Techniques for identifying reviewed software applications providing unauthorized features
By collecting and comparing the current operation characteristics of the software application with its original operation characteristics on the computing device, identifying exceptions and taking remedial measures, the problem of the software application changing from authorized features to unauthorized features in bait conversion operations is solved, improving the security of the computing device.
Patent Information
- Application Number
- CN202380068155.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-01-27
- Filing Date
- 2023-07-20
- Publication Date
- 2025-05-06
AI Technical Summary
The prior art has difficulty detecting and mitigating the problem of software applications transitioning from authorized features to unauthorized features in bait conversion operations, resulting in software applications installed by end users that may be beyond the scope of review and approval of software application stores.
Appropriate remedial measures such as notifying the management entity or terminating the execution of the software application by collecting the current operating characteristics of the software application on the computing device and comparing it with its original operating characteristics.
Effectively identify and mitigate unauthorized features of software applications in bait conversion operations, ensuring that software applications continue to operate in a manner initially reviewed and approved by the software application store, improving the security of computing devices.
Smart Images

Figure CN119948481A_ABST
Abstract
Description
Technical Field
[0001] The described embodiments set forth techniques for identifying when a reviewed software application is transformed to provide unauthorized features. Specifically, these techniques relate to enabling a computing device (on which a reviewed software application is executed) to identify when unauthorized features are provided and implement remedial measures. Background Art
[0002] In recent years, there has been a surge in software applications designed to operate on computing devices such as desktop computers, laptop computers, tablet computers, mobile phones, and wearable devices. This increase is primarily due to computing devices running operating systems that enable "third-party applications" to be developed for computing devices and installed on computing devices (along with the various "native" applications that are typically provided with the operating system). This approach provides numerous benefits, including, among other things, enabling a large number of developers worldwide to exercise their creativity through the use of powerful application programming interfaces (APIs) available through the aforementioned operating systems.
[0003] Different methods can be used to enable users to install third-party software applications on their computing devices. For example, one method involves an environment that is largely unrestricted because developers can write software applications that can virtually access every corner of the operating system / computing device to which they will eventually be installed. Under this method, users are also generally able to freely download and install software applications from any developer and / or distributor. On the one hand, this method provides developers and users with a fairly high level of flexibility because they can participate in a largely uninhibited operating environment. At the same time, this method has security flaws because faulty and / or malicious software applications are common and are often installed by ordinary users.
[0004] In order to address the aforementioned deficiencies, an alternative approach for alleviating at least some of the aforementioned problems involves implementing a more restricted system than the aforementioned unrestricted environment. Specifically, the restricted environment typically involves a software application store implemented by an entity that is (usually) also linked to the operating system and / or computing device on which the software application will ultimately be installed. Under this approach, developers are required to register with the software application store as a first review. Subsequently, the developer submits the proposed software application to the software application store for analysis as to whether the software application complies with various operational requirements, which constitutes a second review. Ultimately, when the software application is approved for distribution through the software application store, users are allowed to download the software application to their computing devices. Therefore, compared to the unrestricted environment discussed above, this approach provides considerable security enhancement benefits.
[0005] Despite the advantages of the restricted environment approach, malicious developers continue to attempt to circumvent existing security measures in order to exploit end users. One common approach involves a bait-and-switch operation, in which a software application is designed to provide authorized features when certain conditions are detected, and then provide unauthorized features when these conditions have been mitigated. For example, these conditions may involve time conditions, geographic conditions, operating conditions, and the like. For example, if the software application review process takes an average of ten days to complete, the developer may design the software application to run in one way for thirteen days and then run in another way (i.e., at a time when the application may have been approved by the software application store). For example, this may involve an innocuous card game that introduces gambling features, an innocuous minor application that introduces adult content, and the like.
[0006] Therefore, there is a need to detect and mitigate the aforementioned bait and switch schemes to ensure that software applications installed by end users continue to operate in the manner originally reviewed and approved by the software application store. Summary of the invention
[0007] This application describes techniques for identifying when a reviewed software application has transformed to provide unauthorized features. Specifically, the techniques involve identifying the original operating characteristics of the software application during the review process. Subsequently, a computing device executing the reviewed software application can collect its current operating characteristics and compare them to the original operating characteristics to identify any anomalies. Appropriate actions can then be taken, such as notifying an administrative entity and / or terminating execution of the reviewed software application.
[0008] One embodiment describes a method for identifying when a reviewed software application transitions to provide unauthorized features. According to some embodiments, the method can be implemented by a computing device and includes the following steps: (1) receiving and installing a reviewed software application, wherein the reviewed software application specifies at least one original operating characteristic of the reviewed software application; (2) collecting at least one current operating characteristic of the reviewed software application during execution of the reviewed software application; (3) identifying that a conflict exists between at least one original operating characteristic of the reviewed software application and at least one current operating characteristic of the reviewed software application; and (4) providing an indication of the conflict to an administrative entity associated with the reviewed software application.
[0009] Another embodiment describes a method for managing a scenario in which a reviewed software application is transformed to provide unauthorized features. According to some embodiments, the method can be implemented by at least one server device associated with a management entity and includes the steps of: (1) receiving an indication from a computing device on which the reviewed software application is installed that there is a conflict between at least one original operating characteristic of the reviewed software application and at least one current operating characteristic of the reviewed software application, and (2) in response to identifying that a threshold number of indications have been received from other computing devices regarding the reviewed software application: causing at least one enforcement action to be performed in association with the reviewed software application.
[0010] Other embodiments include a non-transitory computer-readable storage medium configured to store instructions that, when executed by a processor included in a computing device, cause the computing device to perform the methods and techniques described in the present disclosure. Other embodiments include a hardware computing device that includes a processor that can be configured to cause the hardware computing device to implement the methods and techniques described in the present disclosure.
[0011] Other aspects and advantages of the present invention will become apparent from the following detailed description taken in conjunction with the accompanying drawings which illustrate by way of example the principles of the described embodiments.
[0012] The present disclosure is provided for the purpose of summarizing some example embodiments only, so as to provide a basic understanding of some aspects of the subject matter described herein. Therefore, it should be understood that the above-mentioned features are only examples and should not be construed as narrowing the scope or essence of the subject matter described herein in any way. Other features, aspects and advantages of the subject matter described herein will become apparent through the following detailed description, drawings and claims. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] The present disclosure will be more readily understood through the following detailed description taken in conjunction with the accompanying drawings, in which like reference numerals designate like structural elements.
[0014] Figure 1 Shown is a block diagram of different components of a system for implementing the various techniques described herein, according to some embodiments.
[0015] Figure 2 A conceptual diagram illustrating the manner in which a computing device may self-identify when a reviewed software application may be providing unauthorized features, according to some embodiments.
[0016] Figure 3 An example timeline diagram illustrating the manner in which a computing device may self-identify when a reviewed software application may be providing unauthorized features according to some embodiments.
[0017] 4A to 4H A conceptual diagram of a user interface through which a computing device can self-identify when a reviewed software application is providing unauthorized features is shown, according to some embodiments.
