`Mail Stop 8
`Director of the U.S. Patent & Trademark Office
`P.O. Box 1450
`Alexandria, VA 22313-1450
`St., Suite 400S, Oakland, CA 94612
`In the above—entitled case, the following patent(s) have been included:
`In Compliance with 35 § 290 and/or 15 U.S.C. § 1116 you are hereby advised that a court action has been
`filed in the U.S. District Court
`on the following
`X Patents or
`[1 Trademarks:
`CV 13-05808 DMR
`Oakland Division, 1301 Clay
`(] Answer
`C] Cross Bill
`(| Other Pleading
`(J Amendment
`7, 613, 718
`In the above—entitled case, the following decision has been rendered or judgementissued:
`December17, 2013
`Richard W. Wieking
`Valerie Kyono
`Copy 1—Uponinitiation of action, mail this copy to Commissioner Copy 3—Uponterminationof action, mail this copy to Commissioner
`Copy 2—Uponfiling document adding patent(s), mail this copy to Commissioner Copy 4—Casefile copy


05808 Documenti Filed12/16/13
`and partner feeds process 100 millions
`messages par day
`Recurrent Pattern Detection
`See WP-Proofpoint-Close-the-Zero-Hour-Gap (attached as ExhibitI).
` Proofpoint’s Targeted Attack Protection and Malware Analysis Service (also known as
`Next Generation Detection) allow unknown malicious attacks that are missed bytraditional signature
`based detection to be caught. Proofpoint’s Malware Analysis Service utilizes anomalyticsto identify
`suspicious files and begins the process of analyzingthe files in a sandbox for signs of a malware
`attack. DS-Proofpoint-Targeted-Attack-Protection (attached as Exhibit J).
`39.|On September5, 2013, a wholly-owned subsidiary of Proofpoint merged with and into
`Armorize Technologies, Inc. (“Armorize”), with Armorize surviving as a wholly-owned subsidiary of
`Proofpoint. Armorize develops and markets SaaS anti-malware products and real-time dynamic
`detection of next generation threats. Proofpoint Form 10-Q (attached as Exhibit K).
`40._—_Proofpoint paid $25,000,000 in cash for Armorize and has beenutilizing Armorize
`technologies in Proofpoint’s products for nearly a year before the acquisition. See Proofpoint, Inc. to
`Acquire Armorize Technologies, Inc.pdf (attached as Exhibit L). Armorize products include
`HackAlert Anti-Malware, CodeSecure Automated Static Source Code Analysis and SmartWAF Web
`Application Firewall. Information concerning these products is shown below:


35808 Documenti Filedi2/16/13
.ge10 of 40
` COC SECUlE”qutomated Static Source Code Analysis Platform
`+ Delivers formal static source code analysis and software verification on a plug-and-play appliance
`Identifies critical security vulnerabilities throughout development
`+ Faciitates proactive Web application vulnerability remediation
`Inplements built-in compiler technology for increased accuracyand speed
`* Deploys as browser-accessible appliance to ensure zero software installation overhead
`+ Exports results to SmartWAF™ for immediate vulnerable entry point protection
`* Supports enterprise, consulting and SaaS deployments
`HackAlert"™ web Matware Monitoring andAlerting SaaS
`* Monitors subscriber websites 24x7 for malicious code injection and matware Drive-by-Downioads

`Identifies malware download file type, source and destination on targat PC
`+ Supports automated and on-demand webske crawling as well asindividual URL scans
`+ Generates console, SMS and Email alerts upon matware injection or defacement
`+ Representsa critical component of Webapplication Incident Response process
`* Protects business and customers from Drive-by-Downioads
`SmartWAF™ web application Firewall
`* Defends natwork perimeter at the Web application layer
`* Protects against attacks that target vulnerable Web applications
`* Protects website, corporate resources and end-users
`* Supports aif major Web servers and operating systems

`Implements cluster management through a centralized Web console
`imports CodeSecure™ scan rewults for immediatevulnerable entry point protection
`See Armorize Technologies End-to-End Web Application Security (attached as Exhibit M).
`Armorize, now integrated into Proofpoint, uses, sells, offers for sale, and/or imports
`into the United States and this District products and services that utilize HackAlert Anti-Malware,
`CodeSecure Automated Static Source Code Analysis and SmartWAF Web Application Firewall,
`including but not limited to the following: HackAlert Suite, HackAlert Website Monitoring,
`HackAlert Safe Impressions, HackAlert Safelmpressions, HackAlert CodeSecure, HackAlert
`Vulnerability Assessment and SmartWAF.


