Apparatus, method and computer program for detecting malware
By monitoring and analyzing the power trace of user devices during charging and matching it with the power trace data of normal devices, malware can be identified and defended, solving the vulnerability of mobile devices and improving security.
Patent Information
- Application Number
- CN202110732570.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-07-01
- Filing Date
- 2021-06-30
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2041-06-30
AI Technical Summary
Mobile devices are vulnerable to malware attacks, which can lead to security information leakage or other destructive purposes. Existing technologies are difficult to effectively detect and defend against.
By monitoring the power trace of user devices during charging and analyzing its matching with the power trace data of normal devices, potential malware can be identified.
A method for detecting malware while a device is charging is provided, thereby improving device security and reducing the risk of malware attacks.
Smart Images

Figure HDA0003140318870000011 
Figure HDA0003140318870000021 
Figure HDA0003140318870000022
Abstract
Description
TECHNICAL FIELD
[0001] Examples of the present disclosure relate to apparatuses, methods and computer programs for detecting malware. Some relate to apparatuses, methods and computer programs for detecting malware when a user device is being charged. BACKGROUND
[0002] Malware attacks can present a significant problem for users of wireless devices such as mobile telephones and other communication devices. Malware can be used to attack such devices and obtain secure information, such as a user’s payment details, or to monitor a user or for other destructive purposes.
[0003] It would be desirable to be able to protect such devices from malware attacks. SUMMARY
[0004] According to various, but not necessarily all, examples of the present disclosure there is provided an apparatus comprising mechanisms for: selecting one or more tasks to be performed by a user device during charging of the user device; enabling a power trace to be obtained, wherein the power trace provides an indication of power consumed by the user device when performing the one or more tasks; and enabling the power trace to be analysed to provide an indication of the presence of malware.
[0005] The power trace can be obtained from power monitoring circuitry of a charging device configured to charge the user device.
[0006] The one or more tasks can be performed during inductive charging of the user device.
[0007] The power trace can be obtained from power monitoring circuitry of an inductive charging device configured to charge the user device.
[0008] Analysing the power trace can comprise comparing the obtained power trace with stored power trace data.
[0009] The stored power trace data can be obtained from a plurality of other user devices.
[0010] The power trace data can be compared with power traces of user devices performing the one or more tasks in the absence of malware.
[0011] The one or more tasks performed by the user device can comprise one or more tasks that produce a respective output that can be detected by another device.
[0012] The one or more tasks performed by the user device can comprise one or more of: completing a transaction, uploading data, activating a display, activating an audio output device.
[0013] The one or more tasks to be performed by the user device can be selected based on one or more of: past usage of the user device, predicted usage of the user device, predicted charging time of the user device, vulnerability of an application, current charging status of the user device.
[0014] According to various, but not necessarily all, examples in accordance with the disclosure, there is provided an apparatus comprising at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus at least to perform: selecting one or more tasks to be performed by a user device during charging of the user device; causing a power trace to be obtained, wherein the power trace provides an indication of power consumed by the user device in performing the one or more tasks; and causing the power trace to be analysed to provide an indication of presence of malware.
[0015] According to various, but not necessarily all, examples in accordance with the disclosure, there is provided a user device comprising the apparatus described above.
[0016] According to various, but not necessarily all, examples in accordance with the disclosure, there is provided a charging device comprising the apparatus described above.
[0017] According to various, but not necessarily all, examples in accordance with the disclosure, there is provided a method comprising: selecting one or more tasks to be performed by a user device during charging of the user device; causing a power trace to be obtained, wherein the power trace provides an indication of power consumed by the user device in performing the one or more tasks; and causing the power trace to be analysed to provide an indication of presence of malware.
[0018] In some examples of the method, the one or more tasks are performed during inductive charging of the user device.
[0019] According to various, but not necessarily all, examples in accordance with the disclosure, there is provided a computer program comprising computer program instructions which, when executed by processing circuitry, cause: selecting one or more tasks to be performed by a user device during charging of the user device; causing a power trace to be obtained, wherein the power trace provides an indication of power consumed by the user device in performing the one or more tasks; and causing the power trace to be analysed to provide an indication of presence of malware. BRIEF DESCRIPTION OF DRAWINGS
[0020] Some examples will now be described, by way of example, with reference to the accompanying drawings, in which:
[0021] Figure 1 An example device is shown;
[0022] Figure 2 An example method is shown;
[0023] Figure 3 shows an example system; and
[0024] Figure 4 Example implementations of the present disclosure are shown. DETAILED DESCRIPTION
[0025] Examples of the present disclosure relate to an apparatus 101 that may be configured to detect malware in a user device 301. This is achieved by monitoring power usage when the user device 301 performs one or more tasks during charging.
