Method and system for detecting leakage of mobile security file

The mobile security file leakage detection method and system address the limitations of existing MDM solutions by analyzing media files on connected mobile devices for abnormalities, enhancing detection speed, and ensuring privacy through file deletion, thereby providing effective security and reporting.

WO2025095323A1PCT designated stage expired Publication Date: 2025-05-08UROCK INC
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/013299
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-02
Filing Date
2024-09-04
Publication Date
2025-05-08

AI Technical Summary

Technical Problem

Existing Mobile Device Management (MDM) solutions face challenges such as infringement of personal information, excessive information collection, and complexity, which are not effectively addressed by prior solutions like the Action Detection System for abnormal behavior control.

Method used

A mobile security file leakage detection method and system that connects a mobile device to a PC, analyzes the media file system for abnormalities, and generates a report for file extraction and deletion, using standardized communication protocols for compatibility and flexibility.

Benefits of technology

The system improves mobile device detection and analysis speed by setting a specific analysis range, prevents personal information infringement by deleting media files, and provides a comprehensive report for remote management and security assurance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024013299_08052025_PF_FP_ABST
    Figure KR2024013299_08052025_PF_FP_ABST
Patent Text Reader

Abstract

A method for detecting leakage of a mobile security file according to the present invention includes the steps in which: a detection server receives an operating system type from a mobile device; the detection server loads a media file system by connecting to the mobile device according to the operating system; the detection server connected to the mobile device checks an analysis setting time; the detection server analyzes the media file system to detect whether there is an abnormality; the detection server generates the analysis result on the basis of whether there is an abnormality; the detection server determines whether there is an error in the analysis result and extracts an original file and a thumbnail file when there is no error in the analysis result; the detection server deletes the file, which has undergone the detection for abnormality, according to the analysis result; and the detection server generates and stores a result report on the analysis result. The operating system type is at least one of a first operating system or a second operating system.
Need to check novelty before this filing date? Find Prior Art

Description

Mobile security file leak detection method and system

[0001] The present invention relates to a method and system for detecting mobile security file leaks, which can detect abnormal media files after collecting data by connecting a mobile device to a PC, and can extract the files from the mobile device and delete or store them to generate a result report.

[0002] Mobile security is a key element of mobile devices, providing enhanced security features for smartphones, laptops, and tablets. Companies and corporations are increasingly embracing BYOD (Bring Your Own Device) initiatives to create efficient workspaces for employees. Consequently, employees can access corporate networks not only during work hours but also when off-site, increasing the need to ensure the safety and security of financial and corporate data from remote locations. Furthermore, because mobile devices access critical business data, it's crucial to manage and secure these devices within each corporate environment.

[0003] Mobile Device Management (MDM) is a set of tools designed to address these challenges while maintaining enterprise data security and providing employees with mobile productivity tools and applications. However, MDM implementations have been associated with drawbacks, including privacy violations, excessive data collection, and complexity relative to efficiency. To prevent privacy violations, MDM should be able to set a specific scope for analysis and selectively target specific points in time, and media file deletion capabilities should be implemented to prevent preemptive leaks.

[0004] As for prior patents, there is a domestic registered patent No. 10-1501669 (Behavior detection system for detecting abnormal behavior), but it only provides a behavior detection system for detecting abnormal behavior that can implement dynamic control based on user-specific situation information and profiles to respond to factors that threaten the security of internal corporate infrastructure, such as information leaks in BYOD (Bring Your Own Device) and smart work environments.

[0005] The problem to be solved by the present invention is to solve the problems of the prior art as described above, and to prevent infringement of personal information and privacy, the speed of mobile device detection and analysis can be improved by analyzing abnormal files by setting a range based on a specific point in time through an automated system, and excessive access to and response to stored information can be prevented, and advance leakage can be prevented through a media file deletion function.

[0006] In the mobile security file leak detection method of the present invention, the method comprises: a step in which a detection server receives an operating system type from a mobile device; a step in which the detection server connects to the mobile device according to the operating system and loads a media file system; a step in which the detection server connected to the mobile device checks an analysis setting time; a step in which the detection server analyzes the media file system to detect anomalies; a step in which the detection server generates an analysis result based on the anomalies; a step in which the detection server checks whether there are errors in the analysis result and, if there are no errors, extracts an original file and a thumbnail file; a step in which the detection server deletes a file in which an anomaly is detected based on the analysis result; and a step in which the detection server generates and stores a result report on the analysis result, wherein the operating system type is at least one of a first operating system and a second operating system.

