |
| John McHugh | Saluda, NC | UNC Chapel Hill — Dept. of Computer Science (faculty) |
Unusual patterns — assessed:
- Only one inventor shows a non-North-Carolina address. Krishnan's "Berkeley, CA" correspondence address is the sole mobility flag. It is not the "all inventors departed within 12 months" pattern: three of four inventors remained anchored to the Triangle area, and — critically — every inventor signed the assignment in March 2014, before the PCT filed, and each had a continuing UNC obligation (all four appear as co-authors on the UNC-labelled paper "Crossing the Threshold," DSN 2013, which is the Non-Patent Citation at the top of the patent's reference list). No inventor-to-third-party assignment, no inventor buy-back, and no inventor-recorded security interest exists on this property.
- No post-filing inventor departures are visible in the record. The chain contains no document that transfers any inventor's interest to anyone other than UNC.
- This is a single-lab, single-institution academic invention, not a portfolio assembled for disposition.
Original assignee
The University of North Carolina at Chapel Hill — Chapel Hill, NC (103 South Building, Chapel Hill, NC 27599). The patent's front page names "University of North Carolina at Chapel Hill" as both original and current assignee, and the grant carries a government-interest statement: made with NSF support under Grant No. OCI-1127361 (the government retains certain rights).
- Line of business: public research university (educational institution, per UNC's own trademark filings). Not a product company.
- Did it ship a product embodying the claims? No. The specification describes a research-instrument deployment — a Data Acquisition and Generation (DAG) card tapped into a campus border link, feeding a multi-core, lock-free packet pipeline for DNS-NX classification. That is a laboratory/field-test apparatus, not a commercial offering. There is no evidence of a UNC-licensed product, no SEC filing (UNC is a public institution with no 10-K/8-K disclosure obligation), and no product literature tied to the patent.
- Current status: Operating (public university, no bankruptcy, no dissolution, no acquisition). The university continues to commercialize through its tech-transfer arm rather than by asserting patents.
Corroborating negative on the assignee side: the family's PCT counterpart WO 2014/138205 A2/A3 is marked "not_active — Ceased" (prosecution/lapse status, not a legal proceeding), and the issued U.S. patent lapsed Expired – Fee Related with an adjusted expiration of 2034-03-15. A fee lapse by a well-resourced institutional owner is an economic signal of low enforcement value — see the NPE section.
Assignment timeline
There is exactly one recorded assignment for this patent. A direct check of the patent's own legal-events table (which lists every reassignment entry USPTO has recorded against the property) shows a single reassignment event, so the timeline below is complete as recorded.
- 2014-03-11 (McHugh) / 2014-03-26 (Krishnan) / 2014-03-31 (Monrose) / Taylor executed on the same instrument — recorded 2014-04-14 — Reel 32665/0681
- Conveyance: Assignment — "Assignment of Assignors' Interest" (recorded nature of conveyance: ASSIGNMENT; the reel-indexed short title is the generic "ASSIGNMENT OF ASSIGNORS INTEREST (SEE DOCUMENT FOR DETAILS)")
- Assignor(s): Monrose, Fabian; Taylor, Teryl; Krishnan, Srinivas; McHugh, John (each individually, jointly and severally)
- Assignee: The University of North Carolina at Chapel Hill, 103 South Building, Chapel Hill, NC 27599
- Correspondent of record: Not retrievable in this session. The PlainSite mirror of Reel 32665/0681 exposes a "Correspondent" column, but the correspondent name/address was not returned by the retrieval I was able to perform. I will not guess it. This is the one field of the requested matrix I could not fill, and it should be read directly off the Reel 32665/0681 cover sheet via the USPTO link above before any client relies on this section.
- Context: Routine, pre-filing, inventor-to-institution assignment. Executed by each inventor before the 2014-03-05 PCT filing ticked into national stage, to perfect the university's title per standard employment/IP policy. This is the opposite of a fire-sale: nothing was sold, nothing changed hands commercially, and the instrument predates any product or any assertion.
- Recurrence flag: Cannot be raised or cleared — with only one link in the chain there is no second entry to compare a correspondent across. ✅ No repeat-correspondent finding is possible on this patent in isolation.
No other records exist for this patent: no security agreement, no merger, no change of name, no release, no license recordation, no correction, and — most importantly — no second assignment. The chain terminates at the original assignee.
Timeline diagram
timeline
title Ownership of US 9934379
2013 : Provisional 61772905 filed
2014 : Inventors execute assignment to UNC
: PCT filed 5 March 2014
: Assignment recorded 14 April 2014
2016 : Pre-grant publication 20160026796
2018 : Patent issued 3 April 2018
2034 : Adjusted expiration 15 March 2034
NPE / troll-pattern signals
| # | Signal | Call | Evidence (reel/frame, dates) |
|---|---|---|---|
| 1 | Shell-entity transfer | Not present | The sole assignee is a named public university at a campus street address (103 South Building, Chapel Hill, NC 27599) — Reel 32665/0681. No "IP/Holdings/Ventures/Licensing" entity appears anywhere in the chain, and no registered-agent-service address is of record. |
| 2 | Known asserter in the chain | Not present | No assignee in the chain matches Acacia, Marathon, IV, IPNav, Wi-LAN, Mosaid/Conversant, Vringo, Pendrell, Innovatio, MPHJ, Lumen View, Round Rock, Document Generation Corp, or any Spangenberg vehicle. The only assignee is UNC. Independent litigation/PTAB checks in the prior sections returned nothing for 9,934,379. |
| 3 | Repeat correspondent across the chain | Unclear / not assessable | Impossible to evaluate — one link only, and the Reel 32665/0681 correspondent name was not retrieved (see above). A single appearance is not a signal in any event; the signal requires recurrence. No finding. |
| 4 | Cascading transfers < 24 months | Not present | There is no second transfer, let alone a cascade. The single assignment (Reel 32665/0681, rec. 2014-04-14) is the first and last recorded event. |
| 5 | Pre-litigation transfer (≤6 months before suit) | Not present | No infring |
Generated 9/30/2026, 6:02:22 PM
Prior art
Earlier patents, publications, and products that may anticipate or render the claims unpatentable.