[0026] Figure 1 An apparatus 101 according to an example of the present disclosure is schematically shown. Figure 1 The device 101 shown may be a chip or chipset. In some examples, the device 101 may be provided within a user device 301, such as a mobile phone or other communication device. In some examples, the device 101 may be provided within a charging device 305, which may be used to charge the user device 301. In some examples, the device 101 may be provided within another device, such as a server or processing device separate from the user device 301 or the charging device 305.
[0027] exist Figure 1 In the example of , the device 101 includes a controller 103. Figure 1 In some examples, the controller 103 may be implemented as a controller circuit. In some examples, the controller 103 may be implemented solely in hardware, with certain aspects in software including only firmware, or may be a combination of hardware and software (including firmware).
[0028] like Figure 1 As shown, the controller 103 may be implemented using instructions that enable hardware functionality, for example, by using executable instructions of a computer program 109 in a general-purpose or special-purpose processor 105, which may be stored on a computer-readable storage medium (disk, memory, etc.) to be executed by such processor 105.
[0029] The processor 105 is configured to read and write to the memory 107. The processor 105 may further include an output interface and an input interface. The processor 105 outputs data and / or commands through the output interface, and data and / or commands are input to the processor 105 through the input interface.
[0030] The memory 107 is configured to store the computer program 109 comprising computer program instructions (computer program code 111) that control operations of the apparatus 101 when loaded into the processor 105. The computer program instructions of the computer program 109 provide the logic and routines enabling the apparatus 101 to perform the methods illustrated. Figure 2 The processor 105 is enabled to read the memory 107 to load and execute the computer program 109.
[0031] Thus, the apparatus 101 comprises: at least one processor 105; and at least one memory 107 including computer program code 111, the at least one memory 107 and the computer program code 111 configured to, with the at least one processor 105, cause the apparatus 101 at least to perform: selecting 201 one or more tasks to be performed by a user device 301 during charging of the user device 301; causing a power trace 401 to be obtained 203, wherein the power trace 401 provides an indication of power consumed by the user device 301 when the one or more tasks are performed; and causing the power trace 401 to be analyzed 205 to provide an indication of presence of malware.
[0032] As Figure 1 illustrated, the computer program 109 can arrive at the apparatus 101 via any suitable delivery mechanism 113. The delivery mechanism 113 can be, for example, a machine-readable medium, a computer-readable medium, a non-transitory computer-readable storage medium, a computer program product, a memory device, a record medium such as a compact disc read-only memory (CD-ROM) or digital versatile disc (DVD), or a solid state memory, an article of manufacture that tangibly embodies the computer program 109. The delivery mechanism can be a signal configured to reliably transfer the computer program 109. The apparatus 101 can be a computer program 109 propagating or transiting a computer data signal. In some examples, the computer program 109 can use, for example, Bluetooth, Bluetooth Low Energy, Bluetooth Smart, 6L0WPan (IPv6 over Low power Personal Area Networks), ZigBee, ANT+, Near Field Communication (NFC), Radio Frequency Identification, Wireless Local Area Network (Wireless LAN), or any other suitable protocol.
[0033] The computer program 109 comprises computer program instructions for causing the apparatus 101 at least to perform: selecting 201 one or more tasks to be performed by a user device 301; causing a power trace 401 to be obtained 203, wherein the power trace 401 provides an indication of power consumed by the user device when the one or more tasks are performed; and causing the power trace 401 to be analyzed 205 to provide an indication of presence of malware.
[0034] The computer program instructions can be included in the computer program 109, non-transitory computer readable medium, computer program product, machine readable medium. In some, but not necessarily all, examples, the computer program instructions can be distributed over multiple computer programs 109.
[0035] Although the memory 107 is shown as a single component / circuit, it can be implemented as one or more separate components / circuits, some or all of which can be integrated / removable and / or can provide persistent / semi-persistent / dynamic / cached storage.