[0007] In the mobile security file leak detection system of the present invention, the system includes a mobile device that transmits an operating system type to a detection server and connects to the detection server according to the operating system type, a detection server that receives an operating system type from the mobile device, transmits the operating system type to the detection server, connects to the mobile device according to the operating system to load a media file system, checks an analysis setting time, analyzes the media file system to detect anomalies, generates an analysis result based on the anomalies, checks whether there are errors in the analysis result, and extracts an original image and a thumbnail image if there are no errors, deletes a file in which anomalies are detected according to the analysis result, and generates and stores a result report according to the analysis result.

[0008] According to one embodiment of the present invention, in order to complement the limitations of the MDM solution, a mobile device can be connected to a PC for each operating system to detect media files with abnormalities, and a standardized communication protocol can be used to flexibly respond to updates of each operating system and compatibility with new devices.

[0009] Additionally, you can extract files with abnormalities from your mobile device, save them to your PC, and generate a corresponding result report.

[0010] Additionally, you can remotely check the results report and mobile device analysis and statistics through the web manager.

[0011] FIG. 1 is a flowchart illustrating a mobile security file leak detection method according to an embodiment of the present invention.

[0012] FIG. 2 is a flowchart illustrating a method for analyzing a media file system of a mobile device whose operating system type is a first operating system according to an embodiment of the present invention to detect anomalies.

[0013] FIG. 3 is a flowchart illustrating a method for analyzing a media file system of a mobile device whose operating system type is a second operating system according to an embodiment of the present invention to detect anomalies.

[0014] FIG. 4 is a configuration diagram illustrating a mobile security file leak detection system according to an embodiment of the present invention.

[0015] Figures 5 and 6 are screens that allow remote confirmation of analysis content and statistics through a web manager according to an embodiment of the present invention and via a mobile device.

[0016] Any specific structural or functional descriptions of embodiments according to the concept of the present invention disclosed in this specification are merely illustrative for the purpose of explaining embodiments according to the concept of the present invention, and embodiments according to the concept of the present invention may be implemented in various forms and are not limited to the embodiments described in this specification.

[0017] Embodiments according to the concept of the present invention may have various modifications and take various forms, and thus, embodiments are illustrated in the drawings and described in detail herein. However, this is not intended to limit embodiments according to the concept of the present invention to specific disclosed forms, but rather includes all modifications, equivalents, or alternatives falling within the spirit and technical scope of the present invention.

[0018] The terminology used herein is merely used to describe specific embodiments and is not intended to limit the present invention. The singular expression includes the plural expression unless the context clearly indicates otherwise. In this specification, it should be understood that the terms "comprises" or "has" indicate the presence of a feature, number, step, operation, component, part, or combination thereof described in this specification, but do not exclude in advance the possibility of the presence or addition of one or more other features, numbers, steps, operations, components, parts, or combinations thereof.

[0019] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings attached to this specification.

[0020]

[0021] FIG. 1 is a flowchart illustrating a mobile security file leak detection method according to an embodiment of the present invention.

[0022] Referring to FIG. 1, a detection server (200) receives an operating system type from a mobile device (100), and can load a media file system by connecting to the mobile device (100) according to the operating system type (S101). The mobile device (100) may include, but is not necessarily limited to, mobile devices such as a smart phone, a mobile phone, a computer, a laptop, a digital broadcasting terminal, a PDA (Personal Digital Assistants), a PMP (Portable Multimedia Player), and a tablet. In addition to tablet devices and smart phones, the mobile device (100) may correspond to various devices equipped with a display screen, such as a laptop, a PDA, and a wearable device (watch, glasses, etc.). The operating system type may be at least one of a first operating system and a second operating system. The first operating system may be an Android operating system, and the second operating system may be an iOS operating system, but is not necessarily limited thereto.