I'll research the cited references for US 9,934,379 to assess their prior-art relevance under 35 U.S.C. § 102. Let me start with the patent citations.
Let me research the remaining patent citations.
Prior-Art Analysis — U.S. Patent No. 9,934,379 B2
Patent under analysis: "Methods, systems, and computer readable media for detecting a compromised computing host"
Critical date: March 5, 2013 (provisional 61/772,905 priority; PCT/US2014/020683 filed March 5, 2014; U.S. national stage 14/773,660 filed Sept. 8, 2015)
Independent claims: 1 (method), 12 (system), 22 (non-transitory CRM) — each requiring (i) receipt, within a time period, of DNS NX messages for a host; (ii) a host score tied to unique DNS zones/names; (iii) +1 for a unique / −1 for a non-unique zone; (iv) compromise when the score reaches/exceeds a threshold within the time period; and (v) a mitigation action.
Framing note. Because the provisional was filed before the March 16, 2013 AIA changeover, the disclosure may be entitled to a pre-AIA effective date, so pre-AIA § 102(a)/(b)/(e)/(g) governs. Under that framework the statutory-bar date is March 5, 2013 (one year before the international filing date). References published on or before March 5, 2013 are § 102(a)/(b) art; references published after but filed before that date are § 102(e) art. I flag where each reference falls.
Legal caveat. Anticipation under § 102 requires a single reference to disclose every limitation of a claim, arranged as in the claim. As discussed below, no cited reference appears to disclose the complete combination of claim 1, so several are better characterized as § 103 (obviousness) art or as § 102 art against narrow dependent claims. I present each as the user requested ("which claim(s) it potentially anticipates") while flagging the limits of a true § 102 case.
Part A — The 14 Patent Citations
1. US 6,892,163 B1 — "Surveillance system and method having an adaptive sequential probability fault detection test"
- Full citation: U.S. Patent 6,892,163 B1, inventors James P. Herzog & Randall L. Bickford, assignee Intellectual Assets LLC (NASA/Argonne-funded).
- Dates: Filed March 8, 2002; granted May 10, 2005 → § 102(b) art.
- Description: Applies an Adaptive Sequential Probability (ASP) test — a generalization of Wald's SPRT to non-Gaussian PDFs — to residuals from process/sensor signals (nuclear, industrial asset surveillance). Uses likelihood ratios compared to upper/lower log-thresholds to decide "faulted / normal / continue."
- Potential § 102 relevance: Claims 6–7 (determining compromise "using sequential hypothesis testing," including parameters). This is a § 102(a)/(b) reference for the statistical technique itself, but it discloses nothing about DNS, NX messages, per-host zone-uniqueness scoring, or host compromise. It is at most a building block for a § 103 combination against claims 6–7, not an anticipator of claim 1.
2. US 2009/0083413 A1 — "Distributed frequency data collection via DNS"
- Full citation: U.S. Pub. 2009/0083413 A1, inventor Zachary S. Levow.
- Dates: Filed Sept. 24, 2007; published March 26, 2009 → § 102(b) art.
- Description: Collects frequency/statistical data about domain-name usage through the DNS infrastructure (distributed DNS-based data collection/reporting).
- Potential § 102 relevance: Background art only. It concerns DNS data aggregation, not host compromise detection or uniqueness scoring. No claim mapping.
3. US 2010/0037314 A1 — "Method and system for detecting malicious and/or botnet-related domain names"
- Full citation: U.S. Pub. 2010/0037314 A1, inventors Perdisci & Lee, assignee Damballa, Inc. (provisional filed Aug. 11, 2008; non-provisional Aug. 10, 2009; later granted as US 10,027,688).
- Dates: Published Feb. 11, 2010 → § 102(b) art.
- Description: Passive-DNS sampling → filtering → suspiciousness-score ranking based on query volume vs. distinct source IPs → information search → classification of domain names as malicious/suspicious/legitimate using white/black-lists, IP reputation, and search-engine results.
- Potential § 102 relevance: Claims 4 and 14 (unique DNS zone/name "indicative of malicious activity"). It scores domain names, not hosts, and it does not use a per-host ±1 uniqueness counter. § 103 art at best; not an anticipator of the independent claims.
4. US 2011/0154359 A1 — "Hash partitioning streamed data"
- Full citation: U.S. Pub. 2011/0154359 A1, assignee [Microsoft Corp.](/litigations/by-plaintiff/Microsoft%20Corp.)
- Dates: Filed Dec. 18, 2009; published June 23, 2011 → § 102(b) art.
- Description: Partitions a streamed data flow across processing nodes/partitions using hashing (e.g., for parallel, load-balanced stream processing).
- Potential § 102 relevance: Claims 8–9 and 18–19 (parallel processing / lock-free data structure for analyzing many streams). It discloses parallel partition-based stream handling but not a lock-free structure, and nothing about DNS/host compromise. § 103 art only.
5. US 2011/0185422 A1 — "Method and system for adaptive anomaly-based intrusion detection"
- Full citation: U.S. Pub. 2011/0185422 A1, assignee School of Electrical Eng. & Computer Science (SEECS), National University of Sciences & Technology.
- Dates: Filed Jan. 22, 2010; published July 28, 2011 → § 102(b) art.