[0036] Although the processor 105 is shown as a single component / circuit, it can be implemented as one or more separate components / circuits, some or all of which can be integrated / removable. The processor 105 can be a single core or multicore processor.
[0037] References to “computer-readable storage medium”, “computer program product”, “tangibly embodied computer program” etc., or a “controller”, “computer”, “processor” etc. should be understood to encompass not only computers having different architectures such as single / multi-processor architectures and sequential (Von Neumann) / parallel architectures but also specialized circuits such as field-programmable gate arrays (FPGA), application specific circuits (ASIC), signal processing devices and other processing circuitry. References to computer program, instructions, code etc. should be understood to encompass software for a programmable processor or firmware such as, for example, the programmable content of a field-programmable gate array (FPGA), or programmation logic for an application specific integrated circuit (ASIC), and / or generally as machine- readable instructions, including a plausible format that can be obtained from a storage medium that is readable by a general purpose / computer or a
[0038] As used in this application, the term “circuitry” can refer to one or more or all of the following:
[0039] (a) hardware-only circuitry (e.g., analog and / or digital circuitry) and
[0040] (b) combinations of hardware circuits and software, such as (as applicable):
[0041] (i) combinations of analog and / or digital hardware circuits with software / firmware and
[0042] (ii) hardware processors working in combination with software, such as within a mobile telephone or server, to perform various functions described herein, and
[0043] (c) hardware circuit(s) and / or processor(s), such as a microprocessor(s) or a portion of microprocessor(s), that requires software (e.g., firmware) for operation, but the software can not be present when it is not needed for operation.
[0044] The definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation that is at least partially functional and / or an implementation that is programmed in some manner and / or includes circuitry that is programmed in some manner. The term circuitry also covers, for instance, a baseband integrated circuit for a mobile device or a similar integrated circuit in a server, cellular network device, or other computing or network device, if applicable to a particular claim element.
[0045] Figure 2 The blocks shown in the flowchart illustrations can represent steps in a method and / or portions of code in a computer program 109. The order in which the blocks are presented is not necessarily the order in which the blocks are executed, and the blocks can be executed in different orders or in parallel. Additionally, some blocks can be omitted.
[0046] Figure 2 An example method that can be implemented by an apparatus 101 as shown in FIG. 1 is shown. Figure 1
[0047] The method includes, at block 201, selecting one or more tasks to be performed by the user device 301 during charging of the user device 301.
[0048] The one or more tasks can be performed during inductive charging of the user device 301. To enable inductive charging of the user device 301, the user device 301 can be placed in proximity to the charging device 305 such that one or more inductive coils in the charging device 305 can wirelessly transfer power to the user device 301.
[0049] In other examples, charging can be performed through one or more wires or cables. In some examples, charging can be performed through a wire that also allows for the transfer of data between the user device 301 and the charging device 305.
[0050] The one or more tasks selected to be performed by the user device 301 include one or more tasks that produce a respective output that can be detected by another device. The other device can be the charging device 305, another device that is independent of the user device 301 and the charging device 305, a device that includes one or more sensors that can detect the respective output produced by the user device 301 or any other suitable device.
[0051] In some examples, the one or more tasks selected to be performed can include completing a transaction. For example, a zero-value or very low-value transaction can be performed to enable scanning of a payment application for malware. The other device can be used to determine that the transaction has been completed.
[0052] In some examples, the selected one or more tasks include uploading data. The data can be uploaded to another device, which can then confirm that the data has been successfully uploaded. The uploaded data can include the data sample presented to the user device 301 for use during the examination of malware or data stored in the user device 301 or any other suitable type of data.
[0053] In some examples, the selected one or more tasks can include activating a display. The user device 301 can be configured to display an image or other data on a display of the user device 301. The display of the image can be detected by another device comprising one or more image sensors. In some examples, the selected one or more tasks can include controlling a light source, such as a dedicated LED light source or a display of the user device 301. The user device 301 can be configured to control one or more parameters of emitted light from the light source, such as the intensity (brightness), frequency (color), or temporal sequence of the emitted light. The one or more parameters of the controlled emitted light can be detected by another device comprising one or more light sensors.
[0054] In some examples, the selected one or more tasks can include activating an audio output device. For example, a speaker of the user device 301 can be configured to provide an audible output, which can be detected by a smart speaker device or any other suitable device comprising one or more microphones or other audio sensors.