[0023] If the operating system received from the mobile device (100) is the first operating system, the detection server (200) can load a media file system from the mobile device (100) through MTP (Media Transfer Protocol) communication, and can connect to the mobile device (100) through a command using the ADB (Android Debug Bridge) debugging tool.

[0024] The detection server (200) can connect to the mobile device (100) via MTP (Media Transfer Protocol) communication when the operating system received from the mobile device (100) is a second operating system. In addition, the detection server (200) can connect to the mobile device (100) using AFC (Apple File Conduit) to improve connection speed and access a wide range of media files.

[0025] The detection server (200) connected to the mobile device (100) checks the analysis setting time (S103). The analysis setting time may refer to the time set before the start of analysis, and allows analysis only for the period corresponding to the analysis setting time in the media file system loaded from the mobile device (100). The detection server (200) analyzes the media file system to detect any abnormalities and generates analysis results based on the abnormalities (S105). At this time, the detection server (200) can check the log regarding camera usage and determine that an abnormality has occurred if the camera is used during the analysis setting time. In addition, the detection server (200) can determine that the creation and modification times of directories and files of the mobile device (100) fall within the analysis setting time and determine that an abnormality has occurred if the creation and modification of directories and files are detected during the analysis setting time. In addition, the detection server (200) can check the log related to media and analyze the usage pattern and determine that an abnormality has occurred if the creation and behavior of media files that are different from the pattern are found. Additionally, the detection server (200) can check DB data related to media, extract necessary data, and determine whether there is an abnormality.

[0026] The detection server (200) checks whether there is an error in the analysis result, and if there is no error, extracts the original file and the thumbnail file (S107). The original file is used for storage purposes, and the thumbnail file can be used for the purpose of being added when generating a result report. The detection server (200) deletes files that are detected to be abnormal based on the analysis result (S109), and the detection server (200) generates and stores a result report on the analysis result (S111). The detection server (200) generates a file list of files that have evidence of leakage or are in violation of security based on the analysis result, and can delete them from the mobile device (100). When the detection server (200) deletes a file, it can select a location to be deleted between the local PC and the mobile device (100) and delete it, and a deletion reason can be written for deletion management. The above results report may include, but is not necessarily limited to, at least one of the following: analyzed mobile device information, analyst information, analysis result information, a list of files with thumbnails, a list of deleted files, camera usage information, and timeline summary information.

[0027]

[0028] FIG. 2 is a flowchart illustrating a method for analyzing a media file system of a mobile device whose operating system type is a first operating system according to an embodiment of the present invention to detect anomalies.

[0029] Referring to FIG. 2, the first operating system (220) performs a general analysis to analyze directory files, app-specific directories, and deleted data in the media file system (S201). The general analysis can load the file system of the mobile device via MTP communication, and can perform directory file analysis, app-specific directory analysis, and deleted data analysis. The first operating system (220) performs a detailed analysis to analyze the file system and logs in the media file system (S203). The detailed analysis can be performed via the ADB debugging tool, and can perform file system analysis and log analysis. The first operating system (220) performs a hidden analysis to analyze DB files, DB logs, and secure folders in the media file system (S205). Samsung Galaxy mobile devices using the Android operating system provide a secure folder function, so when the camera is used by utilizing the secure folder function, only administrator rights can access the shooting history, and it is encrypted and cannot be confirmed. Therefore, the first operating system (220) can perform an analysis separately through a hidden analysis for Samsung Galaxy mobile devices. The first operating system unit (220) detects whether there is an abnormality through at least one analysis among general analysis, detailed analysis, and hidden analysis (S207).

[0030]

[0031] FIG. 3 is a flowchart illustrating a method for analyzing a media file system of a mobile device whose operating system type is a second operating system according to an embodiment of the present invention to detect anomalies.

[0032] Referring to FIG. 3, the second operating system (230) performs a general analysis to analyze directory files, app-specific directories, and deleted data in the media file system (S301). The general analysis can obtain a list of media-related files and directories of the mobile device (100) by utilizing AFC, and can perform directory file analysis, app-specific directory analysis, and deleted data analysis. The second operating system (230) analyzes media resource-related files of the mobile device in the media file system to perform a detailed analysis (S303). The detailed analysis can be performed by analyzing media resource-related files of the iOS mobile device. The second operating system (230) detects whether there is an abnormality through at least one of the general analysis and the detailed analysis (S305).

