DCT

7:25-cv-00040

Skysong Innovations LLC v. CrowdStrike Inc

Key Events
Amended Complaint
complaint Intelligence

I. Executive Summary and Procedural Information

  • Parties & Counsel:
  • Case Identification: 7:25-cv-00040, W.D. Tex., 05/16/2025
  • Venue Allegations: Venue is alleged to be proper as Defendant CrowdStrike Holdings, Inc. maintains its principal executive offices in Austin, Texas, and both defendants are alleged to conduct regular business, employ personnel, and commit acts of infringement within the Western District of Texas.
  • Core Dispute: Plaintiff alleges that Defendant's Falcon Platform, a suite of cybersecurity products, infringes five patents, assigned by Arizona State University, related to advanced cyber threat detection, mitigation, and analysis.
  • Technical Context: The technology at issue involves sophisticated cybersecurity techniques, including game-theoretic modeling, automated browser isolation, deep web data analysis, and efficient neural network computation, to proactively identify and defend against complex cyberattacks.
  • Key Procedural History: The complaint alleges that in March 2019, a named co-inventor of three of the asserted patents, Prof. Paulo Shakarian, met with senior CrowdStrike employees, including its Co-Founder and CTO, and disclosed confidential and patent-pending subject matter related to the patents-in-suit. This allegation may be central to claims of pre-suit knowledge and willful infringement.

Case Timeline

Date Event
2013-12-06 '721 Patent Priority Date
2015-11-30 '385 Patent Priority Date
2016-09-26 '831 Patent Priority Date
2017-11-03 '897 Patent Priority Date
2018-05-09 '900 Patent Priority Date
2019-03-04 Meeting alleged between Prof. Shakarian and CrowdStrike
2019-06-04 '385 Patent Issued
2020-02-25 '721 Patent Issued
2022-03-15 '900 Patent Issued
2023-10-03 '831 Patent Issued
2024-02-06 '897 Patent Issued
2025-05-16 Complaint Filed

II. Technology and Patent(s)-in-Suit Analysis

U.S. Patent No. 10,313,385 - "Systems and methods for data driven game theoretic cyber threat mitigation"

The Invention Explained

  • Problem Addressed: The patent's background section notes a lack of game-theoretic approaches to host-based cybersecurity defense that are informed by "un-conventional" sources, specifically data from darknet markets Compl. ¶24 '385 Patent, col. 2:26-31
  • The Patented Solution: The invention proposes a data-driven security game framework that models an attacker's behavior using exploit market data actively mined from the "darknet" Compl. ¶24 '385 Patent, col. 1:15-20 This framework is used to develop near-optimal defensive strategies by analyzing real-world exploit market data to anticipate an attacker's actions Compl. ¶24 '385 Patent, col. 3:4-15
  • Technical Importance: The invention provided a method to formalize and automate proactive cyber defense by incorporating real-world threat intelligence from the then-emerging darknet marketplaces, moving beyond purely reactive or theoretical defense models Compl. ¶24

Key Claims at a Glance

  • The complaint asserts at least independent method claim 8 Compl. ¶64
  • The essential elements of claim 8 include:
    • accessing data comprising dark net information associated with a computer system;
    • obtaining a set of exploits from the dark net information configured to bypass a security feature;
    • applying an exploit function which takes the set of exploits as input and returns a set of vulnerabilities;
    • creating a constraint set of vulnerabilities comprising a minimum set of dependencies to operate the computer system;
    • determining the effect of the exploits on the constraint set;
    • analyzing an application to detect a particular vulnerability; and
    • altering a configuration of the computer system to reduce potential damage Compl. ¶65
  • The complaint does not explicitly reserve the right to assert other claims but states infringement of "one or more claims" Compl. ¶64

U.S. Patent No. 10,574,721 - "Systems and methods for an automatic fresh browser instance for accessing Internet content"