[0055] It will be appreciated that other tasks or functions can be performed in other examples of the present disclosure.
[0056] The one or more tasks to be performed by the user device 301 can be selected in order to improve the security of the user device 301 and reduce the risk of malware being able to compromise the user device 301 or obtain secure information from the user device 301. To achieve this, the selected one or more tasks to be performed by the user device 301 can be tasks relating to applications or functions that provide a higher risk, such as applications and functions that store or use more sensitive information.
[0057] In some examples, the one or more tasks can be selected based on past usage of the user device 301. For example, the past usage of the user device 301 can indicate which applications or functions of the user device 301 are used heavily, or which applications or functions have been used since the user device 301 was last checked for malware. These can be considered to be at risk of infection with malware, and so tasks relating to the recently used applications or functions can be selected for checking for malware.
[0058] In some examples, the one or more tasks can be selected based on predicted usage of the user device 301. For example, it can be predicted that the user is likely to use one or more applications before the next charge of the user device 301 and / or before the next opportunity to scan the user device 301 for malware. For example, the user can use a payment application to pay for a journey to and from work, and so it can be predicted when this app will be used. In this case, the selected task can be related to the predicted application or function that will be used.
[0059] In some examples, the one or more tasks can be selected based on a predicted charging time of the user device 301. The selected task can be any task that can be completed within the length of time that the predicted charge will last, so that the task and malware check are complete when the user next starts using the user device 301. This can result in a different task being selected when the user device 301 is charged overnight for several hours, for example, compared to when the user device 301 is charged during the day.
[0060] In some examples, the current charging status of the user device 301 can also be used to select the one or more tasks. This can help to determine the predicted charging time of the user device 301. In some examples, it can be used to select one or more tasks that the user device has enough power to perform.
[0061] In some examples, the one or more tasks can be selected based on vulnerabilities of applications on the user device 301. For example, applications that use or have access to personal information or payment information can be checked more frequently than applications that do not contain such vulnerable information. For example, a banking application or an application in which the user’s payment details are stored can be considered high priority and checked for malware more frequently than an application such as an image processing or editing application that does not contain any confidential information.
[0062] It will be appreciated that in some embodiments, a combination of the above criteria or any other additional criteria can be used to select the one or more tasks to be performed.
[0063] The one or more tasks to be performed can be initiated by any suitable trigger event. In some examples, the user of the user device 301 can configure the user device 301 to perform a check for malware at defined time intervals or in response to a particular user input. In some examples, the task can be initiated whenever the user device 301 is being charged. In some examples, the task can be initiated whenever it is determined that a particular criterion has been met. The criterion can comprise a length of time since the last check for malware, the use of one or more particular applications, or any other suitable criterion.
[0064] At block 203, the method comprises enabling a power trace 401 to be obtained 203. The power trace 401 provides an indication of power consumed by the user device 301 in performing one or more tasks.
[0065] In some examples, the power trace 401 can be obtained from a power monitoring circuit of a charging device 305 configured to charge the user device 301. In some examples, the charging device 305 can implement inductive charging of the user device 301. This can enable the power trace 401 to be obtained independently of the user device 301, so that the user device 301 does not need to self-report power usage. This helps to protect the user device 301 from malware that can corrupt self-reported power traces.
[0066] At block 205, the method comprises enabling the power trace 401 to be analysed to provide an indication of the presence of malware.
[0067] The analysis of the power trace comprises comparing the obtained power trace data with stored power trace data. The stored power trace data can be obtained from a plurality of other user devices. The stored power trace data can be obtained from a plurality of user devices performing one or more selected tasks in the absence of malware. This can then enable the obtained power trace to be compared with power trace data expected of a user device 301 operating without malware.
[0068] The stored power trace data can include data obtained from user devices having different battery life and battery charge levels, so as to enable these to be taken into account when performing the analysis.
[0069] The obtained power trace 401 can be compared with the stored power trace data using correlation, pattern recognition or any other suitable process.
[0070] If the analysis shows a good match or correlation between the obtained power trace and the stored power trace data indicative of a healthy user device, no further action is required. In some examples, an alert can be provided to a user of the user device 301 that the check has been performed and no malware has been detected.