[0033]

[0034] FIG. 4 is a configuration diagram illustrating a mobile security file leak detection system according to an embodiment of the present invention.

[0035] Referring to FIG. 4, the mobile security file leak detection system (10) is composed of a mobile device (100) and a detection server (200).

[0036] The mobile device (100) transmits the operating system type to the detection server (200), and may be connected to the detection server (200) through different methods depending on the operating system type. In addition, the mobile device (100) may receive confirmation of consent to analysis from the detection server (200) and transmit its opinion on consent to analysis to the detection server (200).

[0037] The mobile device (100) may include, but is not necessarily limited to, mobile devices such as a smart phone, a mobile phone, a computer, a laptop, a digital broadcasting terminal, a PDA (Personal Digital Assistant), a PMP (Portable Multimedia Player), and a tablet, and the mobile device (100) may correspond to various devices equipped with a display screen, such as a tablet device, a smart phone, a laptop, a PDA, a wearable device (watch, glasses, etc.), etc.

[0038] The detection server (200) is composed of a communication unit (210), a first operating system unit (220), a second operating system unit (230), and a remote management unit (240).

[0039] The communication unit (210) may receive an operating system type from the mobile device (100). The operating system type may be at least one of a first operating system and a second operating system. The first operating system may be the Android operating system, and the second operating system may be the iOS operating system, but is not necessarily limited thereto. In addition, the communication unit (210) may check whether the Internet network is properly connected and check whether the mobile device (100) consents to analysis.

[0040] The above first operating system unit (220) is composed of a connection module (221), an analysis module (222), an extraction module (223), a management module (224), and a report generation module (225).

[0041] The connection module (221) can load the media file system by connecting to the mobile device (100) according to the operating system received from the mobile device (100) by the communication unit (210), and can obtain device information such as serial number, firmware, and device name. This can be output on the screen and the device information can be stored to perform device management. The connection module (221) can check whether a subdirectory or file in the Internal Storage exists to confirm whether it is connected to the mobile device (100), and can load the total disk capacity and available capacity of the mobile device and calculate the disk capacity being used.

[0042] The connection module (221) can load the media file system from the mobile device (100) through MTP (Media Transfer Protocol) communication when the operating system received from the mobile device (100) by the communication unit (210) is the first operating system. When the user of the mobile device (100) allows the MTP connection, the connection module (221) can read the media file system, and the connection between the detection server (200) and the mobile device (100) can be completed. Since the connection module (221) can read the media file system, it can check the directories and files under the Internal Storage directory, and through this, it can be connected to the device (100) and general analysis can be performed. When the connection module (221) connects to the mobile device (100) through MTP communication, it can provide a convenient and easy-to-use interface to the general user, and the connection task can be conveniently connected because it is not difficult.

[0043] The connection module (221) may have a different connection method depending on the analysis method when the operating system received from the mobile device (100) by the communication unit (210) is the first operating system. In the case of general analysis, an MTP connection confirmation task may be performed, and in the case of detailed analysis, a connection confirmation task may be performed through ADB communication, but is not necessarily limited thereto. The connection module (221) may connect to the mobile device (100) through a command using the ADB (Android Debug Bridge) debugging tool. When the user turns on the developer mode option and allows the debugging mode on the mobile device (100), the connection module (221) may complete the connection between the detection server (200) and the mobile device (100) using the ADB debugging tool. When the connection module (221) connects to the mobile device (100) using the ADB debugging tool, the connection task may take a long time depending on the user's skill level and situation because the connection task involves entering several menus and a user interface.

