DCT

5:26-cv-02941

Speech Transcription LLC v. Malwarebytes Inc

Key Events
Amended Complaint
complaint Intelligence

I. Executive Summary and Procedural Information

  • Parties & Counsel:
  • Case Identification: 3:26-cv-02941, N.D. Cal., 07/23/2026
  • Venue Allegations: Venue is alleged based on Defendant maintaining an established and regular place of business in the district and committing acts of patent infringement from that location.
  • Core Dispute: Plaintiff alleges that Defendant's ThreatDown endpoint security products infringe a patent related to a dedicated hardware-based subsystem for managing and executing computer security functions.
  • Technical Context: The technology addresses performance and security vulnerabilities in traditional endpoint security by offloading security processing from the host computer to a separate, isolated hardware module.
  • Key Procedural History: The complaint highlights the prosecution history of the asserted patent, noting that the Patent Trial and Appeal Board (PTAB) reversed an examiner's rejection. Following the PTAB decision and the Supreme Court's ruling in Alice, the applicant amended the claims to add limitations related to "hardware structure" to secure allowance, a point that may become central to claim construction.

Case Timeline

Date Event
2004-09-14 '799 Patent Priority Date
2014-08-08 PTAB reverses examiner's rejection of claims
2014-11-03 Inventor interview with USPTO examiner to add "hardware structure"
2015-01-20 '799 Patent Issues
2026-07-23 Complaint Filed

II. Technology and Patent(s)-in-Suit Analysis

U.S. Patent No. 8,938,799 - "SECURITY PROTECTION APPARATUS AND METHOD FOR ENDPOINT COMPUTING SYSTEMS"

  • Patent Identification: U.S. Patent No. 8,938,799, "SECURITY PROTECTION APPARATUS AND METHOD FOR ENDPOINT COMPUTING SYSTEMS", issued January 20, 2015.

The Invention Explained

  • Problem Addressed: The patent's background section describes the problems with conventional, host-based security software. Installing and running multiple security applications directly on a host computer can lead to software conflicts, registry corruption, performance degradation, and increased IT management costs Compl. ¶15 '799 Patent, col. 3:49-67 Furthermore, security software running on the host is vulnerable to being disabled by malware that compromises the host's operating system Compl. ¶16
  • The Patented Solution: The invention proposes a different architecture: a dedicated "security subsystem" physically or logically interposed in the communication path between the network and the host computer Compl. ¶15 This subsystem, described as a "Security Utility Blade" (SUB), contains its own processing resources and executes security functions in its own hardware, distinct from the host's processor '799 Patent, col. 5:17-27 '799 Patent, col. 6:60-67 This design isolates security operations, preventing them from degrading host performance and making them more resilient to attacks on the host Compl. ¶16 Figure 2A of the patent illustrates this concept, showing the SUB (101) positioned between the network and the host endpoint motherboard '799 Patent, FIG. 2A
  • Technical Importance: This architecture represented an effort to resolve the inherent conflict between robust security and system performance by creating a hardware-based, isolated environment for security functions at the endpoint Compl. ¶16

Key Claims at a Glance

  • The complaint asserts independent claim 16 and dependent claim 19 of the '799 Patent Compl. ¶33
  • Independent Claim 16 is broken down into the following essential elements:
    • A security subsystem configurable in the path of communications between a network and a host system of a network endpoint;
    • The security subsystem comprising processing resources at least for providing security for the host system, in part by executing security function software modules;
    • Wherein the processing means comprises at least:
      • holding and executing in hardware means for at least one defense function software module for providing at least one defense function; and
      • agent means for providing at least one immunization function.
  • The complaint notes that Plaintiff may assert additional claims Compl. ¶33

III. The Accused Instrumentality

Product Identification

  • The Accused Instrumentalities are Defendant's "ThreatDown product portfolio," which includes an "Endpoint Security Management Platform" and the "single-tenant Nebula platform" Compl. ¶28

Functionality and Market Context

  • The complaint alleges that the accused platform protects endpoint devices by deploying processing resources, including "Nebula plugins and a lightweight agent," at each protected endpoint Compl. ¶28 These resources are alleged to be positioned in the communication path between the network and the host system Compl. ¶28 The complaint further alleges that these components "hold and execute" security software modules to provide defense functions (e.g., endpoint detection, ransomware rollback) and immunization functions (e.g., vulnerability management, DNS web content filtering) Compl. ¶28 The platform is also alleged to maintain the integrity of its own components and prevent the host from modifying its resources Compl. ¶28

No probative visual evidence provided in complaint.

IV. Analysis of Infringement Allegations

The complaint alleges that the Accused Instrumentalities infringe at least Claim 16 of the '799 Patent. The core allegations are summarized below.

