Book a demo

Cut patent&paper research from weeks to hours with PatSnap Eureka AI!

Try now
CTD Networks v. Google LLC (23-2428) — SIEM Patent Appeal | PatSnap
Explore in Eureka
Case ID23-2428
FiledSep 2023
ClosedMay 2024
Patent Litigation

CTD Networks v. Google (23-2428): Federal Circuit Dismisses Chronicle Security Appeal

CTD Networks, LLC appealed infringement claims against Google’s Chronicle Security Operations platform — including Chronicle SIEM, SOAR, and Threat Intelligence — asserting four cybersecurity patents. The Federal Circuit dismissed the appeal in 240 days, ordering each side to bear its own costs.

Resolution time
240days
240 days — resolved faster than the median Federal Circuit patent appeal (~18 months)
Patents asserted
4
US9503470B2 and 3 further patents asserted across network security and threat detection
Outcome
Appeal Dismissed
Procedural dismissal — no merits ruling; lower court outcome left undisturbed
Cost ruling
Own Costs
Each party bears its own costs — no fee-shifting order entered by the Federal Circuit
Published by PatSnap Insights Team · Verified by PatSnap Eureka Data
Case overview

Four cybersecurity patents, Google’s Chronicle, and a swift Federal Circuit exit

CTD Networks, LLC filed this appeal at the Court of Appeals for the Federal Circuit on 27 September 2023, challenging an earlier district court outcome in an infringement action targeting Google’s Chronicle Security Operations suite. The asserted portfolio spans four patents — US9503470B2, US8327442B2, US9438614B2, and US11171974B2 — covering network security architectures relevant to SIEM, SOAR, and threat intelligence capabilities. Google was represented by Munger Tolles & Olson LLP, while CTD Networks retained Ramey LLP, a firm known for asserting patents in the technology sector.

The Federal Circuit dismissed the appeal on 24 May 2024, just 240 days after filing, with a terse two-part order: the appeal is dismissed, and each side shall bear its own costs. A dismissal at the appellate level without a merits ruling means the court did not evaluate the underlying infringement claims on substance. The lower court’s disposition — whatever it was — remains undisturbed, and no appellate precedent is created on the patent claims themselves. The equal-costs order suggests neither party was found to have litigated improperly.

A 240-day resolution is notably swift for a Federal Circuit patent appeal, which typically takes considerably longer to reach a merits decision. The speed and procedural nature of the dismissal suggest a jurisdictional defect, a deficient notice of appeal, or a voluntary withdrawal by CTD Networks may have driven the outcome — though the public record does not disclose the specific procedural basis. What remains unknown is whether the parties reached any private resolution contemporaneous with the dismissal, and whether CTD Networks retains any avenue to reassert these patents in a new action.

Case at a glance
Case no.23-2428
DefendantGoogle, LLC
CourtCourt of Appeals for the Federal Circuit
JudgeN/A
FiledSeptember 27, 2023
ClosedMay 24, 2024
Duration240 days
OutcomeAppeal Dismissed
Verdict causeInfringement Action
BasisAppeal Dismissed
Prior Art Intelligence
See what prior art exists on this patent.
Eureka scans millions of patents and papers to surface prior art that may have invalidated these claims before costly litigation begins.
Check Prior Art
Case data sourced from PACER / Court of Appeals for the Federal Circuit via PatSnap Eureka Litigation Intelligence Explore similar cases ↗
Case timeline

Filing to Appeal Dismissed in 240 days

240 days — resolved faster than the median Federal Circuit patent appeal (~18 months)

Case timeline: Appeal filed SEP 27 2023, JAN–FEB — 240 days total Horizontal timeline showing the three key events in Ctd Networks, LLC v Google, LLC from filing to resolution. Source: PACER, Court of Appeals for the Federal Circuit. SEP 27 2023 Appeal filed Pre-trial proceedings MAY 24 2024 Appeal Dismissed 240 DAYS TOTAL
Dismissal terms

Federal Circuit dismisses appeal: what the order means for both parties

Legal mechanism

Appeal dismissed — no merits adjudication at the Federal Circuit

A Federal Circuit dismissal at the appellate stage means the court declined or was unable to reach the substance of the infringement claims. Common triggers include jurisdictional defects, a deficient or untimely notice of appeal, failure to prosecute, or appellant withdrawal. No ruling was issued on whether the four asserted patents are infringed or valid. The lower court’s outcome stands, but no appellate precedent is created on the patents or the Chronicle platform.

No merits ruling
Patent holder outcome

CTD Networks loses its appellate path without a merits decision

For CTD Networks, dismissal without a merits ruling forecloses this specific appellate avenue. The patents — US9503470B2, US8327442B2, US9438614B2, and US11171974B2 — are not declared invalid or unenforceable by this order, meaning they could theoretically be asserted again in a new action. However, the cost-bearing order and the failure to obtain appellate review may signal limited commercial momentum behind the portfolio. The equal-costs ruling provides no financial relief to CTD Networks.

