DCT
1:26-cv-01345
Nixu FL IP Protection LLC v. Infoblox Federal Inc
Key Events
Complaint
Table of Contents
complaint Intelligence
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: Nixu FL IP Protection LLC (Texas)
- Defendant: Infoblox Federal, Inc. (Delaware); Infoblox, Inc. (Delaware)
- Plaintiff's Counsel: Spotts Fain, P.C.
- Case Identification: 1:26-cv-01345, E.D. Va., 05/19/2026
- Venue Allegations: Plaintiff alleges venue is proper in the Eastern District of Virginia because Defendant Infoblox, Inc. has a regular and established place of business in Herndon, Virginia, employs individuals within the district, and operates servers in Northern Virginia, and has allegedly committed acts of infringement in the district.
- Core Dispute: Plaintiff alleges that Defendant's network security software and appliances infringe a patent related to securing Domain Name System (DNS) servers against cyberattacks.
- Technical Context: The technology concerns methods for protecting DNS servers from threats like denial-of-service (DoS) attacks by integrating attack detection, automated response, and a hardened operating system into a single "appliance" package.
- Key Procedural History: The complaint alleges that Defendant had pre-suit knowledge of the patent through multiple channels, including due diligence conducted in 2023 by its investor, Warburg Pincus, which involved a virtual data room containing the patent and a meeting with one of the named inventors. The complaint also references a related patent infringement suit filed by the Plaintiff against Infoblox in the Unified Patent Court (UPC) in January 2026 and a refused pre-suit license offer.
Case Timeline
| Date | Event |
|---|---|
| 2006-03-20 | '773 Patent Priority Date |
| 2007-03-20 | '773 Patent Application Filing Date |
| 2013-12-09 | Infoblox announces "first DNS appliance that can protect itself" |
| 2014-11-25 | '773 Patent Issue Date |
| 2020-12-01 | Date by which Warburg Pincus was a substantial investor in Infoblox |
| 2023-06-01 | Approx. date Warburg Pincus representative approached '773 Patent inventor |
| 2023-08-21 | Approx. date of meeting between Warburg, Infoblox, and FusionLayer |
| 2025-04-17 | '773 Patent assigned to Plaintiff NIXU |
| 2025-12-09 | Plaintiff's counsel sends email to Infoblox's general counsel |
| 2026-01-30 | Plaintiff files UPC Action against Infoblox |
| 2026-05-19 | Complaint Filing Date |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Patent No. 8,898,773 - "Applianced Domain Name Server" (issued Nov. 25, 2014)
The Invention Explained
- Problem Addressed: The patent identifies the vulnerability of public-facing DNS servers to network security threats, such as denial-of-service (DoS) attacks Compl. ¶19 '773 Patent, col. 1:29-33 It notes that conventional responses, like increasing server capacity, were a "dead end," and that a conflict existed between "hardening" a system for security and the need to install software updates, as hardening makes patching more difficult '773 Patent, col. 1:62-67 '773 Patent, col. 2:9-12
- The Patented Solution: The invention proposes a DNS server provided as a software "appliance," which integrates a hardened operating system with pre-configured DNS software and, critically, a local attack detection and response logic '773 Patent, abstract '773 Patent, col. 2:15-18 This local logic analyzes incoming IP packets against a set of rules. If an attack is detected, the logic can add a new rule to a firewall to bar packets from the attacker's IP address, thereby blocking the attack without affecting normal traffic or overloading the server itself '773 Patent, col. 5:5-17 This creates the "illusion of a successful attack" to the malicious actor by making the server appear non-responsive '773 Patent, col. 2:24-28
- Technical Importance: This integrated "appliance" model sought to provide a more robust and manageable solution for DNS security by packaging hardening, detection, and response together, overcoming the trade-offs of prior approaches Compl. ¶22
Key Claims at a Glance
- The complaint asserts infringement of independent claims 1 and 3 Compl. ¶¶58-59
- Independent claim 3, a product claim, recites a software installation package for a domain name server comprising the following essential elements:
- a hardened operating system;
- a securely pre-configured domain name server software;
- a management interface;
- a local attack detection logic that performs analyses on IP packets from an individual client computer based on predetermined attack detection rules;
- wherein if the analyses identify an attacking client, the logic "blacklists" the client computer to indicate that its traffic should be blocked; and
- wherein the package is stored on a tangible non-transitory storage medium.