- Description: Adaptive, anomaly-based intrusion detection — behavioral profiling with adaptive thresholds to flag deviations.
- Potential § 102 relevance: Claim 6 (anomaly/hypothesis-based detection) and general threshold-based classification. Not DNS-NX-specific; no host-score ±1 mechanics. § 103 art.
6. US 2011/0197278 A1 — "Containment mechanism for potentially contaminated end systems"
- Full citation: U.S. Pub. 2011/0197278 A1, inventors Chow, Robert, McNamee, Wiemer, McFarlane; assignee Alcatel Lucent (granted as US 8,020,207 B2 on Sept. 13, 2011).
- Dates: Filed Jan. 23, 2007; published Aug. 11, 2011; granted Sept. 13, 2011 → § 102(b) art.
- Description: Malware Detection & Response (MDR) system embedded at network edge devices (switches, ISAM, DSLAM). Counts/monitors control-plane PDUs (ARP, TCP/SYN, DNS/NETBEUI name lookups, ICMP), and an "attack identification and containment" (AIC) unit applies limits tables to identify and contain suspicious end systems.
- Potential § 102 relevance: Claims 10 and 20 (mitigation/containment actions — discarding, rerouting, reporting). Notably it monitors DNS lookups and contains hosts, but it does not score unique NX zones. Relevant as § 103 art for the mitigation limitation and for edge-based monitoring, not as an anticipator of claim 1.
7. US 2012/0047173 A1 — "Method of and Apparatus for Identifying Requestors of Machine-Generated Requests to Resolve a Textual Identifier"
- Full citation: U.S. Pub. 2012/0047173 A1 (related to Ser. No. 12/763,349, filed Apr. 20, 2010), assignee VeriSign, Inc.
- Dates: Filed April 20, 2010; published Feb. 23, 2012 → § 102(b) art.
- Description: Logs requests to resolve NXDomains; identifies a unique set of unresolvable textual identifiers for a given time period; classifies them into taxonomical sets; maintains a mapping of requestor → frequency counts of NXDomains per taxonomic set; and applies heuristics/statistics to identify requestors exhibiting a threshold level of machine-generated traffic (bots).
- Potential § 102 relevance — CLOSEST CITED PATENT ART. This reference speaks directly to the core of claim 1: per-requestor tracking of unique unresolved domains within a time period, with a threshold determination that a requestor is generating machine/bot traffic, plus a scoring mechanism. It is the strongest § 102(a)/(b) candidate for claim 1 and its system/CRM counterparts (claims 12, 22). The residual gap is element (iii): the pub uses frequency counts and heuristics, whereas claim 1 recites a score incremented (+1) for a unique zone and decremented (−1) for a non-unique zone. Unless that specific ±1 mechanic is read into the reference, true anticipation is arguable and the better posture is § 103 over US 2012/0047173 (optionally combined with an SPRT reference such as item 1 or Wald). This is the reference a challenger or a claim-drafter should focus on.
8. US 2012/0131285 A1 — "Locking and signaling for implementing messaging transports with shared memory"
- Full citation: U.S. Pub. 2012/0131285 A1, assignee Tibco Software Inc.
- Dates: Filed Nov. 16, 2010; published May 24, 2012 → § 102(b) art.
- Description: Shared-memory messaging transport with locking/signaling mechanisms for concurrent producers/consumers.
- Potential § 102 relevance: Claims 8–9, 18–19 (shared-memory / concurrent stream processing). It teaches shared-memory messaging with locking/signaling — the opposite emphasis from the claimed lock-free structure. § 103 art.
9. US 2012/0174220 A1 — "Detecting and mitigating denial of service attacks"
- Full citation: U.S. Pub. 2012/0174220 A1, assignee VeriSign, Inc.
- Dates: Filed Dec. 31, 2010; published July 5, 2012 → § 102(b) art.
- Description: Detects DoS/DDoS conditions in DNS traffic and mitigates them (throttling, dropping, redirecting), using traffic statistics.
- Potential § 102 relevance: Claims 10 and 20 (mitigation of DNS-borne attacks). No host-uniqueness scoring. § 103 art.
10. US 8,260,914 B1 — "Detecting DNS fast-flux anomalies"
- Full citation: U.S. Patent 8,260,914 B1, assignee Narus, Inc.
- Dates: Filed June 22, 2010; granted Sept. 4, 2012 → § 102(b) art.
- Description: Detects fast-flux behavior (rapidly changing A-records) by analyzing DNS response patterns/statistics.
- Potential § 102 relevance: Background art on DNS-traffic anomaly detection. It addresses domain/IP flux, not per-host unique-NX scoring. § 103 art for contextual subject matter.
11. US 2013/0014253 A1 — "Network Protection Service"
- Full citation: U.S. Pub. 2013/0014253 A1, inventor Vivian Neou.
- Dates: Filed July 6, 2011; published Jan. 10, 2013 → § 102(a)/(b) art.
- Description: A network protection service (DNS-based security/reputation and traffic analysis for network operators).
- Potential § 102 relevance: General background on network/DNS protection services. No specific host-scoring disclosure identified. § 103 art / background.
12. US 2013/0166571 A1 — "Evaluating typeability of domain names"
- Full citation: U.S. Pub. 2013/0166571 A1, assignee VeriSign, Inc.
- Dates: Filed Dec. 23, 2011; published June 27, 2013 → published after the March 5, 2013 critical date but filed before it → § 102(e) art.
- Description: Scores domain names by "typeability" (likelihood a human would type them), useful for distinguishing human-generated from algorithmically generated names.
- Potential § 102 relevance: Claim 4 (unique/algorithmically generated name indicative of malicious activity) — but it analyzes name properties, which the specification expressly distinguishes from its traffic-pattern approach. § 102(e)/§ 103 art.