The Invention Explained

  • Problem Addressed: The patent identifies the difficulty for users in managing many sources of content within a browser, as well as the security risks of information leakage and active attacks like cross-site request forgery that arise from this practice Compl. ¶29 '721 Patent, col. 1:46-47 '721 Patent, col. 3:1-7
  • The Patented Solution: The patent describes an "automatic fresh browser instance" (FBI) system that segregates different categories of web content into different, independent browser instances to enhance security Compl. ¶29 '721 Patent, col. 1:11-14 '721 Patent, col. 1:61-63 The system uses a daemon and browser extension to intercept web requests and automatically launch a new, isolated browser instance when a user attempts to access sensitive content, thereby providing protection against privacy leaks and integrity threats Compl. ¶29 '721 Patent, col. 3:1-11
  • Technical Importance: This technology automated the security practice of compartmentalization, making it accessible to novice users without requiring them to manually configure complex security settings or manage multiple browser profiles Compl. ¶29 '721 Patent, col. 3:7-11

Key Claims at a Glance

  • The complaint asserts at least independent system claim 1 Compl. ¶105
  • The essential elements of claim 1 include:
    • a processor operable to receive data defining first and second web content classes with different URLs, where the second class has a security risk;
    • generate a first browser instance for the first web content class;
    • intercept a request from the first browser instance to access a URL from the second web content class;
    • confirm the URL is not being accessed by another separate, already-running browser for that class by implementing a daemon, receiving the request via a browser extension, forwarding it to the daemon, and confirming the status; and
    • launch a new browser for the second web content class Compl. ¶106
  • The complaint does not explicitly reserve the right to assert other claims but alleges infringement of "one or more claims" Compl. ¶105

U.S. Patent No. 11,275,900 - "Systems and methods for automatically assigning one or more labels to discussion topics shown in online forums on the dark web"

  • Technology Synopsis: The patent addresses the challenge of classifying content on the deep and dark web, where manual labeling is time-consuming, un-scalable, and hindered by a scarcity of labeled data Compl. ¶34 '900 Patent, col. 2:10-15 It discloses a computer-implemented system that automatically assigns one or more labels or tags in a hierarchical structure to discussion topics found in these forums Compl. ¶34 '900 Patent, col. 1:17-20 '900 Patent, col. 3:10-14
  • Asserted Claims: At least independent method claim 12 is asserted Compl. ¶134
  • Accused Features: CrowdStrike's Falcon Platform services that monitor the deep web, use machine learning to classify data, and apply descriptive tags are accused of infringement Compl. ¶¶137-144

U.S. Patent No. 11,775,831 - "Cascaded computing for convolutional neural networks"

  • Technology Synopsis: The patent addresses the high computational and memory intensity of Convolutional Neural Networks (CNNs), which makes them difficult to use for real-time classification on low-power devices Compl. ¶39 '831 Patent, col. 1:22-29 The invention proposes a "cascaded computing" method that first performs an approximate computation on a limited set of data (e.g., the most significant bits) to identify a maximum value, and only then performs a full-precision computation on the data set that exhibited that maximum, thereby reducing the total computation required Compl. ¶39 '831 Patent, col. 1:33-50
  • Asserted Claims: At least independent claim 1 is asserted Compl. ¶159
  • Accused Features: The Falcon Platform's use of machine learning models, such as its character-level CNN "Kestrel," for malware detection is accused of using this cascaded computing method to efficiently process data Compl. ¶¶164-170

U.S. Patent No. 11,892,897 - "Systems and methods for predicting which software vulnerabilities will be exploited by malicious hackers to prioritize for patching"

  • Technology Synopsis: The patent addresses the shortcomings of prior methods for prioritizing software vulnerability patching, which were often ineffective and not predictive of actual exploitation Compl. ¶44 '897 Patent, col. 1:45-2:7 The invention uses machine learning models that analyze features from various data sources, including social network activity on the dark web and the National Vulnerability Database, to predict which vulnerabilities are likely to be exploited in the wild, thus enabling better prioritization for patching Compl. ¶44 '897 Patent, col. 4:20-23
  • Asserted Claims: At least independent method claim 1 is asserted Compl. ¶184
  • Accused Features: The Falcon Platform's Exposure Management module and its ExPRT.AI model, which analyze data from multiple sources to predict the likelihood of vulnerability exploitation and assign a dynamic risk score, are accused of infringement Compl. ¶¶186 Compl. ¶191

