Synopsys, Inc. v. Risk Based Security, Inc.

District Court, E.D. Virginia·Decided July 28, 2022·No. 3:21-cv-00252·Unknown

Opinion

IN THE UNITED STATES DISTRICT COURT FOR THE EASTERN DISTRICT OF VIRGINIA Richmond Division SYNOPSYS, INC., Plaintiff, v. Civil Action No. 3:21cev252 RISK BASED SECURITY, INC., Defendant. OPINION The companies in this litigation—Synopsys, Inc. (“Synopsys”) and Risk Based Security, Inc. (“RBS”)—identify and share with their customers software security vulnerabilities. After Synopsys announced additional work it would perform in this area, RBS sent Synopsys a cease and desist letter alleging that Synopsys’s planned work would constitute copyright infringement of RBS’s database, misappropriation of RBS’s trade secrets, and tortious interference with RBS’s current and prospective economic relationships. In response, Synopsys filed this suit seeking a declaratory judgment that Synopsys’s conduct does not so infringe, misappropriate, or interfere. Each party has moved to exclude the other’s experts and for summary judgment. After reviewing the experts’ reports and finding much material that will not aid the Court as the fact-finder in this case, the Court will grant in part each party’s motion to exclude. Because RBS’s experts’ reports also suffer from reliability concerns, the Court will exclude the testimony of Ste- ven Kursh in its entirety and will significantly limit the testimony of Adam Shostack. The Court will deny each party’s motion for summary judgment as to Count I, declaratory judgment of no copyright infringement, because the parties dispute material facts regarding that claim. For Count II, declaratory judgment of no trade secret misappropriation, the Court will grant Synopsys’s motion for summary judgment as to all of RBS’s asserted trade secrets because RBS

has failed to establish that any of its materials satisfy the requirements for a trade secret. Lastly, for Count IV, declaratory judgment of no tortious interference, the Court will grant Synopsys’s motion for summary judgment because RBS failed to establish the existence of any particular business expectancy.! The Court further explains these rulings below. I. FINDINGS OF FACT? A, Open Source Software and the Parties’ Roles “Open source software is software with source code available to anyone to inspect, modify, and enhance, and is widely used as the foundation for software applications across every industry.” (ECF No. 227, at 11 § “Because it is so widely used, it is a target for hackers, as one open-source vulnerability can give hackers access to thousands of applications.” (/d.) Many initiatives have endeavored to identify and combat these vulnerabilities. The Open Security Foundation (“OSF”) was a non-profit organization that ran the Open Source Vulnerability

'! The Court previously dismissed Count III, a claim for copyright misuse. (ECF Nos. 128, 170.) 2 The following facts include (1) those that the parties do not dispute, and (2) those that a moving party identified and the other party did not produce sufficient evidence to controvert. See Local Civil Rule 56(B) (“In determining a motion for summary judgment, the Court may assume that facts identified by the moving party in its listing of material facts are admitted, unless such a fact is controverted in the statement of genuine issues filed in opposition to the motion.”); see also Hodgin v. UTC Fire & Sec. Ams. Corp., 885 F.3d 243, 252 (4th Cir. 2018) (the nonmoving party “must produce evidence that goes beyond ‘[c]onclusory or speculative allegations’ and rel[y] on more than ‘a mere scintilla of evidence’ to withstand summary judgment”’). Because the parties filed cross-motions for summary judgment, the Court has “resolve[d] all factual disputes and any competing, rational inferences in the light most favorable” to the party opposing the relevant motion. Rossignol v. Voorhaar, 316 F.3d 516, 523 (4th Cir. 2003) (quoting Wightman v. Springfield Terminal Ry. Co., 100 F.3d 228, 230 (Ist Cir. 1996)); ef United States v. Carolina Transformer Co., 978 F.2d 832, 835 (4th Cir. 1992) (“On summary judgment, we must draw all justifiable inferences in favor of the nonmoving party, including questions of credibility and of the weight to be accorded particular evidence.”). 3 This Opinion cites to the page numbers assigned by the CM/ECF docketing system.