[0018] Figure 5 A method implemented by a computing device for identifying when a reviewed software application transitions to provide unauthorized features is shown according to some embodiments.
[0019] Figure 6 A method implemented by an administrative entity for managing scenarios in which a vetted software application transitions to provide unauthorized features is shown in accordance with some embodiments.
[0020] Figure 7 Shown is a detailed view of a representative computing device that can be used to implement the various methods described herein, according to some embodiments. DETAILED DESCRIPTION
[0021] Representative applications of the methods and apparatus according to the present application are described in this section. These examples are provided only to add context and aid in understanding the described embodiments. Therefore, it will be apparent to those skilled in the art that the described embodiments may be practiced without some or all of these specific details. In other cases, in order to avoid unnecessarily obscuring the described embodiments, well-known processing steps are not described in detail. Other applications are possible, so that the following examples should not be considered limiting.
[0022] In the following detailed description, reference is made to the accompanying drawings which form a part of the specification and in which are shown by way of illustration specific embodiments in accordance with the described embodiments. Although these embodiments are described in sufficient detail to enable those skilled in the art to practice the described embodiments, it is to be understood that these examples are not limiting; other embodiments may be used and changes may be made without departing from the spirit and scope of the described embodiments.
[0023] The described embodiments set forth techniques for identifying when a vetted software application is transformed to provide unauthorized features. As described herein, a vetted software application may represent a software application that has been modified by an administrative entity (e.g., a computer) before the software application is enabled for distribution and installation on a computing device. App ) certified software application. Under one approach, an administrative entity (and / or other reviewing entity) may be configured to receive a software application from a developer entity and, in response to subjecting the software application to at least one review procedure, establish a reviewed software application based on the software application. According to some embodiments, at least one review procedure may involve identifying at least one raw operational characteristic exhibited by the software application during at least one review procedure. The at least one raw operational characteristic may include, for example, user interface (UI) input associated with the software application during at least one review procedure, motion input associated with the software application during at least one review procedure, UI refresh rate associated with the software application during at least one review procedure, sound output associated with the software application during at least one review procedure, power usage associated with the software application during at least one review procedure, memory usage associated with the software application during at least one review procedure, network bandwidth usage associated with the software application during at least one review procedure, microphone usage associated with the software application during at least one review procedure, camera usage associated with the software application during at least one review procedure, and the like. Note that the aforementioned operational characteristics are merely exemplary and are not meant to be limiting, and any aspect of the execution of the software application during at least one review process may be considered without departing from the scope of the present disclosure.
[0024] After the administrative entity has established the reviewed software application, the administrative entity may make the reviewed software application available for download and installation onto a computing device. Specifically, a given computing device may receive and install the reviewed software application, wherein the reviewed software application includes at least one original operating characteristic of the reviewed software application. Subsequently, the computing device may collect at least one current operating characteristic of the reviewed software application during execution of the reviewed software application. Subsequently, the computing device may identify whether there is a conflict between at least one original operating characteristic of the reviewed software application and at least one current operating characteristic of the reviewed software application. According to some embodiments, the conflict may be determined in conjunction with identifying a first operating characteristic and a second operating characteristic shared between the at least one original operating characteristic and the at least one current operating characteristic, respectively, and identifying that a degree of dissimilarity between the first operating characteristic and the second operating characteristic satisfies a threshold. Subsequently, the computing device may provide an indication of the conflict to the administrative entity associated with the reviewed software application. In addition, the computing device may apply its own remedial measures (e.g., before receiving an enforcement action from the administrative entity in response to the indication), such as suspending or terminating the execution of the reviewed (and now problematic) software application.
[0025] According to some embodiments, the indication provided by the computing device may include at least one current operating characteristic and / or a notification that the software application under review appears to be providing unauthorized features. The at least one current operating characteristic may include, for example, any of the operating characteristics discussed herein and any additional operating characteristics that can be used to enable the management entity to effectively identify the nature of the conflict. Then, the management entity may identify whether a threshold number of indications about the software application under review has been received from other computing devices. The enforcement of the threshold can help avoid situations where the management entity imposes harsh reactions on benign conflicts. For example, there may be situations where false positive detection occurs, such as when the software application under review becomes confused (for example, as a result of an OS update) and appears to provide unauthorized functions (but not actually). In any case, when a threshold number of indications has been received, the management entity may implement various remedial measures. For example, the management entity may provide a warning to the developer associated with the software application under review, suspend the download of the software application under review, and / or cause one or more computing devices on which the software application under review is installed to prevent the execution of the software application under review. It should be noted that the aforementioned remedial measures are exemplary and are not intended to be limiting. Rather, any type / number of remedial measures may be implemented without departing from the scope of the present disclosure.
[0026] It is also noted that privacy concerns may be considered in conjunction with implementing the techniques discussed herein. For example, prior to collecting at least one current operating characteristic of a reviewed software application, a computing device may prompt its user with a request to obtain at least one current operating characteristic (and refuse to take further action until the request is authorized). In another example, a computing device may scale overall level monitoring (where appropriate) based on progressive approval provided by its user. In yet another example, a computing device may refuse to implement the remedial measures discussed herein, such that the user maintains a high level of control over their computing device. Thus, the various actions implemented by the entities discussed herein may be modified in any capacity to provide customized privacy levels to meet the preferences of individual users.
[0027] These and other embodiments are referred to below. Figures 1 to 7 Discussion is made; however, those skilled in the art will readily appreciate that the detailed description given herein with respect to these figures is for illustrative purposes only and should not be construed as limiting.
[0028] Figure 1 1 shows a block diagram of different components of a system 100 that can implement the various techniques described herein, according to some embodiments. Figure 1 As shown, system 100 may include a collection of computing devices 114, one or more developer entities 102, and administrative entities 106. According to some embodiments, a given developer entity 102 may collectively represent one or more parties involved in the development, management, publication, etc. of a software application. For example, developer entity 102 may collectively represent a company, an individual developer, etc., as well as one or more computing devices utilized by such parties.
[0029] According to some embodiments, management entity 106 may collectively represent one or more entities involved in distributing software applications to computing devices. For example, management entity 106 may at least partially implement App It constitutes a virtual store that users of computing devices can access to browse, download, and install applications. According to some embodiments, and as described in more detail herein, the management entity 106 may be configured to receive a request to publish a software application candidate 104 from a given developer entity 102. Subsequently, the management entity 106 (and / or other review entities) may be configured to implement an analysis pipeline 108 to identify, at least to a reliable degree, whether the software application candidate 104 functions both as announced and according to various rules enforced by the management entity 106. The analysis pipeline 108 may involve, for example, automatic and / or manual source code analysis, automatic and / or manual asset analysis, automatic and / or manual test analysis, and the like. It should be noted that the aforementioned analysis is merely exemplary and is not meant to be limiting, and any number / form of analyses may be implemented without departing from the scope of the present disclosure.
