CTD Networks v. Microsoft: Federal Circuit Appeal Dismissed After Case Withdrawal
CTD Networks, LLC appealed against Microsoft Co. asserting four US network security patents covering SIEM and XDR technologies including Microsoft 365 Defender and Microsoft Sentinel. The Federal Circuit dismissed the appeal in 240 days, with each party bearing its own costs — a resolution that leaves the underlying merits unadjudicated.
Network Security Patent Appeal Withdrawn at the Federal Circuit
CTD Networks, LLC brought an infringement action against Microsoft Co. asserting four US patents — US9503470B2, US8327442B2, US9438614B2, and US11171974B2 — directed at network security technologies. The accused products include Microsoft 365 Defender, Microsoft Defender for Cloud, and Microsoft Sentinel, Microsoft’s integrated SIEM and XDR solution suite. The appeal was filed at the Court of Appeals for the Federal Circuit on 27 September 2023 under Case No. 23-2429.
The Federal Circuit dismissed the appeal on 24 May 2024 following a case withdrawal, consistent with a voluntary decision by CTD Networks to discontinue the appellate proceedings. The court simultaneously granted a motion to withdraw and substitute counsel, accepted an amended entry of appearance for plaintiff’s attorney Erik Lund, denied all remaining motions, and ordered each side to bear its own costs. No merits determination was issued on any of the four asserted patents.
The 240-day resolution timeline suggests the matter was resolved before substantive appellate briefing concluded or oral argument was scheduled. The absence of fee-shifting — each party bearing its own costs — is consistent with a negotiated or strategic withdrawal rather than a sanctions-driven dismissal. The public record does not disclose whether any licensing agreement, settlement, or other commercial arrangement accompanied the withdrawal, leaving the enforceability of CTD Networks’ four network security patents an open question.
Filing to Case Withdrawn in 240 days
240 days from filing to dismissal — faster than the median Federal Circuit appeal lifecycle
Appeal dismissed after withdrawal: what the order means for both sides
Case withdrawal ends appeal without merits adjudication
A case withdrawal at the appellate level results in procedural dismissal — the Federal Circuit issues no ruling on the substantive patent claims. The underlying district court record and any prior rulings remain in place, but the appellate court makes no finding on validity, infringement, or claim construction. This means none of CTD Networks’ four asserted patents have been judicially invalidated or confirmed infringed by this proceeding.
No merits ruling issuedCTD Networks retains patents but loses appellate momentum
Because the appeal was dismissed rather than decided, CTD Networks’ four network security patents survive this proceeding with no adverse validity finding. However, the voluntary withdrawal suggests the appellate path was no longer commercially viable. The patents remain enforceable assets, and the public record does not disclose whether a licensing resolution or settlement was reached. Future enforcement attempts against Microsoft or third parties remain theoretically possible.
Patents intact; future enforcement openMicrosoft avoids Federal Circuit merits ruling on SIEM/XDR patents
Microsoft exits this appeal without a formal finding of non-infringement or invalidity across the four asserted patents. While the dismissal eliminates the immediate appellate threat to Microsoft 365 Defender, Defender for Cloud, and Sentinel, no estoppel or preclusion arises from a withdrawal-based dismissal. Microsoft’s exposure to the same patents in a future action is not formally extinguished, though the cost-bearing order signals no finding of bad faith on either side.
No estoppel; exposure theoretically persistsSIEM and XDR patent risk remains live for the security sector
The dismissal without merits resolution means the four CTD Networks patents covering network threat detection and security analytics have not been tested at the Federal Circuit level. Competitors and customers in the SIEM/XDR space — a market that includes CrowdStrike, Palo Alto Networks, IBM, and others — cannot rely on this case as precedent for non-infringement or invalidity. The unresolved patent portfolio suggests continued monitoring of CTD Networks’ licensing and litigation activity is warranted.