13. US 8,555,388 B1 — "Heuristic botnet detection"
- Full citation: U.S. Patent 8,555,388 B1, inventors Wang et al., assignee Palo Alto Networks, Inc. (family pub. US 2014/0090059 A1).
- Dates: Filed May 24, 2011; granted Oct. 8, 2013 → granted after the critical date but filed before it → § 102(e) art.
- Description: Monitors network traffic to detect botnet/C&C activity heuristically; assigns a severity score to monitored traffic corresponding to a probability it is botnet-related, increments the score as additional suspicious-behavior indicators are matched, and decides botnet association based on the score. Uses multi-core CPU, FPGA and other hardware.
- Potential § 102 relevance: Claims 1, 12, 22 (score-based botnet classification) and 21 (multi-core/hardware). This is the second-strongest cited patent reference because it discloses (a) monitoring traffic to find compromised/bot hosts and (b) a running, incremented score compared against a criterion. Critically, however, it does not key the score to unique DNS NX zones (±1 for unique vs. non-unique), which is the point of novelty in claim 1. Strong § 103 art; a plausible § 102(e) attack only if the "severity score" is mapped to the claimed host score, which is a stretch given the DNS-NX limitation.
14. US 2014/0089539 A1 — "Lockless spin buffer"
- Full citation: U.S. Pub. 2014/0089539 A1, assignee SAP AG.
- Dates: Filed Sept. 24, 2012; published March 27, 2014 → published after the critical date but filed before it → § 102(e) art.
- Description: Lock-free ("lockless") ring/spin buffer for high-throughput inter-thread/inter-process data exchange.
- Potential § 102 relevance: Claims 8–9, 18–19 (lock-free data structure for parallel stream processing). Discloses a lock-free buffer generally but nothing about DNS or host compromise. § 102(e)/§ 103 art for the lock-free limitation.
Part B — Key Non-Patent Literature (39 citations of record)
Several NPL references are highly material and, because they pre-date March 5, 2013, are § 102(a)/(b) printed publications. The three most relevant to the core claim:
| Ref. | Publication date | Why it matters |
|---|---|---|
| Yadav & Reddy, "Winning with DNS Failures: Strategies for Faster Botnet Detection," SecureComm 2011 | 2011 → § 102(b) | Detects bots from DNS NX/failure traffic; closest NPL analogue to the traffic-pattern premise of claim 1. |
| Yadav, Reddy, Reddy & Ranjan, "Detecting Algorithmically Generated Malicious Domain Names," IMC 2010 | 2010 → § 102(b) | AGD detection; supports claims 4/14 (unique/generated names indicative of malice). |
| Jung, Paxson, Berger & Balakrishnan, "Fast Portscan Detection Using Sequential Hypothesis Testing," IEEE S&P 2004 | 2004 → § 102(b) | The canonical application of SPRT/sequential hypothesis testing to network anomaly detection — the template § 102(b)/§ 103 reference for claims 6–7. |
| Antonakakis et al., "From Throw-Away Traffic to Bots (DGA-based Malware)," USENIX Security 2012 | 2012 → § 102(b) | DGA/NX-domain bot detection; background for the NX-uniqueness insight. |
| Bilge et al., "EXPOSURE: Finding Malicious Domains using Passive DNS Analysis," NDSS 2011 | 2011 → § 102(b) | Passive-DNS feature-based domain classification. |
| Antonakakis et al., "Building a Dynamic Reputation System for DNS" (2010); "Detecting Malware Domains at the Upper DNS Hierarchy" (2011) | 2010/2011 → § 102(b) | DNS reputation / upper-hierarchy malware-domain detection. |
| Hao, Feamster & Pandrangi, "Monitoring the Initial DNS Behavior of Malicious Domains," IMC 2011 | 2011 → § 102(b) | Initial DNS behavior of malicious domains. |
| Schechter, Jung & Berger, "Fast Detection of Scanning Worm Infections," RAID 2004; Ho et al., "…Sequential Hypothesis Testing," IEEE TMC 2011 | 2004/2011 → § 102(b) | Sequential hypothesis testing for infection detection (claims 6–7). |
| Wald, Sequential Analysis (1947) | 1947 → § 102(b) | Foundational SPRT text recited in the specification. |
| Valois, "Implementing Lock-Free Queues," PDCS 1994 | 1994 → § 102(b) | The lock-free data structure relied on for claims 8–9/18–19. |
| Villamarín-Salomón & Brustoloni, "Identifying Botnets Using Anomaly Detection Techniques Applied to DNS Traffic," CCNC 2008 | 2008 → § 102(b) | Botnet detection directly from DNS traffic. |
Note on the inventors' own paper. "Crossing the Threshold: Detecting Network Malfeasance via Sequential Hypothesis Testing" (listed as (2013)) appears to be the inventors' own publication (ACSAC 2013). If its public date is after the March 5, 2013 priority date, it is not § 102 prior art and/or falls within the grace period; I flag this because it is often miscoded as prior art. The remaining NPL (Sommer et al. multi-core NIPS architecture, Born & Gustafson DNS tunnels, Felegyhazi proactive blacklisting, Duda Pattern Classification, etc.) are background/§ 103 support.
Part C — Overall Ranking and Bottom Line
Closest / most material prior art to the independent claims:
- US 2012/0047173 A1 (VeriSign, NXDomain requestor identification) — § 102(b). Discloses per-requestor tracking of unique unresolved domains within a time period and a threshold decision that the requestor is machine/bot-generated. Best § 102(a)/(b) candidate for claim 1 / 12 / 22, subject to the ±1-uniqueness-score gap (more likely § 103).
- US 8,555,388 B1 (Palo Alto, heuristic botnet detection) — § 102(e). Discloses traffic monitoring with a running, incremented score and threshold-based bot classification; strong § 103 art, weaker § 102.