[0030] According to some embodiments, the foregoing analysis may include identifying raw operational characteristics 112 associated with the software application candidate 104. The raw operational characteristics 112 may include, for example, any of the following aspects associated with the analyzed execution of the software application candidate 104: user interface (UI) input, motion input, UI refresh rate, sound output, power usage, memory usage, network bandwidth usage, microphone usage, camera usage, etc. It is noted that the foregoing operational characteristics are merely exemplary and are not meant to be limiting, and any aspect of the execution of a software application may be considered during the review process without departing from the scope of the present disclosure.
[0031] If / when the management entity 106 determines that the software application candidate 104 has satisfied the analysis pipeline 108, the management entity 106 may create a reviewed software application 110. According to some embodiments, the management entity 106 may perform various functions on the software application candidate 104 to create the reviewed software application 110. For example, the management entity 106 may incorporate both the software application candidate 104 and a digital signature that can be used to verify that the management entity 106 has actually reviewed the software application candidate 104 into the reviewed software application 110. Figure 1 As shown, the reviewed software application 110 may also include all (or a subset) of the original operating characteristics 112. As described in more detail below, the inclusion of the original operating characteristics 112 (in the reviewed software application 110) may enable the computing device 114, when executing the reviewed software application 110, to self-identify whether the reviewed software application 110 complies with (or contradicts) the original operating characteristics 112.
[0032] After the software application candidate 104 is converted into the reviewed software application 110, the management entity 106 may make the reviewed software application 110 available for distribution to the computing devices 114. For example, a given computing device 114 may download and install the reviewed software application 110 in response to user input, in response to receiving a configuration profile referencing the reviewed software application 110, etc. Figure 1 As shown, computing device 114 may include metric evaluator 116 configured to monitor current operating characteristics 120 of one or more reviewed software applications 110 executing on computing device 114. According to some embodiments, current operating characteristics 120 may focus on the same (or similar) operating characteristics so that differentiation can be accurately and efficiently identified by metric evaluator 116.
[0033] In short, and as previously described herein, the metric evaluator 116 may be configured to implement different levels of monitoring based on the privacy preferences specified by the user. For example, a given metric evaluator 116 may be configured to receive from a user an indication of an approved level of monitoring of a reviewed software application 110 executed on a computing device 114 prior to the first (ever) execution of the software application on the computing device 114 (on which the metric evaluator 116 is implemented). In addition, the metric evaluator 116 may be configured to scale the overall level of monitoring (where appropriate) based on progressive approvals provided by its users. For example, the metric evaluator 116 may be configured to initially monitor only operational characteristics that are inherently abstract in nature, such as UI refresh rate, power usage, and memory usage. Subsequently, when the management entity 106 identifies a potential problem indicated by one or more of the aforementioned operational characteristics, the management entity 106 may obtain approval to monitor additional operational aspects (such as user interface input, motion input, sound output, microphone usage, camera usage, etc.). Note that these (and any other) operational characteristics may be sampled in a manner that establishes a level of abstraction such that there is no violation of the user's desired level of privacy. For example, user interface input may be detected as the number of taps, gestures, etc. that occur over a period of time, motion input may be detected as basic accelerometer usage (e.g., overall level of motion), sound output may be detected as whether sound is being output (itself) and the frequency of sound output, microphone may be detected as the number of activations / overall usage, camera may be detected as the number of activations / overall usage, etc. In this way, the user may maintain complete control over the manner in which the reviewed software applications 110 are monitored and the level of granularity at which they are monitored, so that the computing device 114 behaves in accordance with the user's privacy expectations.
[0034] Now return to Figure 1, when the metric evaluator 116 has collected enough information to form the current operating characteristics 120 of a given reviewed software application 110, a comparison operation may be performed to determine if there is a conflict between the current operating characteristics 120 and the original operating characteristics 112. Figure 2 A more detailed discussion of the manner in which the comparison may be performed is described below. In any case, the comparison / conflict identification may reveal that the software application 110 under review may be providing unauthorized features to the user of the computing device 114.
[0035] According to some embodiments, when a conflict is identified, metric evaluator 116 may interface with management entity 106 to notify management entity 106 of the conflict. Figure 1 As shown, the metric evaluator 116 may be configured to provide the current operating characteristics 120 and / or the conflict information 122 to the management entity 106. According to some embodiments, the conflict information 122 may represent any information that effectively conveys the nature of the conflict identified by the metric evaluator 116, such as a unique identifier of the application, attributes associated with the execution of the software application 110 under review (e.g., frequency of use, run time, debug messages, etc.), etc. According to some embodiments, the metric evaluator 116 may be configured to provide different amounts (e.g., zero, a subset, or all) of the current operating characteristics 120 to the management entity 106 depending on performance preferences. For example, if the computing device 114 is able to reliably determine when a conflict occurs, power / network bandwidth savings may be achieved by simply omitting the current operating characteristics 120 and only providing the conflict information 122. In another example, the metric evaluator 116 may provide all or a subset of the current operating characteristics 120 to the management entity 106 as a supplement to the conflict information 122, although this will be at the expense of power / network bandwidth consumption. In yet another example, metric evaluator 116 may provide all or a subset of current operating characteristics 120 and omit conflict information 122 so that management entity 106 may perform its own conflict analysis. In any case, if / when current operating characteristics 120 are provided to management entity 106, they may be provided in a form that does not allow management entity 106 to identify personal information associated with a user of computing device 114. It is noted that the foregoing approach is not intended to be limiting, and metric evaluator 116 may be configured to provide any information to metric evaluator 116 at any level of granularity without departing from the scope of the present disclosure.
[0036] According to some embodiments, management entity 106 may take any number of actions that management entity 106 deems appropriate upon receiving current operating characteristics 120 and / or conflict information 122. For example, management entity 106 may be configured to determine whether a threshold number of concerns have been received from other computing devices regarding the reviewed software application 110 in order to identify whether the problem reported by computing device 114 is isolated or widespread. In another example, management entity 106 may be configured to perform its own analysis of current operating characteristics 120 / conflict information 122 provided by computing device 114 regarding the execution of the reviewed software application 110 to determine whether any action should be taken.
[0037] In any case, when the management entity 106 determines that a problem does in fact exist, the management entity 106 may take any number of actions that the management entity 106 deems appropriate to mitigate the problem. For example, the management entity 106 may provide an alert 124 to the developer entity 102 associated with the reviewed software application 110 to prompt the developer entity 102 to remedy the problem. The management entity 106 may also update the virtual application store to effectively suspend the occurrence of downloads / installations of the reviewed software application 110 until further notice. The management entity 106 may also issue one or more enforcement actions 126 to one or more computing devices 114 on which the reviewed software application 110 is installed, causing them to prevent the execution of the reviewed software application 110, uninstall the reviewed software application 110, and so on. It is noted that the aforementioned remedial measures are not intended to be limiting, and the management entity 106 (and / or other entities) may be configured to perform any number / type of remedial measures at any level of granularity without departing from the scope of the present disclosure.
[0038] therefore, Figure 1 A breakdown of the manner in which the developer entity 102, the management entity 106, and the computing device 114 may interact with one another to identify an audited software application 110 that attempts to provide unauthorized features is set forth below. Figure 2 A more detailed explanation of the manner in which computing device 114 is able to make such identifications is provided.