[0044] The analysis module (222) can set the information of the connected mobile device (100) and the analysis setting time when the connection module (221) completes the connection with the mobile device (100). The analysis setting time may refer to the time set before the start of analysis, and can analyze only the period corresponding to the analysis setting time in the media file system loaded from the mobile device (100). In addition, the analysis module (222) can analyze the media file system to detect whether there is an abnormality during the analysis setting time, and can detect whether there is an abnormality through at least one analysis content among general analysis, detailed analysis, and hidden analysis. The analysis module (222) can generate an analysis result based on the detected abnormality. At this time, the analysis module (222) can check the log regarding the use of the camera and determine that an abnormality has occurred if the use of the camera is found during the analysis setting time. In addition, the analysis module (222) can check whether the creation time and modification time of the directory and file of the mobile device (100) fall within the analysis setting time, and if creation and modification of the directory and file are found during the analysis setting time, it can be determined as an abnormality. In addition, the analysis module (222) can check the log related to the media, analyze the usage pattern, and if creation of media files and behavior different from the pattern are found, it can be determined as an abnormality. In addition, the analysis module (222) can check the DB data related to the media, extract the necessary data, and determine whether there is an abnormality.

[0045] The analysis module (222) can perform general analysis when the operating system received from the mobile device (100) by the communication unit (210) is the first operating system. The general analysis can load the file system of the mobile device via MTP communication and can perform directory file analysis, app-specific directory analysis, and deleted data analysis. First, the analysis module (222) can detect the directory required for analysis for directory file analysis and analyze subdirectories and files. If the modification time of the directory does not fall within the analysis setting time, the subfiles are not analyzed, and only the subdirectories are analyzed, which can improve the speed compared to analyzing all files. If the modification time of all directories does not fall within the analysis setting time, the analysis can be completed quickly with a "no abnormality." If a file is found during the search process, it can be detected as an abnormal file. If no file is found but only a folder is found, the analysis results can be reflected based on the information in the found directory. Second, the analysis module (222) can perform app-specific directory analysis. By default, media files generated using the camera are created under the Camera directory. Third-party camera apps installed from the App Store also create directories and save files under the Camera or Pictures directory. In the case of audio files, they are also saved under different directories depending on the mobile device model and OS version, such as Voice Recorder, Sounds, Recordings, my_sounds, and AudioRecorder. The analysis module (222) can check the package directory of the app installed by the user in the directory of the system area among the directory list of the mobile device (100) and find the media files captured or created in the subdirectory.The analysis module (222) is different for each app, but it can detect and extract media files (thumbnails, cache) deleted from the app's chat room and files created in the app deleted from the gallery. Third, the analysis module (222) can perform deletion data analysis. When a file is deleted and moved to the trash, the modification time of the parent directory of the file changes. In addition, when a file in the trash is deleted, the modification time of the trash directory changes. If the file is not found but the modification time of the trash directory has changed, the analysis module (222) can reflect this deletion and change action as an 'abnormality'.

[0046] The analysis module (222) can perform a detailed analysis when the operating system received from the mobile device (100) by the communication unit (210) is the first operating system. The detailed analysis can be performed through the ADB debugging tool, and can perform file system analysis and log analysis. First, the analysis module (222) can perform a file system analysis. Since the ADB debugging tool enables more authority and a high level of control, the analysis module (222) can check areas other than the file system loaded through MTP communication. Since the directory and file access speed through commands is fast, the file system analysis speed is improved, and the analysis module (222) can detect directories and files with high access rights or hidden. In one embodiment, in Android 11 or lower, the trash area cannot be detected through MTP communication, but it is possible through the ADB debugging tool. Secondly, the analysis module (222) can extract various service logs recorded when a command providing information about system services in the ADB debugging tool creates, modifies, deletes, loads a media file, or calls a media-related service. The various service logs may be at least one of a log collecting information about a user's app usage pattern, a system log related to an audio service, a vibration-related log of a mobile device (100), a log recording statistics and information about a media session, and a status information log related to a system camera service, but are not necessarily limited thereto.

[0047] The analysis module (222) can analyze the above log file to check traces of camera operation in the basic camera, 3rd party app, and SNS app, as well as logs of shooting and transmitting media files.

[0048] The logs that collect information about the user's app usage patterns may record actions related to the use of a single app over a specific period of time, such as taking photos and videos or creating audio files using at least one of the default camera app and a messenger app. The messenger app may be at least one of KakaoTalk, WhatsApp, LINE, Telegram, Instagram, or WeChat, and may include any digital platform that allows for exchanging messages via messenger.