- Yadav & Reddy (SecureComm 2011) and the Jung et al. / Wald SPRT line — § 102(b). Together they supply the DNS-failure detection premise and the sequential-hypothesis-testing mechanism (claims 1 and 6–7).
Remaining references (items 1, 2, 4, 5, 8, 9, 10, 11, 12, 14 above) map only to narrow dependent limitations (lock-free structures, mitigation types, DAG/GPU implementation, domain-name typeability) or are general background; none anticipates claim 1.
Bottom line. On the citations of record, the patent's inventive weight rests on the combination: (a) DNS NX-only traffic, (b) a per-host score that moves +1 for a never-seen zone / −1 for a repeat zone, and (c) a threshold-within-a-time-period decision (optionally via SPRT). No single cited reference discloses all three arranged as in claim 1; US 2012/0047173 and US 8,555,388 come closest and would anchor an obviousness challenge, while the SPRT and DNS-failure NPL supply the statistical and domain-of-application elements. A true § 102 anticipation of claim 1 was not found among the references of record.
Confidence/caveats. I verified the content of items 1, 3, 6, 7, and 13 directly from their publications; descriptions of items 2, 4, 5, 8–12, and 14 are drawn from their titles/abstracts and the patent's own citation list and are stated at correspondingly lower confidence. I could not independently confirm every publication date via a live source for items 2, 4, 5, 8–12, 14 before the tool limit was reached. Dates shown for US 2010/0037314 reflect the family (provisional Aug. 11, 2008; non-provisional Aug. 10, 2009; publication Feb. 11, 2010) and merit a primary-source double-check. This analysis addresses § 102 only; a full invalidity opinion would also develop § 103 combinations and confirm each reference's actual disclosure page-by-page.
Generated 9/30/2026, 6:02:53 PM
Obviousness
Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.
I'll ground the prior-art characterizations before building the obviousness analysis.
Let me verify the SPRT mechanics of the Jung/Wald references and the Pleiades NXDOMAIN work.
Obviousness Analysis — U.S. Patent No. 9,934,379 B2 under 35 U.S.C. § 103
Prepared: April 26, 2026 | Patent at issue: US 9,934,379 B2, Methods, systems, and computer readable media for detecting a compromised computing host (UNC–Chapel Hill; filed Mar. 5, 2014; priority Mar. 5, 2013; issued Apr. 3, 2018; expired–fee related).
Primary source used: the "Prior Art" section of the patent page (14 patent citations; 39 non-patent citations), corroborated by Google Patents / Justia / USENIX / ACM records.
Scope note / discipline. This is an attorney-style obviousness assessment built on (a) the references cited on the face of the patent, and (b) verified public descriptions of those references. I did not run a fresh prior-art search, and I have not read every reference end-to-end. Where I characterize a reference's teaching I cite the source; where a characterization rests on the reference's abstract or claim text rather than full-text review, I say so. Patent numbers and identifiers are taken literally as printed.
1. Governing framework
Statute. Because the application claims priority to a provisional filed March 5, 2013 — before the March 16, 2013 AIA transition — and the PCT/national stage was filed March 5, 2014, the patent is presumptively governed by pre-AIA 35 U.S.C. § 103(a). The substantive test is materially the same under AIA § 103.
Critical date. For a printed publication to be § 102(b) art, it must predate March 5, 2013 (one year before the U.S. filing) — or, if the provisional's benefit is challenged, March 5, 2012. Almost every key reference below predates March 5, 2012, so they qualify under any view of the critical date. I flag dates individually.
Standard. Graham v. John Deere (scope/content of art; differences; PHOSITA level; secondary considerations) as refined by KSR Int'l v. Teleflex: the TSM test is a flexible inquiry; a combination is obvious where the improvement is a predictable use of prior-art elements according to known methods to yield a predictable result, or where the combination is "obvious to try" from a finite number of identified, predictable solutions.
2. Person having ordinary skill in the art (PHOSITA)
A PHOSITA here would be a network-security engineer/researcher with (i) a graduate-level or equivalent working knowledge of DNS protocol behavior, (ii) familiarity with statistical anomaly/intrusion detection, including sequential hypothesis testing as taught by Wald and applied to network telemetry by Jung et al., and (iii) ordinary skill implementing multi-core packet-analysis pipelines (lock-free structures, DAG/NIC capture). This is a research-grade but well-populated field: by 2012–2013 the DNS-malware-detection literature cited on the patent's own face (Antonakakis, Yadav, Bilge, Perdisci, Dagon) was extensive.