[0039] Figure 2 A conceptual diagram 200 illustrates the manner in which a computing device 114 may self-identify when a reviewed software application 110 may be providing unauthorized features, according to some embodiments. Figure 2 In the illustrated scenario, the computing device 114 is executing the reviewed software application 110, for example, after downloading the reviewed software application 110 from the management entity 106 and installing the reviewed software application 110 on the computing device 114. Figure 2As shown, current operating characteristics 120 of the software application 110 under review are collected by the metric evaluator 116, for example, in accordance with any privacy requirements enforced by the user of the computing device 114. Figure 2 As shown, the current operating characteristics 120 include various operating characteristics discussed herein, as well as various operating characteristics not described herein. Figure 2 and any other operating characteristics depicted in (as indicated by ellipses).
[0040] According to some embodiments, the metric evaluator 116 may be configured to compare the current operating characteristics 120 to the original operating characteristics 112 using any conceivable method in which data sets can be compared to each other. For example, the metric evaluator 116 may identify at least one operating characteristic (e.g., UI refresh rate) that exists in both the current operating characteristics 120 and the original operating characteristics 112. In this way, the metric evaluator 116 may identify when there is a misalignment between the operating characteristics, such as a level of change that exceeds a threshold level within a threshold amount of time. In another example, the metric evaluator 116 may identify at least one operating characteristic that exists in the original operating characteristics 112 but not in the current operating characteristics 120 (and vice versa) to identify potential problems. For example, if the software application 110 under review does not exhibit sound output during the review process, but (currently) exhibits a high level of sound output when executed on the computing device 114, the software application under review may be suspicious. In yet another example, the metric evaluator 116 may compare unrelated operating characteristics that should theoretically have a related relationship in order to identify potential problems. It is noted that the foregoing methods are merely exemplary and are not intended to be limiting, and that metric evaluator 116 may be configured to perform any analysis on raw operating characteristics 112 and / or current operating characteristics 120 at any level of granularity without departing from the scope of the present disclosure.
[0041] In addition, and if Figure 2As shown, the metric evaluator 116 may be configured to interface with one or more machine learning engines 202 (configured using the training data 204) to obtain information that may be helpful in determining whether any problems are occurring with respect to the execution of the reviewed software application 110. According to some embodiments, the raw operational characteristics 112 may be configured to include one or more classifications of the reviewed software application 110 that are generated using the same or similar machine learning engines used by the management entity 106 (and / or other entities) when performing the review process described herein. For example, the machine learning engine may classify the reviewed software application 110 as a "gaming" application when the machine learning engine observes a high amount of UI input and / or motion input, a high level of UI refresh rate within a given time period, a high level of sound output, a high level of power usage, a high level of memory usage, and / or a high level of network bandwidth usage. In another example, when the machine learning engine observes a large amount of user interface input (e.g., typing on a virtual keyboard), a small amount of motion input, a small amount of UI refresh rate, no sound output, little power usage, little memory usage, little network bandwidth usage, no microphone usage, and no camera usage, the machine learning engine may classify the reviewed software application 110 as a "text editor" application. It is noted that the foregoing examples are not intended to be limiting, and the machine learning engines discussed herein may be configured to analyze any amount of data and provide classifications at any level of granularity without departing from the scope of the present disclosure.
[0042] When the metric evaluator 116 utilizes the machine learning engine 202, the metric evaluator 116 may feed the current operational characteristics 120 to the machine learning engine 202 to obtain an updated classification of the software application under review. The metric evaluator 116 may then compare the updated classification with the original classification (established according to the techniques discussed above) to determine if there are any differences. For example, if the original operational characteristics 112 indicated that the software application under review 110 was reliably a "text editor" application, and the current operational characteristics 120 indicate that the software application under review 110 is now reliably acting as a "game" application, then the metric evaluator 116 may reliably determine that the software application under review 110 is providing unauthorized functionality.
[0043] In any case, and if Figure 2 As shown, when the metric evaluator 116 determines that the reviewed software application 110 is providing unauthorized functionality, the metric evaluator 116 may perform the following operations in accordance with the above combined Figure 1 The described techniques provide current operating characteristics 120 and / or conflict information 122 to the management entity 106. Figure 1With the described techniques, the management entity 106 may issue an enforcement action 126 to the computing device 114 on which the reviewed software application 110 is installed and / or issue a warning 124 to the developer entity 102 .
[0044] therefore, Figure 2 A conceptual diagram 200 illustrates the manner in which a computing device 114 may self-identify when a reviewed software application 110 may be providing unauthorized features, according to some embodiments. Figure 3 A more detailed explanation of an example timeline is described by which these techniques may be implemented.
[0045] Figure 3 An example timeline diagram 300 illustrates the manner in which a computing device 114 may self-identify when a reviewed software application 110 may be providing unauthorized features, according to some embodiments. Figure 3 In the example shown, the software application 110 under review has been classified (e.g., based on its original operating characteristics 112) as a "text editor" application, such that its UI refresh rate is expected to be relatively low. Figure 3 As shown, Figure 3 The Y-axis of the graph of may represent the number of times the software application 110 under review is executed on the computing device 114 over time (as indicated by Figure 3 The X-axis of the chart represents the UI refresh rate. Figure 3 As shown, the software application 110 under review initially exhibited a UI refresh rate averaging twenty-five (25) refreshes per second, which is consistent with the expected refresh rate for a "text editor" application, assuming that relatively infrequent UI refreshes are sufficient. The software application 110 under review continued to exhibit this behavior for up to 14 minutes, but the UI refresh rate suddenly increased to over sixty (60) refreshes per second (as shown in FIG. Figure 3 ). For reasons stated previously herein, this higher refresh rate is inconsistent with the expected refresh rate for a "text editor" application. Instead, the higher refresh rate indicates activity that constitutes a video playback application, a social media application, a gaming application, and the like.
[0046] In any case, when a shift in the UI refresh rate is identified, the metric evaluator 116 may be configured to Figure 1 to Figure 2 The described techniques provide current operating characteristics 120 and / or conflict information 122 to the management entity 106. The management entity 106 can then confirm that the reviewed software application 110 is in fact operating outside of its expected parameters and, in accordance with the above in conjunction with Figure 1 to Figure 2 The described techniques issue one or more enforcement actions 126. Subsequently, the computing device 114 also combines the above Figure 1 to Figure 2The described techniques are used to receive and implement the mandatory action 126. Figure 3 As shown, the implementation of the mandatory action 126 may involve the above also combined with Figure 1 to Figure 2 The described techniques are used to forcefully terminate application 304 .
[0047] therefore, Figure 3 An example timeline diagram 300 illustrates the manner in which a computing device 114 may self-identify when a reviewed software application 110 may be providing unauthorized features according to some embodiments. 4A to 4H A more detailed explanation of the user interface by which these techniques may be implemented is described.
[0048] 4A to 4H A conceptual diagram 400 of a user interface is shown through which a computing device 114 can self-identify when a reviewed software application 110 is providing unauthorized features, according to some embodiments. Figure 4A As shown, step 402 involves a user of computing device 114 launching a “text editor” application on computing device 114. In this example scenario, the “text editor” application constitutes a file that is downloaded from management entity 106 (e.g., App ) receives the reviewed software application 110, so that the reviewed software application 110 includes the original operating characteristics 112.