III. The Accused Instrumentality

Product Identification

  • The accused products are collectively identified as the CrowdStrike Falcon Platform, a cloud-based software-as-a-service ("SaaS") platform for endpoint security, including modules such as Falcon Prevent, Falcon Exposure Management, and Falcon Adversary Intelligence (Compl. ¶7; Compl. ¶8; Compl. ¶9; Compl. ¶10; Compl. ¶11; Compl. ¶12; Compl. ¶13; Compl. ¶14; Compl. ¶15; Compl. ¶16; Compl. ¶17; Compl. ¶18; Compl. ¶19; Compl. ¶20; Compl. ¶21; Compl. ¶22; Compl. ¶23; Compl. ¶24; Compl. ¶25; Compl. ¶26; Compl. ¶27; Compl. ¶28; Compl. ¶29; Compl. ¶30; Compl. ¶31; Compl. ¶32; Compl. ¶33; Compl. ¶34; Compl. ¶35; Compl. ¶36; Compl. ¶37; Compl. ¶38; Compl. ¶39; Compl. ¶40; Compl. ¶41; Compl. ¶42; Compl. ¶43; Compl. ¶44; Compl. ¶45; Compl. ¶46; Compl. ¶47; Compl. ¶48; Compl. ¶49; Compl. ¶50; Compl. ¶51).

Functionality and Market Context

  • The Falcon Platform is implemented on endpoint devices via a single, lightweight "Falcon sensor" or "agent" that protects the device and communicates with the "CrowdStrike Security Cloud" Compl. ¶52 This cloud architecture, which includes the "Threat Graph" database, processes and stores trillions of security events per week to deliver its security capabilities Compl. ¶¶55 Compl. ¶68
  • The complaint provides a visual illustrating the platform's "Single platform, console, and agent" design, which allows it to converge security and IT functions from a unified console Compl. ¶53 Compl. p. 14
  • The platform's modules perform functions such as dark web monitoring, vulnerability assessment using AI models like ExPRT.AI, and threat intelligence analysis Compl. ¶¶70 Compl. ¶79
  • The complaint also includes a visual showing the concentric layers of functionality supported by the single agent, including EDR, Cloud Security, and Intelligence Compl. ¶54 Compl. p. 15

IV. Analysis of Infringement Allegations

'385 Patent Infringement Allegations

Claim Element (from Independent Claim 8) Alleged Infringing Functionality Complaint Citation Patent Citation
accessing data comprising dark net information associated with a computer system; The Falcon Adversary Intelligence module implements dark web monitoring, providing alerts to malicious activity across the open, deep, and dark web. ¶70 col. 3:4-7
obtaining a set of exploits from the dark net information, the set of exploits configured to bypass a security feature of the computer system; The Falcon platform's prior Falcon Intelligence Recon module monitored criminal forums and implemented "Vulnerability Exploit Intelligence," described as exploits configured to penetrate a system. ¶¶75-76 col. 3:40-44
applying an exploit function which takes the set of exploits as input and returns a set of vulnerabilities; The Falcon Adversary Intelligence service tracks threat actors and attributes vulnerabilities to them, connecting specific actors and exploits with associated vulnerabilities. A visual shows 326 vulnerabilities attributed to 78 actors. ¶77; Compl. p. 28 col. 4:1-4
creating a constraint set of vulnerabilities of the computer system from the set of vulnerabilities comprising a minimum set of dependencies to operate the computer system... Falcon Adversary Intelligence detects vulnerabilities attributed to actors based on a customer's computer "environment." A dashboard visual shows "1.6K" assets with "Vulnerability IDs" based on prevalent actors. ¶¶80-81; Compl. p. 32 col. 3:32-40
...wherein application of the set of exploits on the computer system comprises determining the effect of the set of exploits on the constraint set of vulnerabilities...; The platform demonstrates this by showing 326 "Vulnerabilities attributed to 78 actors" based on a customer's computer "environment." ¶82 col. 4:1-4
analyzing an application associated with the set of exploits on the computer system to detect a particular vulnerability...; The Falcon platform allows a user to analyze a criminal group's profile (e.g., "CARBON SPIDER") to reveal "Actor activity," which includes endpoint detections and vulnerabilities on protected computers. ¶84 col. 13:50-54
and altering a configuration of the computer system in response to the analysis...to reduce potential damage of a cyberattack. The Falcon platform's "Kill chain" tab for an adversary provides an "Exploitation" section which contains CVEs the actor is known to leverage; this vulnerability information "can be sent to the vulnerability management team to prioritize patching." ¶89 col. 13:50-62