3. The prior-art landscape (as cited on the patent)
| Ref. | Teaching (verified) | Prior-art date |
|---|---|---|
| Yadav & Reddy, "Winning with DNS Failures: Strategies for Faster Botnet Detection," SecureComm 2011 | Bots "query a large number of domains, some of which may fail"; failed (NXDOMAIN) queries are used to speed botnet detection and locate C&C; validated on a Tier-1 ISP and campus traces; "can be applied at the edge of an autonomous system for real-time detection." (eudl.eu) | Sept. 2011 → § 102(b) |
| Antonakakis et al. (Pleiades), "From Throw-Away Traffic to Bots: Detecting the Rise of DGA-Based Malware," USENIX Security 2012 | Monitors streams of NXDomain responses; clusters domains by name-structure and by the set of machines that queried them; detects bot-compromised machines; identifies and blocks the C&C domains; "lightweight DNS-based monitoring." (usenix.org) | Aug. 2012 → § 102(b) |
| *Yadav et al., "Detecting Algorithmically Generated Malicious Domain Names," IMC 2010; and IEEE/ACM ToN 2012* | Counts/characterizes distinct algorithmically generated domains per host; the ToN paper is expressly "agenerated domain-flux attacks with DNS traffic analysis." | § 102(b) |
| Jung, Paxson, Berger & Balakrishnan, "Fast Portscan Detection Using Sequential Hypothesis Testing," IEEE S&P 2004 ("TRW"/Threshold Random Walk) | SPRT applied to network detection. Models benign vs. malicious host behavior as two processes; per observation computes a likelihood ratio updated on each success/failure; compares to an upper and lower threshold; if between them, continue observing; classifies in 4–5 observations. Parameters θ₀/θ₁ are the per-process success probabilities. (scilit) | 2004 → § 102(b) |
| Wald, Sequential Analysis (1947) | Foundational SPRT — the score/threshold framework itself. | 1947 → § 102(b) |
| US 8,555,388 B1 (Palo Alto Networks), "Heuristic botnet detection" | Monitors network traffic and "visiting a non-existent domain" is an enumerated malware/botnet behavior; assigns/increases a score correlated across suspicious behaviors; determines botnet membership when the score falls within a value range; performs a responsive action (firewall block, monitor, reporting). (freepatentsonline; justia) | Filed May 24, 2011 → § 102(e) |
| Perdisci, US 2010/0037314 A1 (+ Notos USENIX 2010; Kopis USENIX 2011) | Detecting malicious/botnet-related domain names and the hosts that query them. | § 102(b)/§102(e) |
| US 2009/0083413 A1 (Levow), "Distributed frequency data collection via DNS" | Frequency/occurrence data collected over DNS — frequency counting of domain lookups. | § 102(b) |
| US 2012/0047173 A1 (Verisign) | Identifying requestors of machine-generated requests to resolve a textual identifier. | § 102(b) |
| US 2011/0197278 A1 (Alcatel-Lucent) | Containment mechanism for potentially contaminated end systems (quarantine/mitigation). | § 102(b) |
| US 6,892,163 B1 (Intellectual Assets) | Adaptive sequential probability fault-detection test. | 2005 → § 102(b) |
| US 2014/0089539 A1 (SAP), "Lockless Spin Buffer"; US 2011/0154359 A1 (Microsoft), "Hash partitioning streamed data"; Valois, "Implementing Lock-Free Queues" (1994); Sommer et al. (2009) | Lock-free/parallel packet-processing structures and multi-core NIDS pipelines. | § 102(e)/§ 102(b) |
Two threshold observations:
- The patent's own specification concedes the field: it cites Yadav [32], Pleiades [4], and Jung [18] by name and states that "sequential hypothesis testing [
30] may be used to classify hosts as compromised based on observations of unique DNS NX messages." That sentence is, functionally, a roadmap of the claimed invention built from cited art. - This is not a § 102 case — no single reference appears to disclose all elements. The case is a § 103 combination case, and the strongest combination pairs the DNS-NX signal (Yadav/Pleiades) with the SPRT scoring mechanism (Jung/Wald).
4. Element-by-element mapping of claim 1
Claim 1 (granted) requires: (a) receiving, within a time period, DNS NX messages for a host; (b) determining compromise using a host score tied to unique DNS zones/domains, where the score is adjusted up/down based on whether the zone was seen before, incremented for unique and decremented for non-unique, and the determination is whether the score reaches/exceeds a threshold within the time period; (c) a mitigation action.
| Claim 1 element | Primary reference(s) | Mapping |
|---|---|---|
| Receive DNS NX messages associated with a host, within a time period | Yadav 2011; Pleiades 2012 | Both operate on per-host NXDOMAIN streams; Yadav explicitly frames real-time edge deployment. "Time period" is inherent to any windowed/streaming DNS monitor and is expressly described in the patent itself as tracking "for a set window of time." |
| Host score associated with unique zones/domains | Yadav 2011 / Yadav IMC-2010 / Pleiades | To count distinct/NX-domains per host (Yadav) or cluster domains per querying host (Pleiades), the system must decide, for each queried domain, whether the host has seen it before — i.e., the unique vs. non-unique determination. |
| Score adjusted up or down per observation; +1 unique / −1 non-unique | Jung 2004 / Wald 1947 | TRW maintains a running likelihood-ratio score that moves up on a "success" and down on a "failure", with step sizes determined by θ₀ and θ₁. The patent's spec adopts verbatim this structure ("an amount to adjust … a host score may be determined by the values θ₀ and θ₁"). Substituting "zone seen before = success / new zone = failure" for "connection completed = success / failed = failure" is a predictable relabeling of the same random walk. |
| Threshold within the time period | Jung/Wald; US 6,892,163; US 8,555,388 | Jung compares Λ(Y) to η₀/η₁; the patent uses the identical η₀ ≤ Λ(Y) ≤ η₁ decision rule. '388 teaches decision by score falling within a value range; '163 teaches adaptive sequential probability thresholding. |
| Mitigation action | '388 (firewall block/monitor/report); Pleiades (block C&C domains); US 2011/0197278 (containment) | Expressly disclosed in each. |
Conclusion on claim 1: every element is disclosed, and the only "new" aspect — using zone novelty (rather than connection success) as the binary outcome fed to an SPRT random walk — is a substitution of one known binary classifier input for another in a known statistical framework, producing the predictable result the references themselves promise (fast, low-false-positive classification). Independent claim 12 (system: processor + CHD module) and claim 22 (non-transitory CRM) recite the same steps and are obvious for the same reasons; claim 12's "processor" and claim 22's "instructions" add nothing patentable over a general-purpose computer executing the claim-1 method.