[0049] Now go to Figure 4B , step 404 involves a “text editor” application executing on computing device 114. In this example scenario, the “text editor” application is the first application ever launched on computing device 114, such that computing device 114 is unaware of the user's privacy preferences regarding what metric evaluator 116 is (and is not) allowed to monitor. Accordingly, a notification may be presented to the user to inform them of the default operational nature of metric evaluator 116, where the notification provides the user with the option to confirm, learn more, or opt-out. If the user opts-out of what constitutes the highest level of user privacy, metric evaluator 116 may be configured to suspend its operation such that it does not perform the techniques discussed herein. In any case, in Figure 4B In the example scenario shown in , the user approval metric evaluator 116 functions according to its default behavior.
[0050] Now turn to Figure 4C , step 406 involves the user utilizing the intended functionality of the "text editor" application. This may involve, for example, the above combined Figure 3 The first fourteen (14) minutes of the example scenario described.
[0051] Now turn to Figure 4D, step 408 involves the vetted software application 110 requesting from the user an unauthorized feature—for example, a feature that was not exposed by the “text editor” application during the vetting process performed thereon by the administrative entity 106. Figure 4D In the example shown, the "text editor" application attempts to convert to an online gambling game, and the user may or may not be aware that the online gambling game is available through the "text editor" application. In any case, the online gambling game, if exposed to the user by the "text editor" application, would violate the rules implemented by the management entity 106. Figure 4D As shown, the user chooses to enter an online gambling game.
[0052] Now turn to Figure 4E , step 410 involves the audited software application 110 providing an unauthorized feature, namely, a virtual poker game, to a user, wherein the user may engage in gambling activities prohibited by the administrative entity 106. All the while, the metric evaluator 116 continues to monitor the current operating characteristics 120 of the audited software application 110 (as described above in conjunction with Figure 4A approval of the user in question).
[0053] Now turn to Figure 4F At step 412, the metric evaluator 116 detects that the "text editor" application may be providing unauthorized functionality, for example, using the above combined Figures 1 to 3 Then, the metric evaluator 116 presents a notification to the user that the metric evaluator 116 is increasing its overall monitoring of the execution of the "text editor" application (according to the above in conjunction with Figures 1 to 3 Likewise, this may involve the metric evaluator 116 analyzing additional current operating characteristics 120 of the “text editor” application and / or increasing the level of granularity at which the metric evaluator 116 analyzes the current operating characteristics 120 of the “text editor” application. Figure 4F As shown, the user is again presented with the options of approving the increased monitoring, receiving additional information required regarding the increased level of monitoring, and simply closing the "Text Editor" application so that the increased monitoring is unnecessary.
[0054] Now turn to Figure 4G , step 414 involves metric evaluator 116 (1) detecting and notifying a user that current operating characteristics 120 of the "text editor" application are not reliably aligned with original operating characteristics 112, and (2) providing notification (i.e., current operating characteristics 120 and / or conflict information 122) to management entity 106. Figure 4G As shown, the user is again presented with the option of confirming that the notification has been sent, receiving additional information required regarding the notification, and simply closing the "Text Editor" application.
[0055] Now turn to Figure 4H Step 416 involves metric evaluator 116 (1) receiving one or more enforcement actions 126 from management entity 106, (2) notifying a user of the nature of enforcement actions 126, and (3) implementing enforcement actions 126. Figure 4H As shown in , the enforcement action 126 may involve terminating execution of the "text editor" application and disabling future execution of the "text editor" application until further notification is received (e.g., reauthorizing execution of the "text editor" application from the administrative entity 106). Although not shown in Figure 4H , but the metric evaluator 116 may first interface with the user before implementing any mandatory actions 126. For example, the metric evaluator 116 may simply recommend mandatory actions 126 to the user and implement them only upon receiving approval from the user.
[0056] therefore, 4A to 4H A conceptual diagram illustrating a user interface through which a computing device 114 can self-identify when a reviewed software application 110 is providing unauthorized features, according to some embodiments. Figures 5 and 6 A high-level overview of the techniques described herein that are respectively performed by computing device 114 and management entity 106 is provided.
[0057] Figure 5 A method 500 for identifying when a software application 110 under review has been transformed to provide unauthorized features is shown in accordance with some embodiments. According to some embodiments, the method may be performed by Figure 1 The embodiment of the present invention is implemented by one of the computing devices 114 shown and described herein. Figure 5 As shown, method 500 begins at step 502, where computing device 114 receives and installs a reviewed software application 110, where the reviewed software application 110 includes at least original operating characteristics 112 of the reviewed software application 110 (e.g., as described above in conjunction with Figures 1 to 3 and 4A to 4H described).
[0058] At step 504, the computing device 114 collects at least one current operating characteristic 120 of the reviewed software application 110 during execution of the reviewed software application 110 (e.g., as described above in connection with Figures 1 to 3 and 4A to 4H At step 506, the computing device 114 identifies that there is a conflict between at least one original operating characteristic 112 of the reviewed software application 110 and at least one current operating characteristic 120 of the reviewed software application 110 (e.g., as described above in conjunction with Figures 1 to 3 and 4A to 4H described).
[0059] At step 508, the computing device 114 provides an indication of the conflict to the management entity 106 associated with the reviewed software application 110 (e.g., as described above in connection with Figures 1 to 3 and 4A to 4H described). Then—and not in Figure 5 106 may perform various functions that may or may not involve computing device 114, such as enforcement action 126 (e.g., as described above in conjunction with Figures 1 to 3 and 4A to 4H described).
[0060] Figure 6 A method 600 for managing a scenario in which a reviewed software application 110 transitions to provide unauthorized features is shown according to some embodiments. According to some embodiments, the method 600 may be performed by Figure 1 The management entity 106 shown and described herein is implemented as Figure 6 As shown, method 600 begins at step 602, where management entity 106 receives a request from developer entity 102 to make a software application (e.g., software application candidate 104) accessible to computing device 114 (e.g., as described above in conjunction with Figures 1 to 3 and 4A to 4H described).
[0061] At step 604, the management entity 106 subjects the software application candidate 104 to at least one review procedure to identify at least one raw operational characteristic 112 of the software application candidate 104 (e.g., as described above in connection with Figures 1 to 3 and 4A to 4H At step 606, the management entity 106 creates a reviewed software application 110 based on the software application candidate 104, wherein the reviewed software application 110 includes at least one original operating characteristic 112 (e.g., as described above in conjunction with Figures 1 to 3 and 4A to 4H At step 608, the management entity 106 distributes the reviewed software application 110 to at least one computing device 114 (e.g., as described above in conjunction with Figures 1 to 3 and 4A to 4H described).
[0062] At step 610, the management entity 106 receives an indication from the computing device 114 on which the reviewed software application 110 is installed that there is a conflict between at least one original operating characteristic 112 and at least one current operating characteristic 120 of the reviewed software application 110 (e.g., as described above in connection with Figures 1 to 3 and 4A to 4H described).
