ZapFraud, Inc. v. FireEye, Inc.

District Court, D. Delaware·Decided November 20, 2020·No. 1:19-cv-01688·Unknown

Opinion

IN THE UNITED STATES DISTRICT COURT FOR THE DISTRICT OF DELAWARE

ZAPFRAUD, INC., ) ) Plaintiff, ) ) v. ) Civil Action No. 19-1688-CFC ) FIREEYE, INC., ) ) Defendant. ) ) ZAPFRAUD, INC., ) ) Plaintiff, ) ) v. ) Civil Action No. 19-1690-CFC ) MIMECAST NORTH AMERICA, ) INC., MIMECAST UK LIMITED and ) MIMECAST SERVICES LTD., ) ) Defendants. ) ) ZAPFRAUD, INC., ) ) Plaintiff, ) ) v. ) Civil Action No. 19-1691-CFC ) PROOFPOINT, INC., ) ) Defendant. )

REPORT AND RECOMMENDATION Pending before the Court in these three patent infringement cases are motions filed by Defendant FireEye, Inc. (“FireEye”), Defendants Mimecast North America, Inc., Mimecast UK Limited and Mimecast Services Ltd. (“Mimecast”) and Defendant Proofpoint, Inc. (“Proofpoint,” and collectively with FireEye and Mimecast, “Defendants”), pursuant to Federal Rule of Civil Procedure 12(b)(6) (the “Motions”). (Civil Action No. 19-1688-CFC, D.I. 31; Civil Action No. 19-1690-CFC, D.I. 31; Civil Action No. 19-1691, D.I. 31) With their Motions, Defendants argue that the patents asserted against them—United States Patent Nos. 10,277,628 (the “'628 patent”) and 10,609,073 (the “'073 patent”)—are directed to patent-ineligible subject matter pursuant to 35 U.S.C. § 101 (“Section 101”). For the reasons that follow, the Court recommends that the

Motions be GRANTED. I. BACKGROUND A. Factual Background The two patents-in-suit, both titled “Detecting Phishing Attempts,” share a common specification.1 The patents relate to systems and methods for detecting fraud or phishing attempts in e-mail communications using various disclosed techniques. In providing context for the invention, the specification’s “Background of the Invention” section first explains that individuals are “increasingly us[ing] electronic mail to communicate with one another for personal and business reasons.” ('628 patent, col. 1:13-14) But it explains that these e-mail users also face a problem: that “unscrupulous individuals can use electronic

mail for nefarious purposes, such as to send unwarranted advertising email (e.g., SPAM) and perpetrate fraud against victims.” (Id., col. 1:15-18) This fraud might include a scam like a “phishing scam, in which criminals contact unsuspecting Internet users using messages that appear to be authored by legitimate entities such as banks, with the goal of tricking the victims into clicking on links in the messages and providing banking credentials (e.g., usernames and passwords) or other sensitive information.” (Id., col. 3:45-50) The specification then notes that certain prior art systems and methods had attempted to address this problem by identifying and filtering out these “nefarious” e-mails. More

1 As such, the Court will cite below only to the '628 patent, unless otherwise noted. specifically, the patents explain that one such technique “is the blacklisting of certain terms . . . where the presence of a blacklisted term in a message automatically results in the classification of the message as SPAM.” (Id., col. 1:18-21; see also D.I. 29 at ¶¶ 27, 47) However, it notes a problem with this type of prior art approach that allows it to be “defeated by the unscrupulous

individual”: that the wrongdoer could “use terms that a human would recognize” and that are very similar to (but not exactly the same as) the blacklisted word, and thus that “might not appear on a blacklist.” ('628 patent, col. 1:22-26) The specification also explains that “blacklisting of terms can be problematic in preventing fraud, where the goal of a fraudster is often to craft a message that looks as legitimate as possible (e.g., using only terms that commonly appear in legitimate communications).” (Id., col. 1:27-30) In other words, sometimes the fraudulent actor will utilize legitimate-sounding terms like “bank” or “account” in a phishing message, and which would not be on any blacklist; indeed, in such a case, a “phishing message might appear to a recipient to contain, verbatim, the text of a legitimate message sent by a legitimate entity” (but yet, for example, the phishing message might also contain a link to a harmful resource). (Id.,

cols. 3:64-4:7; see also D.I. 29 at ¶¶ 28, 48) This bad actor might also make use of legitimate- looking text, logos, symbols or other phraseology in their phishing e-mails. ('628 patent, col. 3:55-63) The patents note that this “degree of possible customization of scam messages [made] it particularly difficult for existing e-mail filters to provide sufficient protection[.]” (Id. col. 4:7- 10) Other sources of record describe additional prior art e-mail filtering systems, in place at the time of the invention, which attempted to identify deceptive e-mail messages. (D.I. 34 at 5- 6) One of those was a system that “blacklisted” not certain known, problematic words or terms, but instead certain e-mail addresses known to be associated with fraud. (D.I. 32, ex. A at 139) However, this approach also had its problems, in that it obviously could not block an e-mail address that had not yet been “reported as, or determined to be, malicious[.]” (Id.) Another system used a “conventional whitelist approach[,]” which “may erase all emails [from addresses] that are not on a whitelist” (i.e., that are not on a list of previously-approved e-mail addresses).