Watch CTD Networks’ patent activityFull party and counsel information
| Role | Name | Type | Detail |
|---|---|---|---|
| Plaintiff | Ctd Networks, LLC | Company | Network security IP holding company — holder of US9503470B2 and three related patentsSearch in Eureka ↗ |
| Defendant | Microsoft, Co. | Company | Microsoft Co. — developer of Microsoft 365 Defender, Defender for Cloud, and Microsoft Sentinel SIEM/XDR platformSearch in Eureka ↗ |
| Plaintiff counsel | Erik Lund | Attorney | Counsel for Ctd Networks, LLCSearch in Eureka ↗ |
| Plaintiff law firm | Whitestone Law, PLLC | Law Firm | Representing Ctd Networks, LLCSearch in Eureka ↗ |
| Defendant counsel | Henry Huang | Attorney | Counsel for Microsoft, Co.Search in Eureka ↗ |
| Defendant counsel | Jonathan J. Lamberson | Attorney | Counsel for Microsoft, Co.Search in Eureka ↗ |
| Defendant law firm | White & Case LLP | Law Firm | Representing Microsoft, Co.Search in Eureka ↗ |
| Presiding judge | Judge N/A | Judge | Court of Appeals for the Federal CircuitSearch in Eureka ↗ |
Official order — verbatim text
The Federal Circuit’s order is strictly procedural: the appeal is dismissed on withdrawal, with no claim construction, validity analysis, or infringement finding on any of the four asserted patents. The cost-bearing instruction — each side bearing its own costs — is neutral and does not indicate fault or bad faith. Because the dismissal flows from a case withdrawal rather than a merits adjudication, it carries no preclusive effect on the underlying patent rights or any future enforcement action by CTD Networks against Microsoft or third parties.
US9503470B2 — Network threat detection and security analytics patents
The four asserted patents — US9503470B2 (App. No. 14/043567), US8327442B2 (App. No. 10/746825), US9438614B2 (App. No. 13/942175), and US11171974B2 (App. No. 15/357399) — span a substantial filing period, suggesting a portfolio built across successive technology generations in network security. The patents appear directed at threat detection, network monitoring, and security analytics, technologies that underpin modern SIEM and XDR platforms. The application numbers indicate filings across multiple patent families, and the spread of publication numbers from US8327442B2 to US11171974B2 reflects a portfolio developed over more than a decade.
These patents are strategically significant because SIEM and XDR have become the architectural core of enterprise cybersecurity platforms — a market commanding multi-billion dollar valuations. Microsoft’s accused products (Sentinel, 365 Defender, Defender for Cloud) are among the most widely deployed security platforms globally. A patent holder asserting rights in this space against a hyperscaler signals either genuine differentiation in the underlying IP or a litigation-licensing strategy targeting market leaders. The absence of a merits ruling means the competitive risk from this portfolio remains unresolved for the entire XDR vendor ecosystem.
Should your security platform run an FTO against US9503470B2?
Any organisation developing or acquiring SIEM, XDR, network detection and response (NDR), or cloud security analytics capabilities should assess exposure to CTD Networks’ portfolio. The four patents cover network threat detection and security analytics — foundational functions in products built by CrowdStrike, Palo Alto Networks, Splunk, IBM QRadar, and others. Because no claim construction or invalidity ruling was issued in this case, these patents carry maximum uncertainty for FTO purposes.
PatSnap Eureka’s FTO Search Agent can map the claims of US9503470B2, US8327442B2, US9438614B2, and US11171974B2 against your product architecture, identify prior art relevant to each claim family, and flag cited references that could support a validity challenge. For M&A teams evaluating security platform acquisitions, Eureka can accelerate portfolio clearance analysis and surface litigation history across the CTD Networks patent family in minutes.
Run a freedom-to-operate analysis on US9503470B2 to assess your product’s exposure
Run FTO in Eureka →Similar Federal Circuit appeals in network security and SIEM/XDR patent litigation
Cases involving network security and SIEM/XDR patent assertions at the Federal Circuit, including appeals dismissed on withdrawal and infringement actions against cloud security platforms.
