CTD Networks v. Google (23-2428): Federal Circuit Dismisses Chronicle Security Appeal
CTD Networks, LLC appealed infringement claims against Google’s Chronicle Security Operations platform — including Chronicle SIEM, SOAR, and Threat Intelligence — asserting four cybersecurity patents. The Federal Circuit dismissed the appeal in 240 days, ordering each side to bear its own costs.
Four cybersecurity patents, Google’s Chronicle, and a swift Federal Circuit exit
CTD Networks, LLC filed this appeal at the Court of Appeals for the Federal Circuit on 27 September 2023, challenging an earlier district court outcome in an infringement action targeting Google’s Chronicle Security Operations suite. The asserted portfolio spans four patents — US9503470B2, US8327442B2, US9438614B2, and US11171974B2 — covering network security architectures relevant to SIEM, SOAR, and threat intelligence capabilities. Google was represented by Munger Tolles & Olson LLP, while CTD Networks retained Ramey LLP, a firm known for asserting patents in the technology sector.
The Federal Circuit dismissed the appeal on 24 May 2024, just 240 days after filing, with a terse two-part order: the appeal is dismissed, and each side shall bear its own costs. A dismissal at the appellate level without a merits ruling means the court did not evaluate the underlying infringement claims on substance. The lower court’s disposition — whatever it was — remains undisturbed, and no appellate precedent is created on the patent claims themselves. The equal-costs order suggests neither party was found to have litigated improperly.
A 240-day resolution is notably swift for a Federal Circuit patent appeal, which typically takes considerably longer to reach a merits decision. The speed and procedural nature of the dismissal suggest a jurisdictional defect, a deficient notice of appeal, or a voluntary withdrawal by CTD Networks may have driven the outcome — though the public record does not disclose the specific procedural basis. What remains unknown is whether the parties reached any private resolution contemporaneous with the dismissal, and whether CTD Networks retains any avenue to reassert these patents in a new action.
Filing to Appeal Dismissed in 240 days
240 days — resolved faster than the median Federal Circuit patent appeal (~18 months)
Federal Circuit dismisses appeal: what the order means for both parties
Appeal dismissed — no merits adjudication at the Federal Circuit
A Federal Circuit dismissal at the appellate stage means the court declined or was unable to reach the substance of the infringement claims. Common triggers include jurisdictional defects, a deficient or untimely notice of appeal, failure to prosecute, or appellant withdrawal. No ruling was issued on whether the four asserted patents are infringed or valid. The lower court’s outcome stands, but no appellate precedent is created on the patents or the Chronicle platform.
No merits rulingCTD Networks loses its appellate path without a merits decision
For CTD Networks, dismissal without a merits ruling forecloses this specific appellate avenue. The patents — US9503470B2, US8327442B2, US9438614B2, and US11171974B2 — are not declared invalid or unenforceable by this order, meaning they could theoretically be asserted again in a new action. However, the cost-bearing order and the failure to obtain appellate review may signal limited commercial momentum behind the portfolio. The equal-costs ruling provides no financial relief to CTD Networks.
Appellate path closedGoogle avoids merits exposure but patents survive for future assertion
Google emerges from this appeal without an infringement finding against Chronicle Security Operations and without bearing the opponent’s costs. Critically, however, none of the four asserted patents were invalidated. This means Google’s Chronicle SIEM, SOAR, and Threat Intelligence products could face reassertion under the same portfolio, absent a final invalidity finding or inter partes review cancellation. Google’s strong representation by Munger Tolles suggests it was prepared for merits briefing regardless.
No invalidity rulingCybersecurity SIEM/SOAR vendors remain exposed to this patent portfolio
Because the dismissal is procedural, the four CTD Networks patents survive with their validity formally untested at the appellate level. Competitors and customers of SIEM, SOAR, and threat intelligence platforms — not just Google — should note that these patents remain enforceable on their face. Any vendor with overlapping network security architectures should assess FTO exposure against this portfolio. A dismissed appeal with no costs order is a relatively low-cost exit for an NPE, consistent with a reassertion strategy.