[0049] The above audio service-related system log may record log data along with time information when audio output occurs according to an action, such as when taking a photo or video or creating a recording file using at least one of the default camera app and messenger app.

[0050] The vibration-related log of the mobile device (100) can record data logs regarding vibration occurrence when taking photos and videos or creating recording files using at least one of the default camera app and messenger app. Based on this, the act of taking at least one photo or video can be identified.

[0051] Logs that record statistics and information about the aforementioned media sessions can collect and record details about media playback, codec usage, and audio / video processing. When photos and videos are taken using at least one of the default camera and messenger apps, the generated media information and system resource usage information can be recorded in the log file.

[0052] Status information logs related to the above system camera service can be recorded when the camera device is invoked by at least one of the default camera app and messenger app. The recorded logs can be used to check the currently active camera session, request information, and camera status information.

[0053] The analysis module (222) can generate timeline data based on logs for camera execution and calls. The analysis module (222) can more accurately identify actions for creating media files by combining media files, camera shooting logs, and transmission logs existing in the mobile device (100) based on the timeline. In addition, the analysis module (222) can determine that a deletion action has been performed if a shooting log exists but a file does not exist. The analysis module (222) can perform more detailed analysis by performing a detailed analysis that analyzes the file system and logs in the media file system, which allows for faster data transfer speeds and more complex commands than general analysis.

[0054] The analysis module (222) can perform hidden analysis when the operating system received from the mobile device (100) by the communication unit (210) is the first operating system. Samsung Galaxy mobile devices using the Android operating system provide a secure folder function. Therefore, when the camera is used by utilizing the secure folder function, the shooting history is access-restricted and encrypted, so it cannot be confirmed. Therefore, the analysis module (222) can perform analysis through a separate hidden analysis for Samsung Galaxy mobile devices. The analysis module (222) can extract captured media resource-related files using the media file dump function through the hidden menu and perform DB file analysis, DB log analysis, and security folder analysis. First, the analysis module (222) can check not only the list of media resource-related files but also metadata such as shared ID, longitude, and latitude for DB file analysis. Second, the analysis module (222) can extract Media database-related files for DB log analysis and check the DML-related log added to the media DB. The analysis module (222) can analyze each action by checking the query log related to INSERT, UPDATE, and DELETE. Thirdly, the analysis module (222) can detect a secure folder. Since the secure folder provided by Samsung cannot be accessed with general user privileges, the analysis module (222) can extract a list of media files created or located using the secure folder app.

[0055] The extraction module (223) can determine whether the analysis results generated by the analysis module (222) contain errors, and if no errors are found, extract the analysis results. The extraction module (223) can extract at least one of an original file and a thumbnail file. The original file is used for archiving purposes, and the thumbnail file can be used for addition when generating a result report.

[0056] In the case of MTP communication, the extraction module (223) uses the media device communication library to copy the file to extract the original file. In the case of ADB, the file is copied using a command to copy the file on the device to the PC. The access speed is faster when using ADB than when using MTP communication. When the extraction module (223) extracts the original file, it also includes MD5 and SHA256 hash values ​​to verify the integrity of the original.

[0057] In the case of MTP, the extraction module (223) extracts a loadable thumbnail file using the media device communication library to extract a thumbnail file. In the case of ADB, if the thumbnail file cannot be extracted, the extraction module (223) generates a thumbnail using a library that generates an image by utilizing the original image.

[0058] The management module (224) can delete files that are detected to be abnormal based on the analysis results generated by the analysis module (222). The management module (224) can create a file list of files that have been leaked or are in violation of security based on the analysis results, and delete them from the mobile device (100). When the management module (224) deletes a file, it can select a location to delete from among the local PC from which the file was extracted and the mobile device (100) and delete the file, and a deletion reason can be written for deletion management.

[0059] When deletion is completed in the management module (224), the report generation module (225) can generate a result report based on the analysis result generated by the analysis module (222) and the deletion information of the management module (224). The result report may include at least one of analyzed mobile device information, analyst information, analysis result information, a file list including thumbnails, a deleted file list, camera usage information, and timeline summary information, but is not necessarily limited thereto. The result report generated by the report generation module (225) can be extracted as a PDF file.