'773 Patent, col. 6:36-col. 7:14
- The complaint does not foreclose the possibility of asserting other claims.
III. The Accused Instrumentality
Product Identification
- The complaint identifies the accused instrumentalities as Infoblox's NIOS-based solutions and appliances, which include NIOS DDI, the Universal DDI Product Suite, NIOS-based physical and virtual appliances, NIOS software packages (including vNIOS and NIOS-X), and Infoblox DNS Infrastructure Protection (formerly Advanced DNS Protection) Compl. ¶56
Functionality and Market Context
- The complaint alleges that NIOS is a "software-appliance platform" that implements DNS services using a "hardened operating system, preconfigured DNS-related software modules, integrated management functionality, attack detection, and response capabilities" Compl. ¶40 The platform is alleged to use rule-based mechanisms to detect and stop network attacks targeting DNS applications Compl. ¶44 The "Grid Manager" is identified as the web-based management interface for these functions Compl. ¶42 The complaint presents this platform as directly addressing the same market need for secure DNS services that the patent describes (Compl. ¶39).
IV. Analysis of Infringement Allegations
- '773 Patent Infringement Allegations
| Claim Element (from Independent Claim 3) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| a hardened operating system | Infoblox describes its NIOS platform as running on "a security-hardened, real-time set of appliances." | ¶40 | col. 6:39 |
| a securely pre-configured domain name server software | NIOS is described as a platform for DNS service deployments that includes "preconfigured DNS-related software modules." | ¶40 | col. 6:40-41 |
| a management interface | The "Grid Manager" is the NIOS web interface that provides access for performing DNS management and administration tasks. | ¶42 | col. 6:42 |
| a local attack detection logic, wherein the attack detection logic performs one or more analyses, each of which being based on a plurality of IP packets from an individual client computer, based on a predetermined set of attack detection rules | Infoblox's Advanced DNS Protection ("ADP") system allegedly includes an "attack detection logic" that performs analyses based on a predefined set of over 2,500 rules. These analyses are allegedly performed on a plurality of IP packets from client computers. | ¶44; ¶45; ¶46 | col. 6:43-50 |
| wherein, if at least some of the analyses... identify the individual client computer as an attacking client computer, the local attack detection logic blacklists the individual client computer as an attacking client computer thereby indicating that IP traffic from the individual client computer should be blocked | The ADP system is alleged to include "rule-based blacklisting mechanisms" that identify and block traffic from attacking client computers. Custom rules can allegedly be configured to "blacklist" based on an IP address. A screenshot in the complaint shows various "BLACKLIST" rule categories in the Infoblox interface. | ¶45; ¶46; ¶47 | col. 6:51-57 |
| wherein the software installation package is stored in a tangible software carrier that constitutes a non-transitory storage medium | Infoblox allegedly distributes NIOS as a downloadable software image stored on its servers, and for physical appliances, the software is stored on the appliance's internal hardware storage. | ¶49 | col. 7:10-14 |
A screenshot from an Infoblox demo video allegedly depicts a "Grid Rules" interface with categories for blacklisting, such as "BLACKLIST DROP TCP IP" and "BLACKLIST TCP FQDN lookup" Compl. ¶47
- Identified Points of Contention:
- Scope Questions: A potential dispute may arise over the term "blacklists." The defense may argue that its accused "Drop" action or temporary "penalty box" mechanism Compl. ¶45 is functionally and technically distinct from the specific act of "blacklisting" as contemplated by the patent. The question is whether the accused functionality of blocking traffic from an identified malicious source constitutes "blacklisting" within the claim's scope.