'721 Patent Infringement Allegations

Claim Element (from Independent Claim 1) Alleged Infringing Functionality Complaint Citation Patent Citation
...receive data defining a first web content class and a second web content class...the second web content class further being associated with sensitive information presenting a security risk; CrowdStrike's platform employs a "Zero Trust model" that can classify access requests to URLs as, for example, "Isolate" or "Do not Isolate," defining at least two content classes. The "Isolate" class is used to protect from internet threats. ¶¶108-110 col. 4:55-67
generate a first browser instance...associated with the first web content class; The Falcon Platform classifies a web page as "Normal browsing" or "Isolated browsing," either of which can be the first web content class. ¶111 col. 4:55-67
intercept a request to access web content from the first browser instance, the request defining a URL of the second plurality of URLs...; The platform intercepts access requests to "verify[] the identity, context and policy adherence to each access request." ¶112 col. 7:31-39
confirm that the URL is not being accessed by another separate already-running browser instance...by implementing a daemon outside the first browser instance that tracks active browser instances...; The platform's Zero Trust Network Access ("ZTNA") functions in the background to autonomously check and enforce security policies, which constitutes the claimed daemon. The platform can employ "quarantine," "isolation," and "containment." ¶¶114-115 col. 4:42-54
...receiving the request via a browser extension...forwarding the request from the browser extension to the daemon using a native application...; Cloudflare describes how the CrowdStrike Falcon Platform can employ "Browser Isolation policies" using a browser extension. It can also use a "WARP" client as an intermediary native application between the browser and the ZTNA. ¶¶117-118 col. 8:1-10
...and launch a new browser for accessing the web content associated with the second web content class... The platform provides "conditional access" to a web page classified as "isolated," which is presented in a new browser, as distinct from a page classified as "Do not Isolate." ¶116; Compl. ¶121 col. 8:1-10

Identified Points of Contention

  • Scope Questions ('385 Patent): A potential point of contention is whether the accused Falcon Platform, which performs vulnerability management, executes the specific, formal steps of the game-theoretic framework claimed in the '385 Patent. For instance, does identifying vulnerabilities in a customer's environment Compl. ¶80 meet the claim limitation of "creating a constraint set...comprising a minimum set of dependencies to operate the computer system"? The interpretation of "minimum set of dependencies" may be a central dispute.
  • Architectural Questions ('721 Patent): The infringement theory for the '721 Patent appears to rely on the integration of CrowdStrike's platform with third-party services like Cloudflare Compl. ¶¶109 Compl. ¶118 A key question will be whether this distributed, cloud-based security architecture constitutes the specific "daemon outside the first browser instance" and "browser extension" structure required by the claim, which the patent specification appears to describe as a client-side implementation (e.g.,'721 Patent, col. 7:1-9).