Database (“OSVDB”). (ECF No. 221-14, at 1.) OSVDB “provide[d] accurate and unbiased in- formation about security vulnerabilities in computerized equipment.” (/d@.) In 2011, RBS acquired OSVDB from OSF in exchange for, among other things, “management resources, funding, and capital” support. (ECF No. 323-17, at 2; ECF No. 221-16.) RBS initially used the OSVDB data to create its own private software vulnerability database, VulnDB. Later, RBS used a subset of VulnDB data to update OSVDB. (ECF No. 227, at 13 J 14 (citing ECF No. 234-6, at 231:21- 232:6)); id. at 14 4 15.) The U.S. government also maintains a vulnerability identification initiative known as the Common Vulnerabilities and Exposures Program (“CVE Program”).* (/d.) Through this program, a CVE Numbering Authority (“CNA”) may “assign unique identifier numbers to vulnerabilities in open source security software and publish information about the vulnerabilities in the CVE Pro- gram’s public catalogs.” (/d. ]3.) Synopsys became a CNA in March 2021. (/d. 42.) Since that time, Synopsys has disclosed certain vulnerabilities through the program. (/d. 3.) RBS, formed in 2011, competes with Synopsys because RBS maintains a software vulner- ability database, VulnDB. (See id. at 12-13 49 5, 12.) Although competing in the market, RBS does not maintain total secrecy of its methods or products. CEO Jake Kouns has taught software users about the sources where vulnerability information “is ... usually” or “should ... be gath- ered.” (/d. at 14 § 18 (cleaned up).) Further, RBS provides demonstrations of the VulnDB portal to potential customers. Although RBS policy requires potential customers to first agree to certain confidentiality provisions, RBS has entered into licensing agreements with other businesses where the agreement did not explicitly require confidentiality for sublicensees. (/d. at 15 {{ 21, 24-27;

4 The Mitre Corporation runs this vulnerability identification program for the U.S. Depart- ment of Homeland Security. U/d. at 11 § 2.)

ECF No. 341, at 13-14 J 24-27.) RBS has also disclosed portions of its database schema on its GitHub page.’ (ECF No. 227, at 16 | 28.) B. Black Duck, its Programs, and its Files Black Duck Software, Inc. (“Black Duck’), Synopsys’s subsidiary, “offers its customers a suite of analytical software and services to help customers manage their use of open source soft- ware, and identify and track open source components in their software.” (/d. at 11 94.) In 2016, Black Duck hired Chris Fearon as its Director of Security/Research. (/d. at 17 432.) At that time, Black Duck started to develop “the Threat Research Information Management System (‘TRIMS’)}—a ‘document management system’ to allow Black Duck to interface with and store vulnerability data.” (/d.) Black Duck also developed Demeter, “a system of ‘scrapers’ that collect vulnerability information” from mailing lists, RSS feeds, and other websites for TRIMS. □□□□ 4 33.) Black Duck employees review vulnerability information in TRIMS and submit researched vulnerabilities to the “Black Duck KnowledgeBase,” where the vulnerabilities become available to Black Duck customers as security advisories. (da. 734.) As a Black Duck employee, Fearon created several files that Black Duck used, at least in part, to determine the public availability and accessibility of vulnerability references in the Vul- nDB data feed,° (see, e.g., ECF No. 228, at 15-16, 17 ff 1-4, 13; ECF No.

Free access — add to your briefcase to read the full text and ask questions with AI

Synopsys, Inc. v. Risk Based Security, Inc., (E.D. Va. 2022).

Synopsys, Inc. v. Risk Based Security, Inc. (Synopsys, Inc. v. Risk Based Security, Inc.) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Kewanee Oil Co. v. Bicron Corp.
416 U.S. 470 (Supreme Court, 1974)
Anderson v. Liberty Lobby, Inc.
477 U.S. 242 (Supreme Court, 1986)
Daubert v. Merrell Dow Pharmaceuticals, Inc.
509 U.S. 579 (Supreme Court, 1993)
Kumho Tire Co. v. Carmichael
526 U.S. 137 (Supreme Court, 1999)
Desmond v. PNGI Charles Town Gaming, L.L.C.
630 F.3d 351 (Fourth Circuit, 2011)
Farmers Insurance Exchange v. RNK, Inc.
632 F.3d 777 (First Circuit, 2011)
Sun Yung Lee v. Zom Clarendon, L.P.
453 F. App'x 270 (Fourth Circuit, 2011)
Avidair Helicopter Supply, Inc. v. Rolls-Royce Corp.
663 F.3d 966 (Eighth Circuit, 2011)
United States v. Douglas Fred Dorsey
45 F.3d 809 (Fourth Circuit, 1995)