[0071] If the analysis does not show a good match or correlation between the obtained power trace and the stored power trace data indicative of a healthy user device, this indicates that malware can be present within the user device 301. In some examples, further checks for malware can be performed to enable the problem to be diagnosed more specifically. In some examples, an alert can be provided to a user of the user device 301 that malware has been detected.
[0072] The criteria for determining whether a good match or correlation is shown can comprise determining whether the difference between the obtained power trace and the stored power trace is within a threshold. The threshold can be set to a number of standard deviations from a known good power trace. In some examples, the classification of an obtained power trace as a good power trace or otherwise can be performed using a neural network system which can be trained to provide the required detector characteristics without requiring any specific statistical rules.
[0073] Figure 3 An example system for implementing examples of the disclosure is illustrated. The system comprises a user device 301, a cloud device 303 and a charging device 305. It will be appreciated that in other examples of the disclosure the system can comprise additional components.
[0074] The user device 301 can comprise a mobile phone or any other suitable type of user device, such as a laptop, a wearable device such as a watch or heart monitor or a device forming part of the internet of things. The user device 301 can comprise a processor 307, a memory 309 and a power supply 311 as shown. The power supply 311 can comprise a battery or any other suitable power supply. Figure 1 The apparatus 101 as shown is configured to perform the method as shown. In other examples, the apparatus 101 for performing the method can be provided in the cloud device 303 or the charging device 305. In some examples, the method can be performed by different devices within the system such that the user device 301 can perform some of the method and the cloud device 303 and / or the charging device 305 can perform other parts of the method. Figure 2 The apparatus 101 as shown is configured to perform the method as shown. In other examples, the apparatus 101 for performing the method can be provided in the cloud device 303 or the charging device 305. In some examples, the method can be performed by different devices within the system such that the user device 301 can perform some of the method and the cloud device 303 and / or the charging device 305 can perform other parts of the method. Figure 2 The apparatus 101 as shown is configured to perform the method as shown. In other examples, the apparatus 101 for performing the method can be provided in the cloud device 303 or the charging device 305. In some examples, the method can be performed by different devices within the system such that the user device 301 can perform some of the method and the cloud device 303 and / or the charging device 305 can perform other parts of the method.
[0075] In the example shown, the user device 301 comprises a charging session detection module 313. The charging session detection module 313 is configured to detect a charging session initiation by the charging device 305. The charging can be inductive charging or any other suitable type of charging. In the case that the charging is inductive charging, the charging session detection module 313 can be configured to detect that the user device 301 is located in the vicinity of the charging device 305 so as to enable the transfer of power to the user device 301. Figure 3 The user device 301 also comprises a task selection module 315 which is configured to select one or more tasks to be performed by the user device 301 during the charging session. The tasks can be selected based on one or more of: past usage of the user device 301, predicted usage of the user device 301, predicted charging time of the user device 301, vulnerabilities of applications, current charging status of the user device 301 or any other suitable criteria or combination of criteria.
[0076]
[0077] In some examples, the task selection module 315 can be configured to receive input from the charging session detection module 313, to select a task in response to detecting that a charging session is initiated.
[0078] The user device 301 also includes a task initiation module 317, which is configured to initiate one or more selected tasks. The task initiation module 317 can be configured to receive input from the task selection module 315, and use that input as a trigger to initiate a task. This can enable a task to be initiated automatically upon detection of a charging session, without requiring any user input. In some examples, the task initiation module 317 can be configured to initiate a task in response to user input or any other suitable triggering event.
[0079] The selected task initiated by the task initiation module 317 can use one or more applications of the user device 301. The initiated task can include completing a transaction, uploading data, activating a display, activating an audio output device, or any other suitable task or combination of tasks.
[0080] In Figure 3 The user device 301 also includes a detection completed task module 321, which is configured to detect that a task initiated by the task initiation module 317 has completed. For example, the detection completed task module 321 can determine when a selected task has been successfully completed. In some examples, the detection completed task module 321 can determine that a task has completed by receiving a notification from another device. In such examples, the other device can detect that a transaction has been performed or data has been uploaded, and can provide an indication of this to the user device 301. The other device providing the notification can be part of the system, for example it can be the charging device 305 or the cloud device 303, or it can be any other suitable device. In some examples, the detection completed task module 321 can detect that a task has completed itself, without any other input from any other device.