Portfolio risk remainsFull party and counsel information
| Role | Name | Type | Detail |
|---|---|---|---|
| Plaintiff | Ctd Networks, LLC | Company | Cybersecurity patent assertion entity — holder of US9503470B2 and related network security patentsSearch in Eureka ↗ |
| Defendant | Google, LLC | Company | Google, LLC — developer of Chronicle Security Operations, Chronicle SIEM, SOAR, and Threat Intelligence platformSearch in Eureka ↗ |
| Plaintiff counsel | William Peterson Ramey , III | Attorney | Counsel for Ctd Networks, LLCSearch in Eureka ↗ |
| Plaintiff law firm | Ramey LLP | Law Firm | Representing Ctd Networks, LLCSearch in Eureka ↗ |
| Defendant counsel | Adam W. Kwon | Attorney | Counsel for Google, LLCSearch in Eureka ↗ |
| Defendant counsel | Evan Jennings Mann | Attorney | Counsel for Google, LLCSearch in Eureka ↗ |
| Defendant counsel | Heather E. Takahashi Counsel | Attorney | Counsel for Google, LLCSearch in Eureka ↗ |
| Defendant counsel | Vincent Ling | Attorney | Counsel for Google, LLCSearch in Eureka ↗ |
| Defendant law firm | Munger Tolles & Olson LLP | Law Firm | Representing Google, LLCSearch in Eureka ↗ |
| Presiding judge | Judge N/A | Judge | Court of Appeals for the Federal CircuitSearch in Eureka ↗ |
Official order — verbatim text
The Federal Circuit’s two-part order — dismissing the appeal and requiring each side to bear its own costs — is narrow and purely procedural. No merits analysis was conducted on the four asserted patents or their application to Google’s Chronicle platform. The equal-costs ruling is notable: it neither rewards Google with fee-shifting nor penalises CTD Networks, suggesting the dismissal was not treated as frivolous litigation. The absence of any written opinion means this order creates no precedent and provides no claim construction guidance that could affect future assertion of the same portfolio.
US9503470B2 — Network security monitoring and threat detection architecture
US9503470B2, the lead patent in this action, covers network security monitoring architecture — a domain directly relevant to SIEM and SOAR platform functionality. It was filed under application number US14/043567 and granted as a B2 utility patent, indicating it survived at least one examination round with substantive claims intact. The portfolio also includes US8327442B2 (app. US10/746825), US9438614B2 (app. US13/942175), and US11171974B2 (app. US15/357399). The spread of application numbers suggests a continuation or family strategy built over more than a decade, potentially tracking the evolution of commercial security operations platforms.
The commercial relevance of this portfolio centres on Google’s Chronicle Security Operations — a cloud-native SIEM/SOAR platform that aggregates, analyses, and responds to security telemetry at enterprise scale. Patents covering network threat detection, security event correlation, and threat intelligence integration sit at the core of what Chronicle does commercially. For competitors in the SIEM/SOAR space — including Microsoft Sentinel, Splunk, Palo Alto Cortex XSOAR, and IBM QRadar — the survival of these claims without an invalidity ruling is a live FTO concern. The continuation lineage of US11171974B2 in particular suggests claims potentially tailored to current-generation cloud security architectures.
Should you run an FTO against US9503470B2 and the CTD Networks portfolio?
Any organisation developing or deploying SIEM, SOAR, or threat intelligence aggregation products should treat the CTD Networks four-patent portfolio as an active FTO concern. The Federal Circuit’s procedural dismissal leaves all four patents valid and enforceable on their face. Product and engineering teams building network security event correlation, automated threat response workflows, or threat intelligence feeds are operating in the exact claim space this portfolio targets. The risk is not limited to Google — any vendor with overlapping architecture should assess exposure before scaling commercial deployments.
PatSnap Eureka’s FTO Search Agent allows R&D and IP teams to map product features against the claim language of US9503470B2, US8327442B2, US9438614B2, and US11171974B2 in minutes. Eureka identifies relevant prior art, generates claim-by-claim feature mapping, and surfaces related continuation families that may not yet be in litigation. For in-house counsel tracking the Ramey LLP docket, Eureka’s litigation monitoring tools provide early warning of new filings against similar technology profiles — enabling proactive IPR or design-around strategies before a complaint lands.
Run a freedom-to-operate analysis on US9503470B2 to assess your product’s exposure
Run FTO in Eureka →Similar Federal Circuit cybersecurity patent appeals involving SIEM and network security
Cases involving network security and SIEM patent assertions at the Federal Circuit, including NPE actions against cloud security operations platforms.