Appellate path closed
Defendant outcome

Google avoids merits exposure but patents survive for future assertion

Google emerges from this appeal without an infringement finding against Chronicle Security Operations and without bearing the opponent’s costs. Critically, however, none of the four asserted patents were invalidated. This means Google’s Chronicle SIEM, SOAR, and Threat Intelligence products could face reassertion under the same portfolio, absent a final invalidity finding or inter partes review cancellation. Google’s strong representation by Munger Tolles suggests it was prepared for merits briefing regardless.

No invalidity ruling
Commercial implications

Cybersecurity SIEM/SOAR vendors remain exposed to this patent portfolio

Because the dismissal is procedural, the four CTD Networks patents survive with their validity formally untested at the appellate level. Competitors and customers of SIEM, SOAR, and threat intelligence platforms — not just Google — should note that these patents remain enforceable on their face. Any vendor with overlapping network security architectures should assess FTO exposure against this portfolio. A dismissed appeal with no costs order is a relatively low-cost exit for an NPE, consistent with a reassertion strategy.

Portfolio risk remains
Legal analysis based on PACER docket records for case 23-2428 and PatSnap Eureka litigation intelligence Search PatSnap Eureka ↗
Parties and representation

Full party and counsel information

RoleNameTypeDetail
PlaintiffCtd Networks, LLCCompanyCybersecurity patent assertion entity — holder of US9503470B2 and related network security patentsSearch in Eureka ↗
DefendantGoogle, LLCCompanyGoogle, LLC — developer of Chronicle Security Operations, Chronicle SIEM, SOAR, and Threat Intelligence platformSearch in Eureka ↗
Plaintiff counselWilliam Peterson Ramey , IIIAttorneyCounsel for Ctd Networks, LLCSearch in Eureka ↗
Plaintiff law firmRamey LLPLaw FirmRepresenting Ctd Networks, LLCSearch in Eureka ↗
Defendant counselAdam W. KwonAttorneyCounsel for Google, LLCSearch in Eureka ↗
Defendant counselEvan Jennings MannAttorneyCounsel for Google, LLCSearch in Eureka ↗
Defendant counselHeather E. Takahashi CounselAttorneyCounsel for Google, LLCSearch in Eureka ↗
Defendant counselVincent LingAttorneyCounsel for Google, LLCSearch in Eureka ↗
Defendant law firmMunger Tolles & Olson LLPLaw FirmRepresenting Google, LLCSearch in Eureka ↗
Presiding judgeJudge N/AJudgeCourt of Appeals for the Federal CircuitSearch in Eureka ↗
Official verdict

Official order — verbatim text

“IT IS ORDERED THAT: (1) The appeal is dismissed. (2) Each side shall bear its own costs.”
Source: PACER Docket, Case 23-2428, Court of Appeals for the Federal Circuit

The Federal Circuit’s two-part order — dismissing the appeal and requiring each side to bear its own costs — is narrow and purely procedural. No merits analysis was conducted on the four asserted patents or their application to Google’s Chronicle platform. The equal-costs ruling is notable: it neither rewards Google with fee-shifting nor penalises CTD Networks, suggesting the dismissal was not treated as frivolous litigation. The absence of any written opinion means this order creates no precedent and provides no claim construction guidance that could affect future assertion of the same portfolio.

PACER case 23-2428 · Public docket record Explore in Eureka ↗
Patent at issue

US9503470B2 — Network security monitoring and threat detection architecture

Publication No.US9503470B2
Application No.US14/043567
Patent details
ProductNetwork security monitoring and threat detection for enterprise environments
Cited in actionSeptember 27, 2023

Publication No.US8327442B2
Application No.US10/746825
Patent details
ProductNetwork access control and security event management systems
Cited in actionSeptember 27, 2023

Publication No.US9438614B2
Application No.US13/942175
Patent details
ProductCyber threat detection and network security operations architecture
Cited in actionSeptember 27, 2023

Publication No.US11171974B2
Application No.US15/357399
Patent details
ProductNetwork security monitoring with advanced threat intelligence integration
Cited in actionSeptember 27, 2023

US9503470B2, the lead patent in this action, covers network security monitoring architecture — a domain directly relevant to SIEM and SOAR platform functionality. It was filed under application number US14/043567 and granted as a B2 utility patent, indicating it survived at least one examination round with substantive claims intact. The portfolio also includes US8327442B2 (app. US10/746825), US9438614B2 (app. US13/942175), and US11171974B2 (app. US15/357399). The spread of application numbers suggests a continuation or family strategy built over more than a decade, potentially tracking the evolution of commercial security operations platforms.