[0081] Figure 3 The user device 301 also includes a power trace analysis module 319, as shown in the middle. The power trace analysis module 319 is configured to compare power trace data obtained from the user device 301 while one or more tasks are being performed, with power trace data obtained from other user devices. The power trace data obtained from other user devices can be other similar user devices 301, which have performed the same or similar tasks in the absence of malware while being charged by similar charging devices 305. The analysis can include pattern recognition, correlation, or any other similar process.
[0082] In Figure 3In the illustrated example, the power trace analysis module 319 is provided within the user device 301 such that the user device 301 obtains the power trace data from the cloud device 303. In other examples, the power trace data can be stored in the memory of the user device 301. In other examples, the power trace analysis module 319 can be provided in the cloud device 303 such that the analysis of the power trace is performed externally to the user device 301. In such examples, the output indicative of the power trace analysis can be provided to the user device 301.
[0083] The user device 301 also comprises a response module 323. The response module 323 is configured to provide a response in dependence on the analysis of the power trace data. In some examples, the response can be an alert provided to the user indicative of the results of the analysis of the power trace data. For example, it can provide an indication that a check for malware has been performed and provide an indication as to whether any malware is suspected to be present within the user device 301.
[0084] Figure 3 The illustrated system also comprises a cloud device 303. The cloud device 303 can comprise a device external to the user device 301 and the charging device 305. The cloud device 303 can be configured to communicate with the user device 301 and / or the charging device 305 as required. The cloud device 303 can be configured to communicate with the user device 301 and the charging device 305 over any suitable wireless protocol. In some examples, the cloud device 303 can be a server or other processing device which can be remote from the user device 301 and the charging device 305.
[0085] In Figure 3 In the illustrated example, the cloud device 303 comprises a healthy trace identification module 307. The healthy trace identification module 307 can be configured to obtain power traces from a plurality of other user devices 301. The healthy trace identification module 307 can determine which of these traces can be classified as healthy traces corresponding to user devices 301 operating without malware. The healthy traces can be identified using any suitable process, such as machine learning, pattern recognition or any suitable process or combination of processes. In some examples, the healthy power traces can be defined by a majority common signature in the case that these match an initial signature captured prior to exposure to the risk of malware during a challenge task.
[0086] The cloud device 303 comprises a power trace database 309. The power trace database 309 comprises the healthy traces identified by the healthy trace identification module 307. The healthy traces stored in the power trace database 309 can be categorised according to the type of user device 301, the type of task performed, the age of the user device 301 and / or any other suitable category.
[0087] The power trace database 309 is configured to be accessible by the user device 301 so that power trace data of the user device 301 can be compared to power traces of healthy devices.
[0088] The charging device 305 can comprise any device configured to transfer power to the user device 301. The charging device 305 can comprise a charging circuit that enables inductive charging or any other suitable type of charging of the user device 301.
[0089] The charging device 305 further comprises a power monitoring module 311. The power monitoring module 311 comprises any mechanism that can be configured to monitor the power transferred to the user device 301 during charging and obtain a power trace indicative of said power. The power monitoring module 311 can be used to determine the efficiency at which power is being transferred to the user device 301. In said example, the power monitoring module 311 can also determine the power being used by the user device 301 when one or more tasks are being performed.
[0090] The power monitoring module 311 can use any suitable means to determine the power being consumed by the user device 301 when a task is being performed. In some examples, the charging device 305 can comprise a charging coil that can be used by the power monitoring module 311 to determine the power consumed by the user device 301.
[0091] In some examples, the charging device 305 can comprise a plurality of charging coils and at a given time only one or some of these charging coils are actively used to charge the user device 301. In such examples, one or more charging coils that are not currently used to charge the user device 301 can be used to detect magnetic fields generated by the user device 301 when a task is being performed. Information about the magnetic fields can be used in addition to or instead of the power trace data to determine that a task has been completed. In some examples, in addition to a change in the power trace, a change in the electromagnetic field detected by the charging coils of the charging device can be used to provide an indication that malicious software is present on the user device 301. The charging device 305 can comprise a mechanism to filter out the operating frequency of the ongoing charging protocol (e.g. the 80 kHz to 300 Hz frequency range used for medium power charging under the Qi® wireless charging standard) from the detected electromagnetic field signal. The filtering is performed in order to extract information from the detected electromagnetic signal, e.g. that one or more tasks have been completed and / or that the electromagnetic field has changed, as described above.