- Technical Questions: The complaint asserts that NIOS uses a "hardened operating system" Compl. ¶40 A point of contention may be whether the security measures implemented in the NIOS OS meet the technical definition of "hardened" as used in the patent and discussed during its prosecution Compl. ¶26, or if the term requires a more specific set of low-level OS modifications not present in the accused system.
V. Key Claim Terms for Construction
The Term: "hardened operating system"
- Context and Importance: This term is a foundational element of the claimed invention, intended to distinguish it from vulnerable, general-purpose systems. Its construction will be critical in determining whether the accused NIOS platform, described as "security-hardened" Compl. ¶40, meets this limitation.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: During prosecution, the applicants defined hardening as "the process of securing a system by reducing its surface of vulnerability," including the "removal of unnecessary software, unnecessary usernames or logins and the disabling or removal of unnecessary services" Compl. ¶26 This general definition could support a broader reading.
- Evidence for a Narrower Interpretation: The same prosecution history document also provides specific examples of hardening, such as applying kernel patches like "Exec Shield or PaX" and using specific tools like "Bastille Linux" Compl. ¶26 This could support a narrower construction that requires specific types of low-level OS modification.
The Term: "blacklists"
- Context and Importance: This term describes the specific action taken by the claimed attack detection logic. The infringement case hinges on whether the accused Infoblox system performs an action that falls within the scope of this term.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The complaint points to Infoblox's own documentation and user interface, which allegedly use the term "blacklist" Compl. ¶46 Compl. ¶47 Plaintiff may argue this is an admission or, at minimum, evidence that "blacklist" in the context of the art includes Infoblox's "Drop" functionality.
- Evidence for a Narrower Interpretation: The claim states the logic "blacklists the individual client computer... thereby indicating that IP traffic...should be blocked" '773 Patent, col. 6:53-57 This language may suggest that blacklisting is an intermediate state-creating step (i.e., adding an IP to a list) rather than the blocking action itself. A party could argue that a dynamic, rule-based filtering action without a persistent "list" does not meet this definition.
VI. Other Allegations
- Indirect Infringement: The complaint alleges induced infringement, stating that Infoblox provides customers with the NIOS software package along with instructions, technical materials, and support that encourage and facilitate infringing use Compl. ¶¶61, 63 It also alleges contributory infringement, arguing the NIOS system is a material component of the invention, is not a staple article suitable for non-infringing use, and is especially adapted for the infringing purpose Compl. ¶66
- Willful Infringement: The complaint alleges willful infringement based on Defendant's alleged pre-suit knowledge of the '773 Patent. The basis for this knowledge includes: a meeting and due diligence in August 2023 involving Infoblox personnel and an inventor Compl. ¶33 Compl. ¶64; notice via a related UPC action filed in January 2026 Compl. ¶64; and direct communications with Infoblox before the suit Compl. ¶35
VII. Analyst's Conclusion: Key Questions for the Case
- A core issue will be one of definitional scope: whether the term "blacklists" in the context of the '773 Patent will be construed to cover the accused product's rule-based "Drop" and "penalty box" functionalities, or if the court will adopt a narrower definition that distinguishes the accused mechanisms.
- A second key question will be technical characterization: does the accused NIOS platform's "security-hardened" architecture satisfy the "hardened operating system" limitation, or will the definition be narrowed by prosecution history examples to require specific types of OS modifications allegedly absent from the accused products?
- Finally, a central factual question will concern willfulness: given the detailed allegations of pre-suit meetings, data room access, and related foreign litigation, the case will likely focus on whether Infoblox's continued accused activity after gaining knowledge of the patent constitutes willful and deliberate infringement.
Analysis metadata
Loading Complaint
Suggested improvements