The commercial relevance of this portfolio centres on Google’s Chronicle Security Operations — a cloud-native SIEM/SOAR platform that aggregates, analyses, and responds to security telemetry at enterprise scale. Patents covering network threat detection, security event correlation, and threat intelligence integration sit at the core of what Chronicle does commercially. For competitors in the SIEM/SOAR space — including Microsoft Sentinel, Splunk, Palo Alto Cortex XSOAR, and IBM QRadar — the survival of these claims without an invalidity ruling is a live FTO concern. The continuation lineage of US11171974B2 in particular suggests claims potentially tailored to current-generation cloud security architectures.

Patent data sourced from USPTO via PatSnap Eureka patent database Search patent records in Eureka ↗
Freedom to operate

Should you run an FTO against US9503470B2 and the CTD Networks portfolio?

Any organisation developing or deploying SIEM, SOAR, or threat intelligence aggregation products should treat the CTD Networks four-patent portfolio as an active FTO concern. The Federal Circuit’s procedural dismissal leaves all four patents valid and enforceable on their face. Product and engineering teams building network security event correlation, automated threat response workflows, or threat intelligence feeds are operating in the exact claim space this portfolio targets. The risk is not limited to Google — any vendor with overlapping architecture should assess exposure before scaling commercial deployments.

PatSnap Eureka’s FTO Search Agent allows R&D and IP teams to map product features against the claim language of US9503470B2, US8327442B2, US9438614B2, and US11171974B2 in minutes. Eureka identifies relevant prior art, generates claim-by-claim feature mapping, and surfaces related continuation families that may not yet be in litigation. For in-house counsel tracking the Ramey LLP docket, Eureka’s litigation monitoring tools provide early warning of new filings against similar technology profiles — enabling proactive IPR or design-around strategies before a complaint lands.

PatSnap Eureka FTO Search

Run a freedom-to-operate analysis on US9503470B2 to assess your product’s exposure

Run FTO in Eureka →
Related litigation

Similar Federal Circuit cybersecurity patent appeals involving SIEM and network security

Cases involving network security and SIEM patent assertions at the Federal Circuit, including NPE actions against cloud security operations platforms.

🔍
Access 40+ similar cases in PatSnap Eureka
Ctd Networks, LLC patent enforcement history, Court of Appeals for the Federal Circuit case history, Ctd Networks, LLC’s full IP portfolio, and comparable case analysis
NPE vs. cloud SIEM vendorsRamey LLP Federal Circuit casesChronicle platform IP disputesSOAR patent infringement actions
Unlock similar cases in Eureka →
Strategic implications

What this case signals for the cybersecurity IP enforcement landscape

A procedural Federal Circuit exit leaves four network security patents alive — and the Chronicle platform without a clean invalidity shield.

Procedural dismissals don’t extinguish patent risk — monitor for reassertion

CTD Networks’ four patents were never declared invalid or non-infringed by any appellate ruling. Companies deploying SIEM, SOAR, or threat intelligence tooling should treat this dismissal as a pause, not a resolution. NPE portfolios dismissed procedurally are frequently reasserted in new district court actions or via ITC, particularly when no estoppel attaches.

Google’s Chronicle avoided appellate merits exposure — but not permanently

The Federal Circuit’s dismissal leaves Google’s Chronicle Security Operations without a definitive non-infringement or invalidity finding on the asserted claims. In-house teams at Google and peer SIEM/SOAR vendors should assess whether proactive IPR petitions against US9503470B2, US8327442B2, US9438614B2, and US11171974B2 would provide a cleaner defensive posture than waiting for reassertion.

🔒
Full strategic analysis in PatSnap Eureka
Unlock full enforcement risk analysis for the CTD Networks cybersecurity portfolio at the Federal Circuit appellate level.
Ramey LLP assertion mapIPR candidacy for US11171974B2Chronicle SOAR claim mapping
Unlock full analysis →
Analysis powered by PatSnap Eureka Litigation Intelligence Explore in Eureka ↗
Frequently asked questions

Ctd v Google — key questions answered

Still have questions? PatSnap Eureka can answer them instantly from patent and litigation data. Ask Eureka ↗
PatSnap Eureka

Run FTO analysis on the CTD Networks cybersecurity patent portfolio today

Four network security patents survived this Federal Circuit dismissal with no invalidity ruling. PatSnap Eureka helps SIEM and SOAR vendors map claim exposure, identify IPR candidates, and monitor reassertion risk across the full CTD Networks portfolio.

Ask anything about this case.
PatSnap Eureka searches patents and litigation data to answer instantly.
Powered by PatSnap Eureka
Link copied to clipboard

Related Litigation Cases

Help us improve this page

Found incorrect or outdated information? Let us know and we'll get it fixed.