[0063] At step 612, the management entity 106, in response to identifying that a threshold number of indications have been received from other computing devices 114 regarding the reviewed software application 110, causes at least one action—e.g., the enforcement action 126—to be performed in association with the reviewed software application 110 (e.g., as described above in connection with Figures 1 to 3 and 4A to 4H described).
[0064] It is noted that the metric evaluator 116 described herein may be configured to reduce the number of false positive conflict identifications that occur. For example, a free "text editor" application may periodically present a thirty (30) second video advertisement to its users in lieu of charging a fee for use of the software application. In this regard, the metric evaluator 116 may be configured to identify when deviations from the original operating characteristics 112 may be attributed to such advertisements in order to avoid erroneously interpreting such instances as the reviewed software application 110 providing unauthorized features. For example, the metric evaluator 116 may be configured to detect (and ignore) an application programming interface (API) call that indicates that the reviewed software application 110 is calling for a pop-up advertisement to be displayed. In another example, the metric evaluator 116 may be configured to detect (and ignore) an API call that indicates that the reviewed software application 110 is attempting to receive and display an advertisement from an advertisement provider. It is noted that the foregoing examples are not meant to be limiting, and the metric evaluator 116 may be configured to effectively identify and mitigate any issues that may present false positive conflicts.
[0065] Additionally, it is noted that while the embodiments primarily relate to reviewed software applications, similar techniques described herein may be implemented to identify when the execution of non-reviewed software applications exceeds the expectations of the user. According to some embodiments, these embodiments may enable subsets of computing devices 114 to share operational characteristics regarding a given software application that is commonly installed across computing devices 114 (e.g., using a crowdsourcing approach, a decentralized processing approach, etc.). One or more computing devices 114 in the subset of computing devices 114 may then aggregate this information to effectively establish baseline operational characteristics that are functionally equivalent to the original operational characteristics 112 identified by the metric evaluator 116 as discussed herein. The baseline operational characteristics may then be distributed among the subset of computing devices 114, thereby enabling them to self-identify if / when a software application exhibits current operational characteristics that do not conform to the baseline operational characteristics. Subsequently, one or more computing devices 114 in the subset of computing devices 114 that self-identify (or collaboratively identify) any issues may alert other computing devices 114 of their findings. The computing devices 114 may then individually or collectively enforce the remedial measures discussed herein.
[0066] Figure 7 A detailed view of a representative computing device 700 that can be used to implement the various methods described herein is shown according to some embodiments. Specifically, the detailed view shows various components that can be included in one or more computing devices associated with the developer entity 102, one or more computing devices associated with the management entity 106, and the computing device 114. Figure 7 As shown, the computing device 700 may include a processor 702 representing a microprocessor or a controller for controlling the overall operation of the computing device 700. The computing device 700 may also include a user input device 708 that allows a user of the computing device 700 to interact with the computing device 700. For example, the user input device 708 can take a variety of forms, such as buttons, keypads, dials, touch screens, audio input interfaces, visual / image capture input interfaces, inputs in the form of sensor data, etc. Further, the computing device 700 can include a display 710 that can be controlled by the processor 702 to display information to the user. The data bus 716 can facilitate data transmission between at least the storage device 740, the processor 702, and the controller 713. The controller 713 can be used to interface with and control different equipment through the equipment control bus 714. The computing device 700 may also include a network / bus interface 711 communicatively coupled to the data link 712. In the case of a wireless connection, the network / bus interface 711 may include a wireless transceiver.
[0067] The computing device 700 also includes a storage device 740, which may include a single disk or multiple disks (e.g., a hard drive) and a storage management module that manages one or more partitions within the storage device 740. In some embodiments, the storage device 740 may include flash memory, semiconductor (solid-state) memory, etc. The computing device 700 may also include a random access memory (RAM) 720 and a read-only memory (ROM) 722. The ROM 722 may store programs, utilities, or processes to be executed in a non-volatile manner. The RAM 720 may provide volatile data storage and store instructions related to the operation of the computing device 700. The computing device 700 may also include a secure element (SE) 724, which is used for the computing device 700 to access a cellular wireless system.
[0068] The various aspects, embodiments, specific implementations or features of the described embodiments may be used individually or in any combination. Various aspects of the described embodiments may be implemented by software, hardware, or a combination of hardware and software. The described embodiments may also be implemented as computer-readable code on a non-transient computer-readable medium. A non-transient computer-readable medium is any data storage device that can store data, which can then be read by a computer system. Examples of non-transient computer-readable media include read-only memory, random access memory, CD-ROM, HDD, DVD, magnetic tape, and optical data storage devices. Non-transient computer-readable media may also be distributed on network-coupled computer systems so that the computer-readable code is stored and executed in a distributed manner.
[0069] In connection with this disclosure, it is understood that the use of personally identifiable information should be subject to privacy policies and practices that are generally recognized to meet or exceed industry or government requirements for maintaining user privacy. Specifically, personally identifiable information data should be managed and processed to minimize the risk of unintentional or unauthorized access or use, and the nature of the authorized use should be clearly stated to users.
[0070] For the purpose of explanation, the foregoing description uses specific nomenclature to provide a thorough understanding of the described embodiments. However, it will be apparent to those skilled in the art that specific details are not required in order to practice the described embodiments. Therefore, the foregoing description of specific embodiments is presented for the purpose of illustration and description. The foregoing description is not intended to be exhaustive or to limit the described embodiments to the precise form disclosed. It will be apparent to those of ordinary skill in the art that, in view of the above teachings, many modifications and variations are possible.
Claims
1. A method for identifying when a reviewed software application is transformed to provide unauthorized features, the method comprising, at a computing device: receiving and installing the reviewed software application, wherein the reviewed software application specifies at least one original operating characteristic of the reviewed software application; collecting at least one current operating characteristic of the reviewed software application during execution of the reviewed software application; identifying that a conflict exists between the at least one original operating characteristic of the reviewed software application and the at least one current operating characteristic of the reviewed software application; as well as An indication of the conflict is provided to an administrative entity associated with the reviewed software application.
2. The method of claim 1, wherein the indication comprises a notification that the at least one current operating characteristic and / or the reviewed software application appears to be providing an unauthorized feature.
3. The method of claim 1, wherein the vetted software application comprises a software application authenticated by at least the administrative entity prior to enabling the software application to be distributed and installed on a computing device.
4. The method of claim 1 , wherein the at least one current operating characteristic is based on at least one of: user interface (UI) input associated with said execution of said reviewed software application, motion input associated with said execution of said reviewed software application, a UI refresh rate associated with said execution of said reviewed software application, sound output associated with said execution of said reviewed software application, power usage associated with said execution of said reviewed software application, memory usage associated with said execution of said reviewed software application, an amount of network bandwidth usage associated with said execution of said reviewed software application, microphone usage associated with said execution of said reviewed software application, or camera usage associated with the execution of the reviewed software application.
