DCT

1:26-cv-01488

PacSec3 LLC v. Fastly Inc

Key Events
Amended Complaint
complaint Intelligence

I. Executive Summary and Procedural Information

  • Parties & Counsel:
  • Case Identification: 1:26-cv-01488, S.D.N.Y., 04/10/2026
  • Venue Allegations: Plaintiff alleges venue is proper because Defendant maintains a regular and established place of business in the Southern District of New York and has consented to the district for this action.
  • Core Dispute: Plaintiff alleges that Defendant's DDoS protection and firewall systems infringe a patent related to methods for defending against network packet flooding attacks.
  • Technical Context: The technology at issue addresses methods for mitigating Distributed Denial of Service (DDoS) attacks, a common and significant cybersecurity threat to internet-facing services.
  • Key Procedural History: Plaintiff identifies itself as a non-practicing entity and notes that it and its predecessors have entered into settlement licenses with other entities. The patent-in-suit, U.S. Patent No. 7,523,497, was the subject of an ex parte reexamination, which concluded with the confirmation of the patentability of asserted claims 7 and 10.

Case Timeline

Date Event
2000-11-16 U.S. Patent No. 7,523,497 Priority Date
2009-04-21 U.S. Patent No. 7,523,497 Issued
2012-12-15 Earliest observed date of Defendant's accused products via web archive
2023-05-22 Reexamination Certificate for U.S. Patent No. 7,523,497 Issued
2026-04-10 Complaint Filed

II. Technology and Patent(s)-in-Suit Analysis

U.S. Patent No. 7,523,497 - "PACKET FLOODING DEFENSE SYSTEM"

  • Patent Identification: U.S. Patent No. 7,523,497 ("the '497 Patent"), titled "PACKET FLOODING DEFENSE SYSTEM," issued April 21, 2009.

The Invention Explained

  • Problem Addressed: The patent describes the problem of "packet flooding attacks," where an attacker overwhelms a victim's network bandwidth with useless data, rendering services slow or unavailable for legitimate users '497 Patent, col. 2:7-14 A key challenge identified is that attackers can falsify source address information, making it difficult to block malicious traffic without impacting legitimate users '497 Patent, col. 2:2-6
  • The Patented Solution: The invention proposes a distributed defense system where cooperating routers and the target site (victim) work together to mitigate attacks '497 Patent, abstract The core concept involves using "packet marks" applied by routers to trace the forwarding path of data packets. This path information, which is independent of potentially falsified source data, allows a victim site to identify the specific network paths delivering unwanted traffic and request that upstream routers limit the transmission rate from those paths '497 Patent, col. 3:62 - col. 4:5
  • Technical Importance: The described approach sought to provide a more resilient defense against DDoS attacks than simple source-IP-based filtering, which could be circumvented by address spoofing '497 Patent, col. 2:2-6

Key Claims at a Glance

  • The complaint asserts independent method claim 10 and dependent claims 7 and 8 '497 Patent, col. 10:28-53 Compl. ¶15
  • The essential elements of independent claim 10 include:
    • Determining a path by which data packets arrive at a router via "packet marks" provided by upstream routers, where the path comprises all routers in the network through which the packets are routed.
    • Classifying the received data packets by their determined path.
    • Associating a maximum acceptable transmission rate with each class (path) of data packets.
    • Allocating a transmission rate for unwanted data packets that is equal to or less than the associated maximum rate.
  • The complaint indicates that its allegations are preliminary and subject to change, which may suggest the right to assert additional claims is preserved Compl. ¶21

III. The Accused Instrumentality

Product Identification

  • The accused instrumentality is Defendant's "Fastly DDoS Protection" service, described as one or more "firewall systems" Compl. ¶15 Compl., Ex. B, p. 4

Functionality and Market Context

  • The complaint alleges that Fastly operates a global edge network comprised of multiple Points of Presence (POPs) that provides DDoS mitigation services Compl., Ex. B, p. 6 The accused service allegedly uses Border Gateway Protocol (BGP) telemetry and Anycast routing to analyze ingress traffic characteristics, such as source IP, ASN, and geolocation, to infer packet paths and make routing decisions Compl., Ex. B, p. 9 Compl., Ex. B, p. 12 Based on this analysis, the service applies policies such as rate-limiting to block or throttle traffic classified as unwanted or part of an attack, thereby protecting customer applications and APIs Compl., Ex. B, p. 13 A network diagram in the complaint depicts Fastly's edge network topology, highlighting how traffic is filtered before reaching the "Origin Router" Compl., Ex. B, p. 6

IV. Analysis of Infringement Allegations

The complaint provides a claim chart in Exhibit B that maps elements of the asserted claims to the functionality of the accused Fastly DDoS Protection service Compl. ¶21