Case3:13-c.-05808 Document] Filed12/16/13
`HackAlert is a service that analyzes, detects, prevents, and mitigates malware
`infections in online advertisements, documents and e-mails. HackAlert focuses on scanning for zero-
`day malware and exploits used in AdvancedPersistent Threat (“APT”) attacks, which are
`undetectable by typical virus or malware scanners. HackAlert’s sandbox analyzes these zero-day
`exploits and APT,such as malicious binaries, document exploits (PDF, Word, Excel, PowerPoint,
`Flash), Java exploits, browser exploits, drive-by downloads andclick-to downloads. See Take APT
`Malware By Storm (attached as Exhibit N).
` CodeSecure is an automatic static code analysis platform that identifies security
`vulnerabilities and works with SmartWAF and HackAlert to provide vulnerability entry point
`protection. CodeSecure identifies vulnerabilities such as Cross Site Scripting, File Inclusion,
`Malicious File Execution, Information Leakage and SQL Injection. CodeSecure checks for
`vulnerabilities based on algorithms to determine behavior outcomesofinputdata. See CodeSecure
`(attached as Exhibit O).
`SmartWAFis a web application firewall. It defends against web application attacks
`such as SQL Injection, Cross Site Scripting, Cross Site Request Forgery, Cookie Tampering,
`Directory Indexing, Information Leakage, Content Spoofing, Application Fingerprinting and Web
`Server Fingerprinting. SmartWAF mayalso integrate with CodeSecure by importing source code
`analysis findings and reconfiguringits rule set to block web application exploits targeted at
`vulnerabilities identified by CodeSecure.
` Armorize deploys a developers’ API for HackAlert Scanning and Forensics Extraction
`for Malware. With the API, developers can detect malware not normally caught by normal anti-virus
`technologies, such as zero-day exploits or Advanced Persistent Threats; automatically induce
`malware behaviorandcollect forensics information; and scanindividual URLsfor Web malware,


Case3:13-.-05808 Documentl Filed12/16/13
`such as drive-by downloads and click-to downloads, and generate trackbacks, exploitation steps,
`JavaScript execution and malware execution. See APT-malware-malvertising-scanning-api (attached
`as Exhibit P).
`Defendants have been and are now infringing the ‘822 Patent, the ‘633 Patent, the
`‘844 Patent, the ‘305 Patent, the ‘408 Patent, the ‘086 Patent, the ‘154 Patent and the ‘918 Patent
`(collectively “the Patents-In-Suit”) in this judicial District, and elsewhere in the United States by,
`among otherthings, making, using, importing,selling, and/or offering forsale the claimed systems
`and methodsthatutilize Proofpoint’s Zero-Hour Threat Detection, Proofpoint’s Malware Analysis
`Service, Proofpoint’s Targeted Attack Protection, HackAlert, and CodeSecure, including without
`limitation on Proofpoint Enterprise Protection, Proofpoint’s Targeted Attack Protection, Proofpoint
`Essentials, Proofpoint Protection Server, Proofpoint Messaging Security GatewayHackAlertSuite,
`HackAlert Website Monitoring, HackAlert Safe Impressions, HackAlert Safelmpressions, HackAlert
`CodeSecure, HackAlert Vulnerability Assessment and SmartWAF..
`In additionto directly infringing the Patents-In-Suit pursuant to 35 U.S.C. § 271(a)
`eitherliterally or under the doctrine of equivalents, Defendants indirectly infringe the ‘822 Patent, the
`‘633 Patent, the ‘844 Patent, the ‘305 Patent, the ‘408 Patent, the ‘086 Patent and the ‘918 Patent
`pursuant to 35 U.S.C. § 271(b) byinstructing, directing and/or requiring others, includingits users
`and developers, to perform all or someofthe steps of method claimsof the Patents-In-Suit, either
`literally or under the doctrine of equivalents.
`(Direct Infringement of the ‘822 Patent pursuantto 35 U.S.C. § 271(a))
`Finjan repeats, realleges, and incorporates by reference,asif fully set forth herein, the
`allegations of the preceding paragraphs,as set forth above.