5. The method of claim 1 , wherein identifying that the conflict exists comprises: identifying first and second operating characteristics respectively shared between the at least one original operating characteristic and the at least one current operating characteristic, and It is identified that a degree of dissimilarity between the first operating characteristic and the second operating characteristic satisfies a threshold.
6. The method of claim 1, further comprising, prior to collecting the at least one current operating characteristic of the reviewed software application: prompting a user of the computing device with a request for the at least one current operating characteristic; and An approval of the request is received from the user.
7. The method according to claim 1, further comprising: Suspending or terminating said execution of said reviewed software application.
8. A non-transitory computer-readable storage medium configured to store instructions that, when executed by at least one processor included in a computing device, cause the computing device to identify when a reviewed software application transitions to provide unauthorized features by performing steps comprising: receiving and installing the reviewed software application, wherein the reviewed software application specifies at least one original operating characteristic of the reviewed software application; collecting at least one current operating characteristic of the reviewed software application during execution of the reviewed software application; identifying that a conflict exists between the at least one original operating characteristic of the reviewed software application and the at least one current operating characteristic of the reviewed software application; as well as An indication of the conflict is provided to an administrative entity associated with the reviewed software application.
9. The non-transitory computer-readable storage medium of claim 8, wherein the indication comprises a notification that the at least one current operating characteristic and / or the reviewed software application appears to be providing an unauthorized feature.
10. The non-transitory computer-readable storage medium of claim 8, wherein the vetted software application comprises a software application authenticated by at least the administrative entity prior to enabling the software application to be distributed and installed on a computing device.
11. The non-transitory computer-readable storage medium of claim 8, wherein the at least one current operating characteristic is based on at least one of: user interface (UI) input associated with said execution of said reviewed software application, motion input associated with said execution of said reviewed software application, a UI refresh rate associated with said execution of said reviewed software application, sound output associated with said execution of said reviewed software application, power usage associated with said execution of said reviewed software application, memory usage associated with said execution of said reviewed software application, an amount of network bandwidth usage associated with said execution of said reviewed software application, microphone usage associated with said execution of said reviewed software application, or camera usage associated with the execution of the reviewed software application.
12. The non-transitory computer-readable storage medium of claim 8, wherein identifying that the conflict exists comprises: identifying first and second operating characteristics respectively shared between the at least one original operating characteristic and the at least one current operating characteristic, and It is identified that a degree of dissimilarity between the first operating characteristic and the second operating characteristic satisfies a threshold.
13. The non-transitory computer-readable storage medium of claim 8, wherein the steps further comprise, prior to collecting the at least one current operating characteristic of the audited software application: prompting a user of the computing device with a request for the at least one current operating characteristic; and An approval of the request is received from the user.
14. The non-transitory computer readable storage medium of claim 8, wherein the steps further comprise: Suspending or terminating said execution of said reviewed software application.
15. A computing device configured to identify when a reviewed software application transitions to provide unauthorized features, the computing device comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the computing device to perform steps comprising: receiving and installing the reviewed software application, wherein the reviewed software application specifies at least one original operating characteristic of the reviewed software application; collecting at least one current operating characteristic of the reviewed software application during execution of the reviewed software application; identifying that a conflict exists between the at least one original operating characteristic of the reviewed software application and the at least one current operating characteristic of the reviewed software application; as well as An indication of the conflict is provided to an administrative entity associated with the reviewed software application.
16. The computing device of claim 15, wherein the indication comprises a notification that the at least one current operating characteristic and / or the reviewed software application appears to be providing an unauthorized feature.
17. The computing device of claim 15, wherein the vetted software application comprises a software application authenticated by at least the administrative entity prior to enabling the software application to be distributed and installed on the computing device.
18. The computing device of claim 15, wherein the at least one current operating characteristic is based on at least one of: user interface (UI) input associated with said execution of said reviewed software application, motion input associated with said execution of said reviewed software application, a UI refresh rate associated with said execution of said reviewed software application, sound output associated with said execution of said reviewed software application, power usage associated with said execution of said reviewed software application, memory usage associated with said execution of said reviewed software application, an amount of network bandwidth usage associated with said execution of said reviewed software application, microphone usage associated with said execution of said reviewed software application, or camera usage associated with the execution of the reviewed software application.
19. The computing device of claim 15, wherein identifying that the conflict exists comprises: identifying first and second operating characteristics respectively shared between the at least one original operating characteristic and the at least one current operating characteristic, and It is identified that a degree of dissimilarity between the first operating characteristic and the second operating characteristic satisfies a threshold.
20. The computing device of claim 15, wherein the steps further comprise, prior to collecting the at least one current operating characteristic of the reviewed software application: prompting a user of the computing device with a request for the at least one current operating characteristic; and An approval of the request is received from the user.
21. The computing device of claim 15, wherein the steps further comprise: Suspending or terminating said execution of said reviewed software application.
22. A computing device configured to identify when a reviewed software application transitions to provide unauthorized features, the computing device comprising: means for receiving and installing the reviewed software application, wherein the reviewed software application specifies at least one original operating characteristic of the reviewed software application; means for collecting at least one current operating characteristic of said reviewed software application during execution of said reviewed software application; means for identifying a conflict between said at least one original operating characteristic of said reviewed software application and said at least one current operating characteristic of said reviewed software application; and Means for providing an indication of the conflict to an administrative entity associated with the reviewed software application.
23. The computing device of claim 22, wherein the indication comprises a notification that the at least one current operating characteristic and / or the reviewed software application appears to be providing an unauthorized feature.
24. The computing device of claim 22, wherein the vetted software application comprises a software application authenticated by at least the administrative entity prior to enabling the software application to be distributed and installed on the computing device.
25. The computing device of claim 22, wherein the at least one current operating characteristic is based on at least one of: user interface (UI) input associated with said execution of said reviewed software application, motion input associated with said execution of said reviewed software application, a UI refresh rate associated with said execution of said reviewed software application, sound output associated with said execution of said reviewed software application, power usage associated with said execution of said reviewed software application, memory usage associated with said execution of said reviewed software application, an amount of network bandwidth usage associated with said execution of said reviewed software application, microphone usage associated with said execution of said reviewed software application, or camera usage associated with the execution of the reviewed software application.
26. The computing device of claim 22, wherein identifying that the conflict exists comprises: identifying first and second operating characteristics respectively shared between the at least one original operating characteristic and the at least one current operating characteristic, and It is identified that a degree of dissimilarity between the first operating characteristic and the second operating characteristic satisfies a threshold.
27. The computing device of claim 22, further comprising means for, prior to collecting the at least one current operating characteristic of the audited software application: prompting a user of the computing device with a request for the at least one current operating characteristic; and An approval of the request is received from the user.
28. The computing device of claim 22, further comprising: Means for pausing or terminating said execution of said reviewed software application.
29. A method for managing scenarios in which a vetted software application is transformed to provide unauthorized features, the method comprising: receiving, from a computing device on which the reviewed software application is installed, an indication that there is a conflict between at least one original operating characteristic of the reviewed software application and at least one current operating characteristic of the reviewed software application; and In response to identifying that a threshold number of indications have been received from other computing devices regarding the reviewed software application: At least one enforcement action is caused to be performed in association with the reviewed software application.