[0092] The charging device 305 is configured so that the power trace data obtained by the power monitoring module 311 can be provided to the user device 301 to enable the power trace analysis module 319 to analyse the power trace data.
[0093] Figure 4Example implementations of the disclosure are shown. The implementation includes a user device 301, for example a mobile phone or any other suitable type of device. The user device 301 can include an apparatus 101 as shown. Figure 1
[0094] The user device can be configured to perform one or more selected tasks during a charging session in order to enable a power trace 401 to be obtained. The power trace 401 provides an indication of the power provided to the user device 301 as a function of time. The power trace 401 can then be analysed for anomalies 403 or differences compared to a power trace obtained from a healthy device, thereby providing an indication of whether any malware is present in the user device.
[0095] Accordingly, examples of the disclosure provide an apparatus 101 and method that enables a user device 301 to be scanned for malware during a charging session. This provides a convenient way to protect a user device 301 from malware attacks.
[0096] In some examples, the system, apparatus 101, method and computer program can use machine learning including statistical learning. For example, machine learning can be used by the cloud device 303 to identify healthy power traces, or can be used by the user device 301 to compare an obtained power trace to a healthy power trace. Machine learning is a field of computer science that endows computers with the ability to learn without being explicitly programmed. A computer learns from experience E with respect to some class of task T and performance measure P if its performance on tasks T, measured by P, improves with experience E. Computers typically learn from previous training data in order to make predictions on future data. Machine learning includes fully or partially supervised learning and fully or partially unsupervised learning. It can implement discrete outputs (e.g. classification, clustering) and continuous outputs (e.g. regression). Machine learning can be implemented using different methods, for example cost function minimization, artificial neural networks, support vector machines and Bayesian networks. For example, cost function minimization can be used for linear and polynomial regression and K-means clustering. Artificial neural networks, for example with one or more hidden layers, model complex relationships between input vectors and output vectors. Support vector machines can be used for supervised learning. Bayesian networks are a directed acyclic graph representing conditional independencies of a plurality of random variables.
[0097] The term “comprising” as used in this document has an inclusive meaning and not an exclusive meaning. That is, any reference to X comprising Y indicates that X can comprise only one Y or can comprise more than one Y. If it is intended to use “comprising” in an exclusive sense, then this will be explicitly stated by reference to “comprising only one …” or by using “consisting of”.
[0098] In this description, reference has been made to various examples. The description of features or functions in relation to an example indicates that the features or functions are present in that example. The use of the term "example" or "for example" or "may" or "might" in the text denotes, where appropriate, examples of what is described, whether or not it is explicitly stated. Thus, "example", "for example" or "may" or "might" refers to a particular instance in a class of examples. The properties of the instance can be properties of only that instance or properties general to the class or properties general to a subclass of the class, the subclass including some but not all instances of the class. Thus, features described with reference to one example are implicitly disclosed as being referable to, where possible, a working combination part of the other examples, but do not necessarily have to be used in the other examples.
[0099] Although examples have been described in the preceding paragraphs with reference to various examples, it should be understood that modifications can be made to the given examples without departing from the scope of the claims.
[0100] Features described in the preceding description can be used in combinations other than the combinations explicitly described above.
[0101] Although functions have been described with reference to certain features, those functions can be performed by other features whether or not the other features are described.
[0102] Although features have been described with reference to certain examples, those features can also be present in other examples whether or not the other examples are described.
[0103] The terms "a" or "the" as used herein are inclusive of both singular and plural referents. Any reference to an item, without the use of articles, means that the item can be used either alone or in combination. The use of "at least one" or "one or more" in certain instances can be used to emphasize the inclusive nature of the reference to that feature. However, the lack of these terms should not be taken to imply any exclusive interpretation.
[0104] The presence of a feature (or combination of features) in a claim has the meaning defined by the claim. It indicates the presence of that feature or (combination of features) itself and also a feature (equivalent feature) that implements the substantially same technical effect. Equivalent features include, for example, features that are variants and implement substantially the same outcome in substantially the same way. Equivalent features include, for example, features that perform substantially the same function in substantially the same way to achieve substantially the same results.
[0105] In this specification, reference is made to various examples using adjectives or adjective phrases to describe example features. Such description of features in relation to examples indicates that the feature is present in some examples exactly as described and in other examples substantially as described.