Related patent case — similar technology
Comparable case in the same technology domain. Patent holder and defendant reached resolution after proceedings.
SettledRelated infringement action — same court
Comparable Chronical SIEM-adjacent infringement action. Patent enforcement dynamics analysed in depth.
Active · District CourtRelated invalidity challenge — appellate outcome
Combined invalidity and infringement action in the same technology space. Decided after substantive proceedings.
DecidedCtd Networks, LLC’s broader IP enforcement history
Ctd Networks, LLC’s full litigation history covering prior enforcement, licensing activity, and inter partes review proceedings.
Portfolio viewWhat this case signals for the cybersecurity IP enforcement landscape
A procedural Federal Circuit exit leaves four network security patents alive — and the Chronicle platform without a clean invalidity shield.
Procedural dismissals don’t extinguish patent risk — monitor for reassertion
CTD Networks’ four patents were never declared invalid or non-infringed by any appellate ruling. Companies deploying SIEM, SOAR, or threat intelligence tooling should treat this dismissal as a pause, not a resolution. NPE portfolios dismissed procedurally are frequently reasserted in new district court actions or via ITC, particularly when no estoppel attaches.
Google’s Chronicle avoided appellate merits exposure — but not permanently
The Federal Circuit’s dismissal leaves Google’s Chronicle Security Operations without a definitive non-infringement or invalidity finding on the asserted claims. In-house teams at Google and peer SIEM/SOAR vendors should assess whether proactive IPR petitions against US9503470B2, US8327442B2, US9438614B2, and US11171974B2 would provide a cleaner defensive posture than waiting for reassertion.
Ramey LLP filing patterns suggest systematic cybersecurity assertion strategy
Ramey LLP is a high-volume patent assertion firm with a documented pattern of filing infringement actions in the technology sector. Analysing their active docket against the CTD Networks portfolio suggests this appeal dismissal is unlikely to mark the end of enforcement activity. Companies with network security products should track Ramey LLP filings as an early-warning indicator.
US11171974B2’s 2021 grant date makes it the freshest litigation lever in this portfolio
With a patent term extending furthest into the future, US11171974B2 — granted in 2021 — carries the highest residual enforcement risk among the four asserted patents. Its application number (US15/357399) suggests a continuation lineage, which typically signals claim scope designed to track evolving commercial products. SIEM and SOAR vendors should prioritise FTO analysis on this patent specifically.
Ctd v Google — key questions answered
The Federal Circuit dismissed CTD Networks’ appeal on 24 May 2024, 240 days after filing. The court issued a two-part order: the appeal is dismissed, and each side bears its own costs. No merits ruling was issued on the four asserted cybersecurity patents or their application to Google’s Chronicle Security Operations platform.
CTD Networks asserted four patents: US9503470B2, US8327442B2, US9438614B2, and US11171974B2. These cover network security monitoring and threat detection architectures. They were asserted against Google’s Chronicle SIEM, Chronicle SOAR, Chronicle Security Operations, and Threat Intelligence products.
No. A procedural dismissal at the Federal Circuit does not declare patents invalid or unenforceable. All four CTD Networks patents — US9503470B2, US8327442B2, US9438614B2, and US11171974B2 — survive with their validity formally untested by this ruling. They could potentially be reasserted in a new district court action.
The public record does not specify the procedural basis for dismissal. Common reasons for a swift Federal Circuit dismissal include a jurisdictional defect, a deficient or untimely notice of appeal, failure to prosecute, or voluntary withdrawal by the appellant. The 240-day resolution is faster than a typical merits appeal, which is consistent with a procedural exit rather than full briefing.
Because no invalidity ruling was issued, US9503470B2, US8327442B2, US9438614B2, and US11171974B2 remain live enforcement risks for vendors offering SIEM, SOAR, or threat intelligence platforms. Companies including Microsoft, Splunk, Palo Alto Networks, and IBM with overlapping network security architectures should conduct FTO analysis against this portfolio, with particular focus on US11171974B2, the most recently granted patent in the family.
Run FTO analysis on the CTD Networks cybersecurity patent portfolio today
Four network security patents survived this Federal Circuit dismissal with no invalidity ruling. PatSnap Eureka helps SIEM and SOAR vendors map claim exposure, identify IPR candidates, and monitor reassertion risk across the full CTD Networks portfolio.
PatSnap Eureka searches patents and litigation data to answer instantly.