5. The combinations
Combination A (strongest): Yadav & Reddy 2011 + Jung et al. 2004 (via Wald 1947), optionally + Pleiades 2012
What each contributes. Yadav supplies the signal and the domain of application: DNS NXDOMAIN responses, aggregated per host, effectively distinguish bot-infected machines from benign ones, and the technique is lightweight and edge-deployable. Pleiades reinforces that NXDomain streams permit identification of compromised machines and blocking of C&C domains. Jung/Wald supply the classifier: a per-observation score incremented on one outcome and decremented on the other, compared to an upper and lower threshold, with a "continue observing" band — literally the "host score … reaches or exceeds a threshold" logic of claim 1.
Motivation to combine (articulated, KSR-compliant):
- Same field, same problem. All three address detecting malicious/compromised network hosts from traffic telemetry, and all were cited on the face of the patent as the pertinent art.
- Complementary, not competing. Yadav explicitly frames NXDOMAIN analysis as "speeding up … present detection strategies" and as a real-time edge technique; Jung's TRW is expressly motivated by the need for prompt, low-false-positive detection of a scanning host. A PHOSITA seeking a fast, self-parameterizing classifier for the Yadav signal would naturally reach for TRW — a technique already proven on the analogous "failed-attempt" signal (failed TCP connections) that Jung shows is more discriminating than successful attempts, exactly as Yadav shows for failed DNS lookups.
- Predictable result / obvious to try. Applying SPRT to a new but structurally identical binary-failure signal is the sort of "predictable use of prior-art elements according to known methods" KSR condemns. The patent's own advantages — classification "in as little as three to four DNS NX messages" — mirror Jung's reported 4–5 observations to a decision; the benefit was known and expected, not newly discovered.
- The patent practically admits the combination. The specification states that "sequential hypothesis testing [
30= Wald] may be used to classify hosts as compromised based on observations of unique DNS NX messages," and cites Yadav [32] as the DNS-failure detection work. A specification's own citation of the two building blocks, side by side, is powerful § 103 evidence.
Combination B: US 8,555,388 (Palo Alto) + Jung/Wald (§6, §7)
'388 expressly enumerates "visiting a non-existent domain" as a monitored malware heuristic, and claims a score that is increased on correlated suspicious behavior and a determination that the host is botnet-associated when the score falls in a specified value range — i.e., claim 1's "score … reaches or exceeds a threshold." '388 also discloses the responsive action (firewall block/monitor/report) of claim 1's final step.
Motivation: '388 supplies the DNS-non-existent-domain heuristic and a raw cumulative score but is coarse (a severity tally). Jung/Wald supply a statistically principled, self-terminating score with bounded false-positive/missed-detection rates — precisely the improvement a PHOSITA would make to reduce '388's false positives and to decide when the threshold is met. Both references are in the network-security/botnet-detection art and both are directed to detecting C&C-associated hosts.
Gap to note: '388's score is a severity score that increases with correlated behaviors and does not by itself recite the +1/−1 novelty-gated update; that limitation is supplied by Yadav/Pleiades (novelty of the NX domain relative to the host's history) or by Jung (success/failure random walk). A challenger would therefore typically plead A + B + Jung, not B alone.
Combination C: Perdisci US 2010/0037314 (+ Notos/Kopis) + Yadav/Pleiades + Jung/Wald
Perdisci discloses detecting malicious/botnet-related domain names and identifying the hosts that query them, with reputation scoring over DNS data. Yadav/Pleiades supply the NXDomain/novelty feature; Jung/Wald supply the thresholded random-walk score. Motivation: Perdisci's reputation approach is domain-centric and static-ish; the NXDomain-novelty signal is the acknowledged way to catch DGA/domain-flux hosts before blacklists update (Pleiades' stated contribution), and SPRT gives the fast per-host decision Perdisci's scoring lacks.
6. Dependent claims — secondary references
| Claim(s) | Feature | Reference(s) that render it obvious | Motivation |
|---|---|---|---|
| 2 / 13 | Observe & copy NX messages from a link/node (tap) | '388 (monitor network traffic at a security device); US 2011/0197278 | Tapping/mirroring DNS traffic is routine network monitoring. |
| 3 | Mitigation before host contacts a malicious entity/C&C | Yadav 2011 (real-time, edge-of-AS detection ahead of C&C contact); Pleiades (block C&C domains before use) | Both expressly aim to act before C&C rendezvous. |
| 4 / 14 | Unique zones = malicious or previously unknown | Yadav IMC-2010 / ToN-2012; Pleiades; Hao 2011 | Novel AGDs are exactly what DGA bots generate. |
| 5 / 15 | Non-unique zone = benign or previously known | US 2009/0083413 (Levow) frequency data; Bilge EXPOSURE (passive-DNS "existence/history" features); patent's own Zipf observation | A previously seen, commonly resolved domain is the definition of benign traffic in this art. |
| 6 / 16–17 | Sequential hypothesis testing; parameters from network characteristics/delay/user base/etc. | Jung 2004; Wald 1947; US 6,892,163 (adaptive sequential probability test) | Jung's TRW is SPRT for network host classification, with θ₀/θ₁, α, β parameters. |
| 8 / 18–19 | Lock-free data structure for header/payload analysis; parallel streams | US 2014/0089539 (SAP, Lockless Spin Buffer); US 2011/0154359 (Microsoft, hash partitioning streamed data); Valois 1994 (lock-free queues); Sommer 2009 (multi-core NIDS pipeline) | Lock-free buffers/multi-core pipelines were the standard way to hit line-rate packet analysis; the patent's own spec cites Valois [28] and Sommer [25]. |
| 10 / 20 | Reporting, logging, discarding, rerouting | '388 (block/monitor/report); Pleiades (block C&C); US 2011/0197278 (containment); US 2012/0174220 (Verisign) | Each mitigation is a conventional responsive action. |
| 11 / 21 | Implement on DAG card, GPU, or general-purpose processor | '388 (general-purpose processor/security appliance); DAG capture cards (Endace) and GPUs as packet-processing accelerators were well-known | A POSITA would select hardware from a finite set of known packet-processing platforms. |
7. Secondary considerations / rebuttal (Graham factors)
- No commercial success or licensing evidence is known. The patent is Expired – Fee Related (adjusted expiration March 15, 2034) and, per the earlier litigation section, has never been asserted. Lapse-for-non-payment is at least as consistent with lack of commercial value as with validity.