Case3:13-c.-05808 Document Filed12/16/13
`Defendants have infringed and continueto infringe one or more claims ofthe ‘822
`Patent in violation of 35 U.S.C. § 271 (a).
`Defendants’ infringement is based uponliteral infringementor,in the alternative,
`infringement underthe doctrine of equivalents.
`Defendants’ acts of making, using, importing, selling, and/or offering for sale infringing
`products and services have been without the permission, consent, authorization or license of Finjan.
`Defendants’ infringementincludes, butis not limited to, the manufacture, use, sale,
`importation and/or offer for sale of Defendants’ products and services, including but not limited to
`HackAlert, Proofpoint Malware Analysis Service, and Proofpoint Targeted Attack Protection, which
`embodythe patented invention of the ‘822 Patent.
`Asaresult of Defendants’ unlawful activities, Finjan has suffered and will continue to
`suffer irreparable harm for which there is no adequate remedy at law. Accordingly, Finjanis entitled
`to preliminary and/or permanentinjunctiverelief.
`Defendants’ infringementof the ‘822 Patent has injured and continuesto injure Finjan
`in an amountto be provenattrial.
`(Indirect Infringement of the ‘822 Patent pursuant to 35 U.S.C. § 271(b))
`Finjan repeats, realleges, and incorporates by reference,asif fully set forth herein, the
`allegations of the preceding paragraphs,as set forth above.
`Defendants have induced and continue to induce infringementofat least claims 1-3, 4-
`8, and 16-27 of the ‘822 Patent under 35 U.S.C. § 271(b).
`In addition to directly infringing the ‘822 Patent, Defendants indirectly infringe the
`‘822 Patent pursuant to 35 U.S.C.§ 271(b) byinstructing, directing and/or requiring others, including
`but notlimited to its customers, users and developers,to perform all or someofthe steps of the


Case3:13-L.-05808 Document Filed12/16/13
`method claims, eitherliterally or under the doctrine of equivalents, of the “822 Patent, whereall the
`steps of the method claimsare performed by either Defendants ortheir customers, users or
`developers, or some combination thereof. Defendants have knownor have been willfully blind to the
`fact that they are inducingothers, including customers, users and developers, to infringe by
`practicing, either themselves or in conjunction with Defendants, one or more methodclaimsof the
`822 Patent.
`Defendants knowingly and actively aid and abetthe direct infringementof the ‘822
`Patent by instructing and encouraging their customers, users and developers to use the HackAlert,
`Proofpoint Malware Analysis Service, and Proofpoint Targeted Attack Protection. Such instructions
`and encouragementinclude, but are not limited to, advising third parties to use the HackAlert,
`Proofpoint Malware Analysis Service, and Proofpoint Targeted Attack Protection in an infringing
`manner; providing a mechanism through which third parties may infringe the ‘822 Patent, specifically
`through the use of the HackAlert, Proofpoint Malware Analysis Service, and Proofpoint Targeted
`Attack Protection; advertising and promoting the use ofthe HackAlert, Proofpoint Malware Analysis
`Service, and Proofpoint Targeted Attack Protection in an infringing manner; and distributing
`guidelines and instructions to third parties on how to use the HackAlert, Proofpoint Malware Analysis
`Service, and Proofpoint Targeted Attack Protection in an infringing manner.
`Defendants provide detailed instructions to their customers and users regardingall
`aspects of the HackAlert, Proofpoint Malware Analysis Service, and Proofpoint Targeted Attack
`Protection, including HackAlert Suite, HackAlert Website Monitoring, HackAlert Safe Impressions,
`HackAlert Safelmpressions, HackAlert Vulnerability Assessment, Proofpoint Enterprise Protection,
`Proofpoint’s Targeted Attack Protection, Proofpoint Essentials (including the packages of Beginner,
`Business, and Professional), Proofpoint Protection Server, and Proofpoint Messaging Security