'497 Patent Infringement Allegations

Claim Element (from Independent Claim 10) Alleged Infringing Functionality Complaint Citation Patent Citation
determining a path by which data packets arrive at said router via packet marks provided by routers leading to said host computer; said path comprising all routers in said network via which said packets are routed to said computer; Fastly's system allegedly determines ingress routes using BGP telemetry and Anycast routing. It is alleged to analyze metadata such as source IP, ASN, and ingress location to infer packet paths. The complaint contends that this telemetry acts as "packet marks" for determining routing paths. A diagram from Fastly marketing materials illustrates how the DDoS Protection service positions "Fastly Edge Nodes" to filter traffic from attackers while allowing traffic from "Real Users" to pass to the "Customer Origin" server Compl., Ex. B, p. 11 Ex. B, p. 9 col. 3:62 - col. 4:5
classifying data packets received at said router via packet marks provided by routers leading to said host computer by path; The complaint alleges that Fastly classifies traffic based on ingress characteristics and content-aware routing rules, using aspects like client geolocation, user status, and URL paths. This classification allegedly relies on BGP information to determine traffic paths and reroute high-nuisance traffic to protect hosts. Ex. B, p. 12 col. 8:12 - col. 8:16
associating a maximum acceptable transmission rate with each class of data packet received at said router; and Fastly is alleged to apply dynamic "rate limiting" and traffic shaping rules to different classes of traffic, which can be defined by ASN, region, or IP range. The complaint asserts that this establishes an "assigned acceptable bandwidth threshold" for each identified traffic group. Ex. B, p. 13 col. 8:62 - col. 8:64
allocating a transmission rate equal to or less than said maximum acceptable transmission rate for unwanted data packets. The accused service is alleged to allocate a lower or zero throughput for unwanted traffic by "dropping irrelevant non-HTTP/HTTPS traffic" or "blocking" traffic from malicious sources. This is allegedly done at the network edge via automated rules and policies that enforce throttling or blocking when allowed thresholds are exceeded. Ex. B, p. 14 col. 10:49 - col. 10:53

Identified Points of Contention

  • Scope Questions: A primary issue may be whether Fastly's use of BGP telemetry and traffic metadata qualifies as the "packet marks provided by routers" required by the claim. The defense may argue that this claim language, read in light of the specification, requires a literal modification or "stamping" of the data packet itself, whereas Fastly's system relies on analyzing routing protocol information that is external to the packet content.
  • Technical Questions: The infringement read on the claim limitation "said path comprising all routers in said network" may be contested. The analysis will raise the question of whether Fastly's system determines the complete, end-to-end path of a packet across the internet, or if it only determines the path from the internet edge into its own network infrastructure.

V. Key Claim Terms for Construction

  • The Term: "packet marks"
  • Context and Importance: The definition of this term appears central to the dispute. Plaintiff's infringement theory depends on construing this term to cover BGP telemetry and other metadata used in modern, software-defined networks, while the patent was filed in 2000.
  • Intrinsic Evidence for Interpretation:
    • Evidence for a Broader Interpretation: The specification describes the invention's purpose as using "attacker-independent information about the path a packet takes to allocate forwarding bandwidth" '497 Patent, col. 4:1-3 This focus on the function of the information (path determination) rather than a specific form could support an interpretation that includes BGP path data.
    • Evidence for a Narrower Interpretation: The complaint's own exhibit quotes the patent specification stating, "As a packet goes to and from a router, they each stamp the packet, so the next router knows where the packet has come from and where it is going" ('497 Patent, col. 4:3-5, as cited in Compl., Ex. B, p. 9). This language may support a narrower construction requiring a literal alteration of the packet data.

VI. Other Allegations

  • Indirect Infringement: The complaint's prayer for relief seeks judgment that Defendant induced infringement by "instructing to use Defendant's products" Compl., prayer a The complaint does not, however, plead specific factual allegations detailing the acts of inducement beyond the general offering and sale of the accused services Compl. ¶15
  • Willful Infringement: The complaint does not allege pre-suit knowledge of the '497 Patent. Instead, it makes a contingent allegation for willful infringement, stating that willfulness and treble damages should be declared if discovery reveals that Defendant knew of the patent prior to the lawsuit and knew its conduct constituted infringement Compl., prayer e The complaint does allege that Defendant "made no attempt to design around the claims" ('497 Patent, Compl. ¶17).

VII. Analyst's Conclusion: Key Questions for the Case

  • A core issue will be one of definitional scope: Can the term "packet marks," which the patent specification describes as a "stamp" on a packet, be construed to cover the BGP telemetry and metadata analysis used by Fastly's modern DDoS mitigation platform? The case may turn on whether this older patent language can be applied to a newer, more abstract method of path determination.
  • A key evidentiary question will be one of technical proof: Can Plaintiff provide evidence that the accused system determines a "path comprising all routers in said network" as required by the plain language of Claim 10? The technical feasibility and practical implementation of this claim element within Fastly's service will likely be a significant point of factual dispute.
Loading Amended Complaint