- No unexpected results. The claimed performance "in as little as three to four DNS NX messages" is the expected performance of SPRT, which Jung reports requires 4–5 observations. Speed is an inherent property of the statistical technique, not an unexpected result with a nexus to the claims.
- No teaching away identified. If anything, the prior art (Yadav, Pleiades, Jung) points toward NXDomain-based, statistically-scored, rapid host classification.
- "Long-felt need." The underlying need (fast, low-false-positive botnet detection) was being actively attacked by the very references cited; the patent is one incremental step in a crowded, fast-moving literature (2010–2013), which cuts against non-obviousness.
8. Prosecution-history consideration and overall conclusion
The granted claims were narrowed during prosecution — the "adjusted up or down … +1 unique / −1 non-unique" and "reaches or exceeds a threshold within the time period" limitations were added relative to the published claims (the pre-grant publication carried 28 claims; the patent has 22). That amendment suggests the examiner distinguished over the cited art (including '388, Perdisci, and the NXDomain literature) on these points. A post-grant challenger would therefore have to prove the specific +1/−1 novelty-gated score to be taught or obvious — which is precisely what the Yadav/Pleiades + Jung/Wald combination supplies, because:
- Yadav/Pleiades necessarily determine per-host domain novelty (to count distinct NX domains / cluster per queried domain), and
- Jung/Wald supply the ±1-style, thresholded increment/decrement per binary observation.
Bottom line. Independent claims 1, 12, and 22 are, in my assessment, reasonably likely to be held obvious under § 103(a) over Yadav & Reddy (2011) in view of Jung et al. (2004)/Wald (1947), and alternatively over US 8,555,388 (Palo Alto) in view of Jung/Wald and one of Yadav/Pleiades (and further in view of Perdisci where a domain-reputation element is needed). The dependent claims are obvious in view of the additional references tabulated in § 6 (Jung/'163 for SPRT; SAP/Microsoft/Valois/Sommer for lock-free multi-core processing; '388/Pleiades/'278 for mitigation; DAG/GPU as known hardware).
Residual uncertainty to close before relying on this as an invalidity opinion: (i) full-text review of Yadav 2011, Pleiades, and '388 to confirm the precise per-host novelty/score mechanics; (ii) confirmation of the pre-AIA vs. AIA framing and the exact critical date; and (iii) a fresh prior-art search for references not cited on the patent face that may independently teach the +1/−1 novelty-gated score (e.g., 2009–2011 DGA/domain-flux patents).
Sources
- US 9,934,379 B2 — https://patents.google.com/patent/US9934379/en
- Yadav & Reddy, Winning with DNS Failures (SecureComm 2011) — https://eudl.eu/doi/10.1007/978-3-642-31909-9_26
- Antonakakis et al., From Throw-Away Traffic to Bots (USENIX Security 2012) — https://www.usenix.org/conference/usenixsecurity12/technical-sessions/presentation/antonakakis
- Jung et al., Fast Portscan Detection Using Sequential Hypothesis Testing (IEEE S&P 2004) — https://www.scilit.com/publications/bea09757a3412e77b0ef0b9b1dca11cb and http://icir.org/vern/papers/portscan-oak04.pdf
- US 8,555,388 B1 (Palo Alto Networks) — https://www.freepatentsonline.com/y2014/0090059.html and https://patents.justia.com/patent/[8555388](/patent/8555388)
Generated 9/30/2026, 6:03:22 PM
Extensions
Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.
Derivative works
Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.
Keep exploring
Other patents in Software Technology & Computing Systems (T)
- US 8510859I'll search for litigation/docket information on this specific patent, then compile the summary. I found no litigation or CAFC hits. Let me try two more targeted docket-focused searches before concluding. Search results for…
- US 5659703I'll search for authoritative information on this patent, including any 2026 CAFC docket activity. Let me search for the patent's claims and any litigation history. Let me look for the actual claim text of this patent. US 5,659,703 —…
- US 12244630I'll search for the patent and any related litigation. Let me verify the granted patent's claims and check for any litigation or PTAB proceedings. US Patent 12,244,630 — Analyst Summary Bibliographic data | Field | Value | |---|---| |…
- US 8606819I'll search for authoritative information on this patent number before summarizing. Let me check the CAFC docket and the specific claims. US Patent 8,606,819 — Analyst Summary Scope note: I searched for the exact identifier 8606819 only…
- US 8280819I'll verify the patent's details against current sources and check for any litigation or CAFC 2026 activity. Let me search more specifically for litigation and CAFC 2026 activity involving this exact patent number. Verification status…
- US 7155451I'll verify the patent details and check for any 2026 CAFC activity. Let me check the specific CAFC docket and 2026 activity. Let me check the Federal Circuit docket 25-1651 and the current litigation status. US Patent 7,155,451 —…
- US 10353811I'll search for authoritative information on this patent, including any 2026 CAFC docket activity. Let me check for any Federal Circuit appeal activity and confirm the litigation posture. US Patent 10,353,811 — Analyst Summary Search scope…
- US 7212534I'll search for the authoritative record on this patent number and check for any 2026 CAFC activity. Now let me check for any CAFC 2026 docket activity and confirm the full claim set. Let me confirm the remaining independent claims and…