Case3:13-Lv-05808 Documentl Filed12/16/13
`Gateway. Examplesofthese instructions can be found at the Armorize Resource Center(at
`, Armorize Forums / Tutorials, FAQs (at
`-Resources), and Proofpoint Resources
`(at http:/
`Proofpointitself and through its authorized partners regularly provides classroom style
`training, demonstrations, webinars, and certification programsto help users use Proofpoint Targeted
`Attack Protection and Malware Analysis Service, including without limitation the following:
`e Webinars on Contextual Security Approachto Protection From Targeted Threats,
`Undetected Threats: Finding and protecting against hundreds of missed attacks,
`Combatting 2013’s Most DangerousAttacks, and Spearing the Spear Phishers: How
`to Reliably Defeat Targeted Attacks. See
` php (attached as Exhibit Q).
`Demonstrations including Proofpoint Integrated Product Suite Demo and Proofpoint
`Enterprise Protection Live Demo. The demonstrations show howto use the
`Targeted Attack Protection to protect organizations. See
` (attached as Exhibit R).
`Technical Briefs on Proofpoint Zero-Hour Anti-Virus and White Papers on Targeted
`Attack: The Best Defense, Defense against the Dark Arts: Finding and Stopping
`Advanced Threats, and Longline Phishing: A New Class of Advanced Phishing
`Attacks. See (attached as
`Exhibit 8),
`Proofpoint Education Portal which offers courses in Enterprise Protection
`Accredited Engineer, Enterprise Protection Suite, Enterprise Protection for the
`Administrator, Proofpoint Targeted Attack Protection for End Users, Staying Safe
`on Email, and Enterprise Protection Associate Level Training. See
`http:/ (attached as Exhibit T).
`Proofpoint Education Portal which offers On-Site Training where a group of up to 8
`people can betrained live by Proofpoint to use their Protection products. See
`http://www (attached as
`Exhibit U).
`Proofpoint offers Professional Services, which helps customers design and implement
`Proofpoint’s products onto the customers’ network. Professional Services also offers integration,
`customization, training and maintenance of Proofpoint’s products.


Case3:13-c.-05808 Documentl Filed12/16/13
` Armorize poststutorials, user guides, troubleshooting and explanationsonits online
`forum on how to use Armorize technology. These include withoutlimitation HackAlert Resources,
`HackAlert Safelmpression question documents, tutorials on whatto do “when a drive-by-download
`knocks at your door,” tutorial on “How to add a website into HackAlert to be monitored,” and
`tutorial on “what to do when receiving an alert.” See
`Tutorials-FAQs-Resources(attached as Exhibit V).
` Armorize provides the HackAlert V5 API, which encourages developers and
`customers to use HackAlert with step-by-step instructions on how to integrate into the HackAlert
`Software. See Armorize Malware Scanning and Forensics Extraction AP] (attached as Exhibit P).
`Defendantsactively and intentionally maintains and updates websites, including
` and, to promote and provide demonstration, instruction and technical
`assistance for the HackAlert, Proofpoint Malware Analysis Service, and Proofpoint Targeted Attack
`Protection products, and to encourage customers,users and developersto use the HackAlert,
`Proofpoint Malware Analysis Service, and Proofpoint Targeted Attack Protection products and
`practice the methods taught in the ‘822 Patent.
`Defendants have had knowledge ofthe ‘822 Patentat least as of the time they learned
`ofthis action for infringement, and by continuing their actions described above, Defendants have had
`the specific intent to or were willfully blind to the fact that their actions would induce infringement of
`the ‘822 Patent.
`(Direct Infringement of the ‘633 Patent pursuantto 35 U.S.C. § 271(a))
`Finjan repeats, realleges, and incorporates by reference, as if fully set forth herein, the
`allegations of the preceding paragraphs, as set forth above.