(Id.) The problem with that system is that it can be overprotective: it might block e-mails that the user actually wants to receive and that are not in fact fraudulent. (Id.) Because there “exist[ed] an ongoing need to protect against the victimization of legitimate email users[,]” ('628 patent, col. 1:31-32), the patented inventions attempted to provide a new and better system—one that met the above-referenced need, but that did so without blocking too many desired e-mails. The patented systems and methods do not employ a “blacklist” or “whitelist” approach, as in the prior art. Instead, as will be discussed further below, they attempt to identify e-mails that “appear[] to have been transmitted by an authoritative entity” by, inter alia, “computing a similarity distance” between: (1) either the display name or header associated with the e-mail at issue (i.e., the e-mail that might purport to

come from an “authoritative entity”) and (2) the display name or header actually associated with that authoritative entity, which is stored in a separate database. (Id., col. 35:43-57; see also id., col. 7:22-27; D.I. 29 at ¶¶ 29, 49) The claims also require that the system or method will go on to make a determination of whether this legitimate-looking e-mail is in fact fraudulent and, if it is, will take certain action with that e-mail. ('628 patent, col. 36:4-28) Additional facts about the patents-in-suit will be set out below in Section III. B. Procedural Background Plaintiff filed its initial Complaint in all three actions on September 10, 2019. (See, e.g., D.I. 1)2 The currently operative complaint in all three actions is the Second Amended Complaint, in which Plaintiff alleges that Defendants directly, indirectly and willfully infringe at least claim 1 of the '628 patent and at least claim 1 of the '073 patent. (See, e.g., D.I. 29)

All Defendants filed their respective Motions on May 22, 2020. (D.I. 31; Civil Action No. 19-1688-CFC, D.I. 31; Civil Action No. 19-1691-CFC, D.I. 31) FireEye and Proofpoint simply joined Mimecast’s Motion and all of Mimecast’s briefing in support thereof. (Civil Action No. 19-1688-CFC, D.I. 31; Civil Action No. 19-1691-CFC, D.I. 31) These three cases have been referred to the Court by United States District Judge Colm F. Connolly to hear and resolve the pending Motions. (See D.I. 33; Civil Action No. 19-1688-CFC, D.I.

Free access — add to your briefcase to read the full text and ask questions with AI

ZapFraud, Inc. v. FireEye, Inc., (D. Del. 2020).

ZapFraud, Inc. v. FireEye, Inc. (ZapFraud, Inc. v. FireEye, Inc.) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

In Re Scott E. Johnston
435 F.3d 1381 (Federal Circuit, 2006)
CLS Bank International v. Alice Corp. Pty. Ltd.
717 F.3d 1269 (Federal Circuit, 2013)
Ultramercial, Inc. v. Hulu, LLC
772 F.3d 709 (Federal Circuit, 2014)
Internet Patents Corporation v. Active Network, Inc.
790 F.3d 1343 (Federal Circuit, 2015)
Enfish, LLC v. Microsoft Corporation
822 F.3d 1327 (Federal Circuit, 2016)
Tli Communications LLC v. Av Automotive, L.L.C.
823 F.3d 607 (Federal Circuit, 2016)
Electric Power Group, LLC v. Alstom S.A.
830 F.3d 1350 (Federal Circuit, 2016)
Intellectual Ventures I LLC v. Symantec Corp.
838 F.3d 1307 (Federal Circuit, 2016)
Synopsys, Inc. v. Mentor Graphics Corporation
839 F.3d 1138 (Federal Circuit, 2016)
Credit Acceptance Corp. v. Westlake Services
859 F.3d 1044 (Federal Circuit, 2017)
Two-Way Media Ltd. v. Comcast Cable Communications, LLC
874 F.3d 1329 (Federal Circuit, 2017)
Finjan, Inc. v. Blue Coat Systems, Inc.
879 F.3d 1299 (Federal Circuit, 2018)
Bsg Tech LLC v. Buyseasons, Inc.
899 F.3d 1281 (Federal Circuit, 2018)
Bozeman Financial LLC v. Federal Reserve Bank
955 F.3d 971 (Federal Circuit, 2020)
Mortgage Grader, Inc. v. Costco Wholesale Corp.
89 F. Supp. 3d 1055 (C.D. California, 2015)
Twilio, Inc. v. Telesign Corp.
249 F. Supp. 3d 1123 (N.D. California, 2017)
OIP Technologies, Inc. v. Amazon.com, Inc.
788 F.3d 1359 (Federal Circuit, 2015)
Sincavage v. Barnhart
171 F. App'x 924 (Third Circuit, 2006)