'799 Patent Infringement Allegations

Claim Element (from Independent Claim 16) Alleged Infringing Functionality Complaint Citation Patent Citation
A security subsystem configurable in the path of communications between a network and a host system of a network endpoint... The ThreatDown platform allegedly deploys resources, including plugins and an agent, that are positioned in the path of communications between the network and the host systems of protected endpoints. ¶28 col. 10:5-9
...the security subsystem comprising processing resources at least for providing security for the host system, in part by executing security function software modules... The accused platform allegedly deploys its own processing resources, including Nebula plugins and a lightweight agent, to execute security function software modules. ¶28 col. 6:60-67
...holding and executing in hardware means for at least one defense function software module for providing at least one defense function... The accused platform's components allegedly "hold and execute" defense function software modules, such as those for endpoint detection and response, ransomware rollback, and brute force protection. ¶28 col. 8:46-54
...and agent means for providing at least one immunization function. The accused platform's components allegedly provide immunization functions, including vulnerability management, patch management, and DNS web content filtering. ¶28 col. 8:63-67
  • Identified Points of Contention:
    • Scope Questions: A central question may be whether the accused products-described as a platform with "plugins" and a "lightweight agent"-constitute the "security subsystem" with "hardware means" required by the claim. Given that the "in hardware" language was added to secure allowance Compl. ¶20, a significant dispute may arise over whether a software-centric architecture can satisfy this limitation.
    • Technical Questions: The infringement theory raises the question of whether the accused "lightweight agent" is architecturally equivalent to the patent's "Security Utility Blade." The analysis may focus on whether the agent is truly "in the path of communications" in the manner described by the patent, or if it is a more conventional software process running on the host with network monitoring capabilities.

V. Key Claim Terms for Construction

  • The Term: "holding and executing in hardware means"

    • Context and Importance: This term is identified in the complaint as a means-plus-function limitation subject to 35 U.S.C. § 112, ¶ 6 Compl. ¶22 It was added during prosecution after the PTAB's reversal and the Supreme Court's Alice decision, explicitly to add "hardware structure" as a condition of allowance Compl. ¶¶19-20 Its construction will be paramount, as it directly addresses the core novelty asserted by the patentee during prosecution.
    • Intrinsic Evidence for Interpretation:
      • Evidence for a Broader Interpretation: A party might argue that "hardware means" could encompass any processing resources separate from the primary host CPU, even if they are part of the same physical device, so long as they perform the claimed function. The specification notes the circuitry "may include one or more processors" '799 Patent, col. 6:62-64, which could be argued to not require a completely separate physical blade.
      • Evidence for a Narrower Interpretation: The corresponding structures identified in the complaint are the "Repository and Execution Unit 108" and the "Security Utility Unit 304" Compl. ¶17 The specification consistently describes these as components of a distinct hardware apparatus, the "Security Utility Blade (SUB)" '799 Patent, FIG. 3 '799 Patent, FIG. 5A, which is shown as a separate module attached to or embedded in a motherboard '799 Patent, FIGS. 2A-2D The prosecution history further suggests a narrow definition was intended and required for allowance Compl. ¶20
  • The Term: "agent means"

    • Context and Importance: This is also identified as a means-plus-function limitation Compl. ¶22 Its scope will determine the specific "immunization function" capabilities required for infringement.
    • Intrinsic Evidence for Interpretation:
      • Evidence for a Broader Interpretation: A party could argue this term covers any software component that performs the general function of providing an immunization function.
      • Evidence for a Narrower Interpretation: The complaint identifies the corresponding structure as the "Unified Agent 109 and its sub-agents" Compl. ¶22 The patent's detailed description breaks down the Unified Agent into several specific sub-agents for functions like Patch Management, Configuration Management, and Vulnerability Scanning '799 Patent, col. 12:40-13:51 A narrower construction would likely require the accused feature to perform functions corresponding to these specifically disclosed sub-agents.

VI. Other Allegations

  • Indirect Infringement: The complaint alleges induced infringement, stating that Defendant provides "product literature and website materials inducing end users and others to use its products in the customary and intended manner that infringes" Compl. ¶36 Compl. ¶37 The complaint also makes a general allegation of contributory infringement Compl. ¶33
  • Willful Infringement: The willfulness allegation is based on post-suit conduct. The complaint alleges that service of the complaint constitutes actual knowledge of infringement and that Defendant's continued infringement thereafter is willful Compl. ¶31 Compl. ¶36

VII. Analyst's Conclusion: Key Questions for the Case

The dispute appears to center on fundamental questions of claim scope and technical equivalence, driven by the patent's specific prosecution history.

  • A core issue will be one of definitional scope: can the term "holding and executing in hardware means," which was added to the claims to impart "hardware structure" and overcome prior art, be construed to read on the accused "lightweight agent" and "Nebula plugins"? The case may turn on whether these software components are determined to be the kind of distinct hardware apparatus described in the patent's specification and contemplated during prosecution.
  • A key evidentiary question will be one of architectural equivalence: does the accused platform, which relies on an agent installed on the endpoint, implement the same structure and provide the same functional isolation as the patent's "Security Utility Blade" that is physically or logically interposed "in the path of communications"? The analysis will likely scrutinize whether the accused system achieves the claimed hardware-level separation from the host or operates as a more conventional, albeit advanced, software security solution.
Loading Amended Complaint