Case3:13-c.-05808 Documenti Filed12/16/13
`Defendants have infringed and continueto infringe one or more claims of the “633
`Patent in violation of 35 U.S.C. § 271(a).
`Defendants’ infringementis based uponliteral infringementor, in the alternative,
`infringement underthe doctrine of equivalents.
`Defendants’ acts of making, using, importing,selling, and/or offering for sale infringing
`products and services have been withoutthe permission, consent, authorization or license of Finjan,
`Defendants’ infringementincludes, but is not limited to, the manufacture, use, sale,
`importation and/or offer for sale of Defendants’ products andservices, including but not limited to
`the HackAlert, Proofpoint Malware Analysis Service, and Proofpoint Targeted Attack Protection,
`which embody the patented invention of the ‘633 Patent.
` Asaresult of Defendants’ unlawful activities, Finjan has suffered and will continue to
`suffer irreparable harm for which there is no adequate remedyat law. Accordingly, Finjan is entitled
`to preliminary and/or permanentinjunctiverelief.
`Defendants’ infringement of the ‘633 Patent has injured and continues to injure Finjan
`in an amountto be provenattrial.
`(Indirect Infringement of the ‘633 Patent pursuantto 35 U.S.C. §§ 271(b))
`Finjan repeats, realleges, and incorporates byreference,as if fully set forth herein, the
`allegations ofthe preceding paragraphs,as set forth above.
`Defendants have induced andcontinue to induceinfringementofat least claims 1-7
`and 28-33 of the ‘633 Patent under 35 U.S.C. § 271(b).
`In addition to directly infringing the ‘633 Patent, Defendants indirectly infringe the
`‘633 Patent pursuant to 35 U.S.C. § 271(b) by instructing, directing and/or requiring others, including
`but not limited to its customers, users and developers, to performall or someofthe steps of the
Case3:13-cv-05808 Document] Filed12/16/13
`methodclaims,eitherliterally or under the doctrine of equivalents, of the “633 Patent, whereall the
`steps of the method claimsare performed by either Defendants or their customers, users or
`developers, or some combination thereof. Defendants have knownor have been willfully blind to the
`fact that they are inducing others, including customers, users and developers, to infringe by
`practicing, either themselves or in conjunction with Defendants, one or more method claims ofthe
`‘633 Patent.
`Defendants knowingly and actively aid and abet the direct infringementof the 633
`Patentby instructing and encouraging their customers, users and developers to use the HackAlert,
`Proofpoint Malware Analysis Service, and Proofpoint Targeted Attack Protection. Such instructions
`and encouragement include butare notlimited to, advising third parties to use Hack Alert, Proofpoint
`Malware Analysis Service, and Proofpoint Targeted Attack Protection in an infringing manner;
`providing a mechanism through which third parties may infringe the ‘633 Patent, specifically through
`the use of HackAlert, Proofpoint Malware Analysis Service, and Proofpoint Targeted Attack
`Protection; advertising and promoting the use of HackAlert, Proofpoint Malware Analysis Service,
`and Proofpoint Targeted Attack Protection in an infringing manner, and distributing guidelines and
`instructionsto third parties on how to use HackAlert, Proofpoint Malware Analysis Service, and
`Proofpoint Targeted Attack Protection in an infringing manner.
`Defendants provide detailed instruction to its customers and users regardingall aspects
`of the HackAlert, Proofpoint Malware Analysis Service, and Proofpoint Targeted Attack Protection
`including, HackAlert Suite, HackAlert Website Monitoring, HackAlert Safe Impressions, HackAlert
`Safelmpressions, HackAlert Vulnerability Assessment, Proofpoint Enterprise Protection,
`Proofpoint’s Targeted Attack Protection, Proofpoint Essentials (including the packages of Beginner,
`Business, and Professional), Proofpoint Protection Server, and Proofpoint Messaging Security


Case3:13-vv-05808 Documenti Filed12/16/13
; aget of 40
`PAUL J. ANDRE (State Bar No. 196585)
`LISA KOBIALKA(State Bar No. 191404)
`JAMES HANNAH(State Bar No. 237978)
`990 Marsh Road
`Menlo Park, CA 94025
`Telephone: (650) 752-1700
`Facsimile: (650) 752-1800
`Attorneysfor Plaintiff
Case No.:


Case3:13-c.-05808 Documentl Filed12/16/13
`Gateway. Examplesof these instructions can be foundat the Armorize Resource Center located at
`2|| id=product, Armorize Forums/ Tutorials, FAQs(at
`, and Proofpoint Resources
`Proofpointitself and through its authorized partners regularly provides class-room
`style training, demonstrations, webinars, and certification programsto help users use Proofpoint
`Targeted Attack Protection and Malware Analysis Service, including withoutlimitation the
`Webinars on Contextual Security Approach to Protection From Targeted Threats,
`Undetected Threats: Finding and protecting against hundreds of missed attacks,
`Combatting 2013’s Most DangerousAttacks, and Spearing the Spear Phishers: How
`to Reliably Defeat Targeted Attacks. See
` (attached as Exhibit Q).
`Demonstrations including Proofpoint Integrated Product Suite Demo and Proofpoint
`Enterprise Protection Live Demo. The demonstrations show how to use the
`Targeted Attack Protection to protect organizations. See
` as Exhibit R).
`Technical Briefs on Proofpoint Zero-Hour Anti-Virus and White Papers on Targeted
`Attack: The Best Defense, Defense against the Dark Arts: Finding and Stopping
`Advanced Threats, and Longline Phishing: A New Class of Advanced Phishing
`Attacks. See (attached as
`Exhibit S).
`Proofpoint Education Portal, which offers courses in Enterprise Protection
`Accredited Engineer, Enterprise Protection Suite, Enterprise Protection for the
`Administrator, Proofpoint Targeted Attack Protection for End Users, Staying Safe
`on E-mail, and Enterprise Protection Associate Level Training. See
` (attached as Exhibit T).
`Proofpoint Education Portal which offers On-Site Training where a group of up to 8
`people can betrained live by Proofpointto use their Protection products. See
`http:/ (attached as
`Exhibit U).


Case3:13-c.-05808 Document Filed12/16/13
` Proofpoint offers Professional Services, which helps customers design and implement
`Proofpoint’s products onto the customers’ network. Professional Services also offers integration,
`customization, training and maintenance of Proofpoint’s products.
`Armorize posts tutorials, user guides, troubleshooting and explanationsonits online
`forum on how to use Armorize technology. These include withoutlimitation HackAlert Resources,
`HackAlert Safelmpression question documents, tutorials on what to do “when a drive-by-download
`knocks at your door,” tutorial on “How to add a website into HackAlert to be monitored,” and
`tutorial on “what to do when receiving analert.” See
`Tutorials-FAQs-Resources (attached as Exhibit V).
` Armorize provides the HackAlert V5 API, which encourages developers and
`customers to use HackAlert with step-by-step instructions on howto integrate into the HackAlert
`Software. See Armorize Malware Scanning and Forensics Extraction API (attached as Exhibit P).
`Defendants actively and intentionally maintain and update their websites, including
` and, to promote and provide demonstration, instruction and technical
`assistance for the HackAlert, Proofpoint Malware Analysis Service, and Proofpoint Targeted Attack
`Protection products, and to encourage customers,users and developersto use the HackAlert,
`Proofpoint Malware Analysis Service, and Proofpoint Targeted Attack Protection products and
`practice the methods taught in the ‘633 Patent.
`Defendants have had knowledgeof the ‘633 Patentat least as of the time they learned
`of this action for infringement, and by continuing the actions described above, Defendants have had
`the specific intent to or was willfully blind to the fact that their actions would induce infringement of
`the ‘633 Patent.


