In Re Enhanced Security Research, LLC

739 F.3d 1347, 109 U.S.P.Q. 2d (BNA) 1265, 2014 WL 104023, 2014 U.S. App. LEXIS 586
CourtCourt of Appeals for the Federal Circuit
DecidedJanuary 13, 2014
Docket20-115
StatusPublished
Cited by8 cases

This text of 739 F.3d 1347 (In Re Enhanced Security Research, LLC) is published on Counsel Stack Legal Research, covering Court of Appeals for the Federal Circuit primary law. Counsel Stack provides free access to over 12 million legal documents including statutes, case law, regulations, and constitutions.

Bluebook
In Re Enhanced Security Research, LLC, 739 F.3d 1347, 109 U.S.P.Q. 2d (BNA) 1265, 2014 WL 104023, 2014 U.S. App. LEXIS 586 (Fed. Cir. 2014).

Opinions

Opinion for the court filed by Circuit Judge DYK.

Dissenting opinion filed by Circuit Judge O’MALLEY.

DYK, Circuit Judge.

Enhanced Security Research, LLC (“ESR”) appeals from the decision of the Board of Patent Appeals and Interferences (“Board”), now the Patent Trial and Appeal Board, in an ex parte reexamination of U.S. Patent No. 6,119,236 (“the '236 patent”). The Board affirmed the Patent and Trademark Office (“PTO”) examiner’s rejection of claims 1-5 and 7-19 as obvious. We affirm.

Background

The '236 patent, as amended, claims a computer security device and method for preventing unauthorized individuals from gaining access to a local computer network. The patent specification describes an “intelligent network security device” (“INSD”) that is capable of balancing the desire for network security against the need for network accessibility. '236 patent col. 3 1. 47. The INSD protects a local network by: (1) monitoring the data packets flowing into and out of the network in order to detect suspicious patterns of communications; (2) assigning weighted values to any threatening activity it detects; and (3) blocking communications based on their assigned weight using a firewall.

Claim 1 of the amended '236 patent reads:

In a computer system connected to an external communications medium, a security device comprising:
a programmable firewall device interposed between the computer system and the external communications medium;
a controller device configured within the computer system such that said controller device can access all communications into and out of the computer system; and
a communications device for communicating instructions from said controller device to said firewall device for controlling said firewall device; wherein
said controller device is configured to operate generally continuously and repeatedly to:
(i) examine, in essentially real time, communications incoming to the computer system;
(ii) analyze, in essentially real time, communications to detect if the communications contain patterns of activity indicative of an attempted security breach;
(iii) assign a weight to the attempted security breach if an attempted security breach is detected; and
(iv) continuously control the firewall during the operation of the computer system to block communications between the computer system and the external communications medium, based on the weight assigned to the attempted security breach, when an attempted security breach is detected.

JA 9622-23. Thus; claim 1 pertains to a security device that provides protection to a local area network (“LAN”) by monitoring communications, analyzing whether they represent attempted security breaches, assigning weights to any detected breach attempts, and, finally, commanding the firewall to block attempted breaches based on their assigned weight.

Claims 2-5 and 7-11 are dependent on claim l.1 Amended claims 8 and 9 relate to the blocking process. Claim 8 states:

[1350]*1350the controller controls the firewall to block the communication between the computer system and the external communication medium for a predetermined, period according to the weight assigned to the attempted security breach.

Id. claim 8 (emphasis added). Claim 9 presents a slight variation on claim 8: after the controller assigns a weight to the attempted breach, “the controller controls the firewall to block communications between a selected portion of the computer system and the external communications medium according to the weight assigned to the perceived attempted security breach.” Id. claim 9 (emphasis added). Thus, under these dependent claims, the INSD has limited blocking capabilities: the INSD can only command the firewall to undertake a certain, predetermined response.

Next, independent claim 12 covers the method portion of the '236 patent. According to amended claim 12, this method comprises

monitoring, in essentially real time, communications between the local area network and the wide area network;
determining, over time, if the communications between the local area network and the wide area network contain patterns of activity indicative of an attempted security breach;
classifying 'by assigning a weight to the attempted security breach if an attempted security breach is detected; and
generally simultaneously controlling a firewall to selectively block communications between the local area network and the wide area network depending upon the weighted classification assigned to the attempted security breach.

Id. claim 12. Under some of the dependent claims, the method entails classifying and assigning a weight to an attempted security breach depending on: (1) “the importance of a portion of the local area network which the attempted security breach attempts to access,” id. claim 15 (emphasis added); (2) “the number of attempts made in the course of the attempted security breach,” id. claim 16 (emphasis added); or (3) “the relative sophistication of the attempted security breach,” id. claim 17 (emphasis added).

A third party requested reexamination of the original patent, and, among other documents, two potential pieces of prior art were before the PTO: the manual of a software product called NetStalker (“Net-Stalker” or the “Manual”) and a scholarly article authored by G.E. Liepins and H.S. Yaccaro (“Liepins”). Similar to the '236 patent, the NetStalker software protects a LAN from attempted security breaches. The Manual describes how the product functions and teaches the user how to install the software and tailor it to his needs. Through these descriptions, the Manual discloses a dynamic security device that provides protection to a LAN by monitoring the incoming and outgoing communications, identifying attempted security breaches, and then automatically blocking any unauthorized access attempts. As discussed below, ESR contends that the Manual is not prior art.

Liepins is a scholarly article that describes a computer system, called Wisdom and Sense (“W & S”), that is capable of detecting anomalous network activity. [1351]*1351Liepins first recognizes that the identification of activity patterns not previously known to be associated with misuse is intrinsically difficult to systematize. Lie-pins also notes that “just checking” historical data regarding misuse patterns is not sufficient. To solve this problem, Liepins teaches a framework that can detect newly identified anomalous activity by automatically generating, weighing, and applying a “forest” of decision rules. Using stored data to identify patterns associated with unauthorized access, W & S generates rules that are capable of parsing new anomalous activity from acceptable activity.2 Through this mechanism, the W & S system protects a LAN without shutting down all network activity. ESR does not dispute the prior art status of Liepins.

Free access — add to your briefcase to read the full text and ask questions with AI

Related

Weber, Inc. v. Provisur Technologies, Inc.
92 F.4th 1059 (Federal Circuit, 2024)
Samsung Electronics Co. v. NVIDIA Corp.
160 F. Supp. 3d 866 (E.D. Virginia, 2015)
K-Swiss Inc. v. Glide'n Lock Gmbh
567 F. App'x 906 (Federal Circuit, 2014)
Inre: Teles Ag Information
Federal Circuit, 2014
In re Teles AG Informationstechnologien
747 F.3d 1357 (Federal Circuit, 2014)

Cite This Page — Counsel Stack

Bluebook (online)
739 F.3d 1347, 109 U.S.P.Q. 2d (BNA) 1265, 2014 WL 104023, 2014 U.S. App. LEXIS 586, Counsel Stack Legal Research, https://law.counselstack.com/opinion/in-re-enhanced-security-research-llc-cafc-2014.