Related patent case — similar technology
Comparable case in the same technology domain. Patent holder and defendant reached resolution after proceedings.
SettledRelated infringement action — same court
Comparable Microsoft 365 Defender-adjacent infringement action. Patent enforcement dynamics analysed in depth.
Active · District CourtRelated invalidity challenge — appellate outcome
Combined invalidity and infringement action in the same technology space. Decided after substantive proceedings.
DecidedCtd Networks, LLC’s broader IP enforcement history
Ctd Networks, LLC’s full litigation history covering prior enforcement, licensing activity, and inter partes review proceedings.
Portfolio viewWhat this case signals for the network security IP landscape
A withdrawn Federal Circuit appeal over SIEM and XDR patents leaves four enforcement-ready assets in play and the market without a definitive ruling.
Withdrawal without prejudice keeps CTD Networks’ patent arsenal live
Procedural dismissal based on case withdrawal does not invalidate the four asserted patents. CTD Networks retains the ability to assert US9503470B2, US8327442B2, US9438614B2, and US11171974B2 against Microsoft or other SIEM/XDR vendors. Security product teams should treat this as a deferral, not a resolution.
No fee-shifting signals a negotiated exit rather than sanctions
The court’s order that each side bear its own costs is consistent with a commercially negotiated or strategically timed withdrawal — not a finding of frivolous litigation. This pattern typically signals that a confidential arrangement may have been reached, though the public record is silent on terms. IP counsel should monitor for licensing activity.
Four unlitigated patents create FTO risk across the XDR market
With no claim construction order or invalidity ruling on record, the four CTD Networks patents carry maximum uncertainty for freedom-to-operate analyses in network threat detection, SIEM correlation, and XDR integration. Companies building or acquiring similar capabilities should commission targeted FTO analyses against this portfolio before market entry or M&A.
Counsel substitution mid-appeal may signal a strategy pivot
The court’s simultaneous grant of a motion to withdraw and substitute counsel — alongside the dismissal order — suggests a change in litigation strategy or commercial direction at CTD Networks. Monitoring the plaintiff’s future filings and patent assignments could reveal whether a licensing program, new enforcement campaign, or portfolio sale is underway.
Ctd v Microsoft — key questions answered
The Federal Circuit dismissed CTD Networks’ appeal in Case No. 23-2429 on 24 May 2024 following a case withdrawal. CTD Networks had asserted four network security patents against Microsoft’s SIEM and XDR products. No merits ruling was issued. Each side was ordered to bear its own costs.
CTD Networks asserted four US patents: US9503470B2, US8327442B2, US9438614B2, and US11171974B2. These patents are directed at network threat detection and security analytics technologies. The accused products were Microsoft 365 Defender, Microsoft Defender for Cloud, and Microsoft Sentinel.
No. The dismissal was procedural, based on case withdrawal. The Federal Circuit issued no validity, infringement, or claim construction ruling. All four CTD Networks patents remain in force and are potentially enforceable against Microsoft or other parties in future proceedings.
The cost-bearing order means neither party was awarded litigation costs by the Federal Circuit. This neutral outcome is consistent with a voluntary or negotiated withdrawal rather than a sanctions-based dismissal. It does not preclude future litigation over the same patents, and the public record does not confirm whether any settlement was reached.
The dismissal without merits adjudication means the four CTD Networks patents carry unresolved claim scope and validity uncertainty. Companies operating in the SIEM, XDR, and cloud security analytics space should treat these patents as active FTO concerns. No judicial precedent from this case limits or clarifies the patents’ enforceability against third parties.
Monitor CTD Networks’ patent activity before it impacts your security roadmap
With four unlitigated network security patents still in force, R&D and IP teams building SIEM or XDR capabilities need real-time enforcement monitoring and FTO clarity. PatSnap Eureka tracks litigation activity, patent assignments, and claim scope changes across this portfolio.
PatSnap Eureka searches patents and litigation data to answer instantly.