Case3:13-L.-05808 Documenti Filed12/16/13
`(Direct Infringementof the “844 Patent pursuantto 35 U.S.C. § 271(a))
`Finjan repeats, realleges, and incorporates by reference,asif fully set forth herein, the
`allegations of the preceding paragraphs,as set forth above.
` Proofpoint has infringed and continuesto infringe one or more claimsofthe ‘844
`Patent in violation of 35 U.S.C. § 271{a).
` Proofpoint’s infringement is based upon literal infringementor, in the alternative,
`infringement underthe doctrine of equivalents.
` Proofpoint’s acts of making,using, importing, selling, and/or offering for sale infringing
`products and services have been without the permission, consent, authorization or license ofFinjan.
`Proofpoint’s infringement includes, but is not limited to, the manufacture, use, sale,
`importation and/or offer for sale ofProofpoint’s products andservices, including but notlimited to
`Proofpoint Malware Analysis Service and Proofpoint Targeted Attack Protection, which embodies
`the patented invention ofthe ‘844 Patent.
`As aresult ofProofpoint’s unlawfulactivities, Finjan has suffered and will continue to
`suffer irreparable harm for which there is no adequate remedyatlaw. Accordingly, Finjan is entitled
`to preliminary and/or permanent injunctiverelief.
`Proofpoint’s infringement ofthe ‘844 Patent has injured and continues to injure Finjan
`in an amountto be proven attrial.
`(Indirect Infringementof the ‘$44 Patent pursuantto 35 U.S.C.§ 271(b))
`Finjan repeats, realleges, and incorporates by reference,asif fully set forth herein, the
`allegations ofthe preceding paragraphs,as set forth above.
` Proofpoint has induced and continues to induce infringementofat least claims 1-14
`and 22-27of the ‘844 Patent under 35 U.S.C. § 271(b).


Case3:13--Lv-05808 Documentl Ciled12/16/13
`In addition to directly infringing the ‘844 Patent, Proofpointindirectly infringes the
`‘844 Patent pursuant to 35 U.S.C.§ 271(b) by instructing, directing and/or requiring others, including
`but not limited to its customers, users and developers, to perform all or someofthe steps ofthe
`methodclaims,either literally or under the doctrine of equivalents, ofthe ‘844 Patent, where all the
`steps ofthe methodclaimsare performed by either Proofpoint or its customers, users or developers,
`or some combination thereof. Proofpoint has known orhasbeenwillfully blind to the fact that it is
`inducing others, including customers, users and developers, to infringe by practicing, either
`themselves or in conjunction with Proofpoint, one or more methodclaimsofthe ‘844 Patent.
` Proofpoint knowingly and actively aids and abetsthe direct infringement ofthe ‘844
`Patent by instructing and encouraging its customers, users and developers to use the Proofpoint
`Malware Analysis Service and Proofpoint Targeted Attack Protection. Such instructions and
`encouragement include butare not limited to, advising third parties to use the Proofpoint Malware
`Analysis Service and Proofpoint Targeted Attack Protection in an infringing manner, providing a
`mechanism through whichthird parties may infringe the ‘844 Patent, specifically through the use of
`the Proofpoint Malware Analysis Service and Proofpoint Targeted Attack Protection; advertising and
`promoting the use ofthe Proofpoint Malware Analysis Service and Proofpoint Targeted Attack
`Protection in an infringing manner; and distributing guidelines and instructionsto third parties on
`how to use the Proofpoint Malware Analysis Service and Proofpoint Targeted Attack Protection in an
`infringing manner.
` Proofpoint provides detailed instructions to its customersandusers regarding all
`aspects ofthe Proofpoint Malware Analysis Service and Proofpoint Targeted Attack Protection
`including, Proofpoint Enterprise Protection, Proofpoint’s Targeted Attack Protection, Proofpoint
`Essentials (including the packages ofBeginner, Business, and Professional), Proofpoint Protection


Case3:13-..-05808 Document Eiled12/16/13
`Server, and Proofpoint Messaging Security Gateway. Examples ofthese instructions can be found at
`the Proofpoint Resources located at
` Proofpoint itselfand through its authorized partners regularly provides class-room
`style training, demonstrations, webinars, and certification programsto help users use Proofpoint
`Targeted Attack Protection and Malware Analysis Service, including without limitation the
`e Webinars on Contextual Security Approachto Protection From Targeted Threats,
`Undetected Threats: Finding and protecting against hundreds of missed attacks,
`Combatting 2013’s Most Dangerous Attacks, and Spearing the Spear Phishers: How
`to Reliably Defeat Targeted Attacks. See
` (attached as Exhibit Q).
`e Demonstrations includingProofp