30. The method of claim 29, wherein the at least one enforcement action comprises: providing a warning to a developer associated with the reviewed software application; suspending the downloading of said reviewed software application; and / or One or more computing devices on which the reviewed software application is installed are caused to prevent execution of the reviewed software application.
31. The method of claim 29, further comprising, before receiving the indication: receiving a software application from a developer entity; and In response to subjecting the software application to at least one review procedure: The reviewed software application is established based on the software application.
32. The method of claim 31, wherein the at least one review procedure comprises: The at least one raw operational characteristic is identified as exhibited by the software application during the at least one audit procedure.
33. The method of claim 32, wherein the at least one raw operating characteristic is based on at least one of: user interface (UI) input associated with said software application during said at least one review procedure, motion input associated with said software application during said at least one review procedure, a UI refresh rate associated with the software application during the at least one review procedure, sound output associated with said software application during said at least one review procedure, power usage associated with the software application during the at least one audit procedure, memory usage associated with the software application during the at least one audit procedure, an amount of network bandwidth usage associated with the software application during the at least one audit procedure, usage of a microphone associated with the software application during the at least one review procedure, or camera usage associated with the software application during the at least one audit procedure.
34. The method of claim 29, wherein the at least one original operating characteristic is included in the reviewed software application.
35. A non-transitory computer-readable storage medium configured to store instructions that, when executed by at least one processor included in at least one server device associated with an administrative entity, cause the at least one server device to manage a scenario in which a reviewed software application is transformed into providing unauthorized features by performing steps comprising: receiving, from a computing device on which the reviewed software application is installed, an indication that there is a conflict between at least one original operating characteristic of the reviewed software application and at least one current operating characteristic of the reviewed software application; and In response to identifying that a threshold number of indications have been received from other computing devices regarding the reviewed software application: At least one enforcement action is caused to be performed in association with the reviewed software application.
36. The non-transitory computer-readable storage medium of claim 35, wherein the at least one enforcement action comprises: providing a warning to a developer associated with the reviewed software application; suspending the downloading of said reviewed software application; and / or One or more computing devices on which the reviewed software application is installed are caused to prevent execution of the reviewed software application.
37. The non-transitory computer readable storage medium of claim 35, wherein the steps further comprise, before receiving the indication: receiving a software application from a developer entity; and In response to subjecting the software application to at least one review procedure: The reviewed software application is established based on the software application.
38. The non-transitory computer readable storage medium of claim 37, wherein the at least one review procedure comprises: The at least one raw operational characteristic is identified as exhibited by the software application during the at least one audit procedure.
39. The non-transitory computer-readable storage medium of claim 38, wherein the at least one raw operating characteristic is based on at least one of: user interface (UI) input associated with said software application during said at least one review procedure, motion input associated with said software application during said at least one review procedure, a UI refresh rate associated with the software application during the at least one review procedure, sound output associated with said software application during said at least one review procedure, power usage associated with the software application during the at least one audit procedure, memory usage associated with the software application during the at least one audit procedure, an amount of network bandwidth usage associated with the software application during the at least one audit procedure, usage of a microphone associated with the software application during the at least one review procedure, or camera usage associated with the software application during the at least one audit procedure.
40. The non-transitory computer-readable storage medium of claim 35, wherein the at least one raw operating characteristic is included in the reviewed software application.
41. At least one server device associated with a management entity, the at least one server device configured to manage scenarios in which a reviewed software application is transformed to provide unauthorized features, the at least one server device comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the at least one server device to perform steps comprising: receiving, from a computing device on which the reviewed software application is installed, an indication that there is a conflict between at least one original operating characteristic of the reviewed software application and at least one current operating characteristic of the reviewed software application; as well as In response to identifying that a threshold number of indications have been received from other computing devices regarding the reviewed software application: At least one enforcement action is caused to be performed in association with the reviewed software application.
42. The at least one server device of claim 41, wherein the at least one enforcement action comprises: providing a warning to a developer associated with the reviewed software application; suspending the downloading of said reviewed software application; and / or One or more computing devices on which the reviewed software application is installed are caused to prevent execution of the reviewed software application.
43. The at least one server device of claim 41, wherein the steps further comprise, prior to receiving the indication: receiving a software application from a developer entity; and In response to subjecting the software application to at least one review procedure: The reviewed software application is established based on the software application.
44. The at least one server device of claim 43, wherein the at least one review procedure comprises: The at least one raw operational characteristic is identified as exhibited by the software application during the at least one audit procedure.
45. The at least one server device of claim 44, wherein the at least one raw operational characteristic is based on at least one of: user interface (UI) input associated with said software application during said at least one review procedure, motion input associated with said software application during said at least one review procedure, a UI refresh rate associated with the software application during the at least one review procedure, sound output associated with said software application during said at least one review procedure, power usage associated with the software application during the at least one audit procedure, memory usage associated with the software application during the at least one audit procedure, an amount of network bandwidth usage associated with the software application during the at least one audit procedure, usage of a microphone associated with the software application during the at least one review procedure, or camera usage associated with the software application during the at least one audit procedure.
46. The at least one server device of claim 41, wherein the at least one original operating characteristic is included in the audited software application.
47. At least one server device associated with a management entity, the at least one server device configured to manage scenarios in which a reviewed software application is transformed to provide unauthorized features, the at least one server device comprising: means for receiving, from a computing device on which the reviewed software application is installed, an indication that a conflict exists between at least one original operating characteristic of the reviewed software application and at least one current operating characteristic of the reviewed software application; and Means for, in response to identifying that a threshold number of indications have been received from other computing devices regarding the reviewed software application, performing the following operations: At least one enforcement action is caused to be performed in association with the reviewed software application.
48. The at least one server device of claim 47, wherein the at least one enforcement action comprises: providing a warning to a developer associated with the reviewed software application; suspending the downloading of said reviewed software application; and / or One or more computing devices on which the reviewed software application is installed are caused to prevent execution of the reviewed software application.
49. The at least one server device of claim 47, further comprising means for, prior to receiving the indication, performing the following operations: receiving a software application from a developer entity; and In response to subjecting the software application to at least one review procedure: The reviewed software application is established based on the software application.
50. The at least one server device of claim 49, wherein the at least one review procedure comprises: The at least one raw operational characteristic is identified as exhibited by the software application during the at least one audit procedure.
51. The at least one server device of claim 50, wherein the at least one raw operational characteristic is based on at least one of: user interface (UI) input associated with said software application during said at least one review procedure, motion input associated with said software application during said at least one review procedure, a UI refresh rate associated with the software application during the at least one review procedure, sound output associated with said software application during said at least one review procedure, power usage associated with the software application during the at least one audit procedure, memory usage associated with the software application during the at least one audit procedure, an amount of network bandwidth usage associated with the software application during the at least one audit procedure, usage of a microphone associated with the software application during the at least one review procedure, or camera usage associated with the software application during the at least one audit procedure.
52. The at least one server device of claim 47, wherein the at least one original operating characteristic is included in the reviewed software application.