[0106] While efforts have been made to draw attention to those features of the application believed to be of particular importance, it should be understood that the applicant can seek protection for any patentable feature or combination of features described hereinabove or illustrated in the drawings whether or not emphasis has been placed thereon.
Claims
1. A device for detecting malware, comprising: at least one processor; as well as at least one memory including computer program code stored thereon; The at least one memory and the computer program code are configured to, with the at least one processor, cause the apparatus to: selecting, prior to a next charge of the user device, one or more tasks to be performed by the user device during the next charge of the user device, wherein the one or more tasks to be performed by the user device are based on at least predicted usage of applications on the user device or past usage of applications on the user device since the user device was last checked for malware; enabling a power trace to be obtained, wherein the power trace provides an indication of power consumed by the user equipment while performing the one or more tasks; as well as enabling said power trace to be analyzed to provide an indication of the presence of malware, Analyzing the power trace includes comparing the obtained power trace with stored power trace data obtained from a plurality of other user equipments.
2. The device according to claim 1, wherein The power trace is obtained from a power monitoring circuit of a charging device configured to charge the user device.
3. The apparatus of claim 1, wherein the one or more tasks are performed during inductive charging of the user device.
4. The device according to claim 3, wherein The power trace is obtained from a power monitoring circuit of an inductive charging device configured to charge the user device.
5. The apparatus of claim 1, wherein the power trace data is compared to a power trace of a user device executing the one or more tasks in the absence of the malware.
6. The apparatus of claim 1, wherein the one or more tasks to be performed by the user device include one or more tasks that produce a corresponding output detectable by another device.
7. The apparatus of claim 1, wherein the one or more tasks to be performed by the user device include one or more of: completing a transaction, uploading data, activating a display, activating an audio output device.
8. The apparatus of claim 1, wherein the one or more tasks to be performed by the user device are selected based on one or more of: a predicted charging time of the user device, a vulnerability of an application, a current charging state of the user device.
9. A charging device comprising the device according to claim 1.
10. A method for detecting malware, comprising: selecting, prior to a next charge of the user device, one or more tasks to be performed by the user device during the next charge of the user device, wherein the one or more tasks to be performed by the user device are based on at least predicted usage of applications on the user device or past usage of applications on the user device since the user device was last checked for malware; enabling a power trace to be obtained, wherein the power trace provides an indication of power consumed by the user equipment while performing the one or more tasks; as well as enabling said power trace to be analyzed to provide an indication of the presence of malware, Analyzing the power trace includes comparing the obtained power trace with stored power trace data obtained from a plurality of other user equipments.
11. The method of claim 10, wherein the one or more tasks are performed during inductive charging of the user device.
12. The method of claim 10, wherein: The power trace is obtained from a power monitoring circuit of a charging device configured to charge the user device.
13. The method of claim 10, wherein: The one or more tasks to be performed by the user device include one or more tasks that produce a corresponding output detectable by another device.
14. The method of claim 10, wherein: The one or more tasks to be performed by the user equipment include one or more of the following: Complete transactions, upload data, activate displays, activate audio output devices.
15. A non-transitory computer-readable medium comprising computer program instructions stored thereon, which, when executed by a processing circuit, result in at least the following: selecting, prior to a next charge of the user device, one or more tasks to be performed by the user device during the next charge of the user device, wherein the one or more tasks to be performed by the user device are based on at least predicted usage of applications on the user device or past usage of applications on the user device since the user device was last checked for malware; enabling a power trace to be obtained, wherein the power trace provides an indication of power consumed by the user equipment while performing the one or more tasks; and enabling said power trace to be analyzed to provide an indication of the presence of malware, Analyzing the power trajectory includes: The obtained power trace is compared with stored power trace data obtained from a plurality of other user devices.
16. The non-transitory computer-readable medium of claim 15, wherein: The one or more tasks to be performed by the user device include one or more tasks that produce a corresponding output detectable by another device.
17. The non-transitory computer-readable medium of claim 15, wherein: The one or more tasks to be performed by the user equipment include one or more of the following: Complete transactions, upload data, activate displays, activate audio output devices.
18. The non-transitory computer-readable medium of claim 15, wherein: One or more tasks to be performed by the user device are selected based on one or more of: a predicted charging time of the user device, a vulnerability of an application, and a current charging state of the user device.
Citation Information
Patent Citations
System and method for monitoring power consumption to detect malware
US20180330091A1