V. Key Claim Terms for Construction

'385 Patent

  • The Term: "exploit function"
  • Context and Importance: This term is central to claim 8 and appears to describe a core analytical step of the invention. The dispute may turn on whether CrowdStrike's process of associating known exploits with threat actors and vulnerabilities Compl. ¶77 performs the function required by the claim. Practitioners may focus on this term because its definition will determine if a general threat intelligence correlation engine falls within the scope of a more specific, functional step in a game-theoretic model.
  • Intrinsic Evidence for Interpretation:
    • Evidence for a Broader Interpretation: The patent defines the "Exploit Function" simply as a function that "takes a set of exploits as input and returns a set of vulnerabilities" '385 Patent, col. 3:60-62, which could support an argument that any process performing this input-output mapping qualifies.
    • Evidence for a Narrower Interpretation: The context of the patent is a "rigorous and thoroughly analyzed framework" for penetration testing '385 Patent, col. 3:4-7 A defendant may argue this implies the "exploit function" is not just a correlation but a specific algorithmic component within the claimed game-theoretic model, requiring more than just linking data points.

'721 Patent

  • The Term: "browser instance"
  • Context and Importance: The claim requires generating a "first browser instance" and launching a "new browser" for a second content class Compl. ¶106 The infringement allegation relies on CrowdStrike's platform classifying browsing as "Normal" or "Isolated" Compl. ¶111 The definition of "browser instance" is critical to determining whether an "isolated browsing" session, which may occur within the same browser application via sandboxing or remote browser isolation technology, constitutes a "new" or "separate" browser instance as required by the patent.
  • Intrinsic Evidence for Interpretation:
    • Evidence for a Broader Interpretation: The patent's background focuses on the problem of a user having "multiple windows open" and difficulty locating "tabs and content" '721 Patent, col. 1:46-47 This could support an interpretation where a "browser instance" refers to any functionally separate browsing context, even if running under a single parent application.
    • Evidence for a Narrower Interpretation: The patent describes an "instance of a web browser" as a "software process that executes the browser code and has associated with it a profile" '721 Patent, col. 3:40-43 This language may support a narrower definition requiring a distinct operating system process with its own profile, rather than merely a sandboxed tab or a remotely rendered session.

VI. Other Allegations

  • Indirect Infringement: The complaint alleges that Defendants induce infringement of all asserted patents. The allegations are based on Defendants providing the Accused Products along with instructions, guides, manuals, marketing, technical support, and customer contracts that allegedly direct and encourage customers and partners to use the Falcon Platform in a manner that performs the claimed methods (e.g., for the '385 Patent, Compl. ¶¶94-99).
  • Willful Infringement: The complaint alleges willful infringement for all asserted patents. For the '385, '900, and '897 patents, willfulness is supported by allegations of pre-suit knowledge stemming from a March 2019 meeting where an inventor, Prof. Shakarian, allegedly disclosed the patent-pending technology to senior CrowdStrike employees Compl. ¶¶59-61 Compl. ¶102 For all patents, willfulness is also alleged based on knowledge of the patents since at least the filing of the initial complaint Compl. ¶102 Compl. ¶122 Compl. ¶156 Compl. ¶181 Compl. ¶205

VII. Analyst's Conclusion: Key Questions for the Case

  1. A central issue of technical scope will be whether the commercially implemented, AI-driven security features of the accused Falcon Platform perform the specific, often academic, analytical steps recited in the patents. For instance, for the '385 patent, does CrowdStrike's system of attributing vulnerabilities to threat actors meet the requirement of "creating a constraint set...comprising a minimum set of dependencies to operate the computer system", or is there a material difference between a commercial threat intelligence product and the claimed game-theoretic model?

  2. A key question of architectural equivalence will arise for the '721 patent: can CrowdStrike's cloud-native, Zero Trust security architecture, which relies on background services and integrations, be considered equivalent to the patent's described client-side system of a "daemon outside the first browser instance" and an associated "browser extension", or does this represent a fundamental difference in the location and operation of the infringing components?

  3. A critical evidentiary question will concern the allegation of pre-suit knowledge. The outcome of discovery related to the alleged March 2019 meeting between an inventor and senior CrowdStrike personnel will likely be determinative for the willfulness claims associated with the '385, '900, and '897 patents, and could significantly influence the overall complexion and potential damages in the case.

Loading Amended Complaint