[0060] The above second operating system unit (230) is composed of a connection module (231), an analysis module (232), an extraction module (233), a management module (234), and a report generation module (235).

[0061] The connection module (231) can load a media file system by connecting to the mobile device (100) according to the operating system received from the mobile device (100) by the communication unit (210). If the operating system received from the mobile device (100) by the communication unit (210) is a second operating system, the connection module (231) can connect to the mobile device (100) through MTP (Media Transfer Protocol) communication. In addition, the connection module (231) can connect to the mobile device (100) using AFC (Apple File Conduit) to improve the connection speed and access a wide area of ​​media files. The connection module (231) can use liDeviceLib to check whether the mobile device (100) is connected to the detection server (200). If connected, it can have a udid value, which is a unique identification value. In order for the connection module (231) to load the directory and files of the mobile device (100) with AFC, trust permission of the mobile device (100) is required. The connection module (231) verifies the lock settings and activation information of the mobile device (100) and uses the library in charge of control and the library in charge of controlling the mobile device to verify whether the mobile device (100) is in a permitted state, and if so, completes the connection.

[0062] The analysis module (232) can check the analysis setting time when the connection module (231) completes the connection with the mobile device (100). The analysis setting time may refer to a time set before the start of analysis, and can analyze only the period corresponding to the analysis setting time in the media file system loaded from the mobile device (100). In addition, the analysis module (232) can analyze the media file system to detect any abnormality during the analysis setting time, and can detect any abnormality through at least one analysis result of general analysis or detailed analysis. The analysis module (232) can generate an analysis result based on the detected abnormality. At this time, the analysis module (232) can check the log regarding camera usage and determine that an abnormality has occurred if the camera is used during the analysis setting time. In addition, the analysis module (232) can determine that the creation and modification times of the directories and files of the mobile device (100) fall within the analysis setting time, and determine that an abnormality has occurred if the creation and modification of the directories and files are found during the analysis setting time. Additionally, the analysis module (232) can check media-related logs, analyze usage patterns, and determine that abnormalities exist when media file creation and behavior deviate from the patterns. Furthermore, the analysis module (232) can check media-related database data, extract necessary data, and determine whether anomalies exist.

[0063] The analysis module (232) can perform general analysis when the operating system received from the mobile device (100) by the communication unit (210) is a second operating system. The general analysis can obtain a list of media-related files and directories of the mobile device (100) by utilizing AFC, and can perform directory file analysis, app-specific directory analysis, and deleted data analysis. First, the analysis module (232) can select a directory required for analysis in order to analyze a directory file and analyze its subdirectories and files. If the modification time of the directory does not fall within the analysis setting time, the subfiles are not analyzed, and only the information for the corresponding directory is analyzed, which can improve the speed compared to analyzing all files. If the modification times of all directories do not fall within the analysis setting time, the analysis can be quickly completed with 'no abnormality'. In addition, the analysis module (232) can check a file containing at least one of device information and media information prior to directory detection. After that, if there is an abnormality, it can operate like the analysis module (222) above, but unlike the analysis module (222), if an actual photo was not taken, it can output a 'no abnormality' result within 2 seconds. If a file is found during the search process, it can be detected as an abnormal file. If no file is found but only a folder is found, it can be reflected in the analysis result according to the information of the found directory. Second, the analysis module (232) can perform directory analysis for each app. Photo and video files taken with an iOS mobile device are stored in a format with a regular file name and a directory name according to a specific rule under the DCIM directory. In the case of audio files, they are stored under the Recordings directory, and by performing the directory analysis method as above in the Recordings directory, actions of creating, changing, and deleting audio files are set up so that audio files can be analyzed through settings in the agent or web manager.When voice file analysis is activated, the specified directory detection and analysis are performed. Thirdly, the analysis module (232) can perform deleted data analysis. The analysis module (232) can identify media files that the user deleted and moved to the trash through directory analysis. Since image files have file names with specific rules, the data deleted from the trash can can be inferred based on the most recent file before the analysis setting time and the files currently existing in the mobile device. In addition to the DCIM directory where photos are stored, thumbnails or cache data of deleted files may also exist in directories where media files and configuration files are stored. The analysis module (232) can extract the corresponding files and identify temporary files that are files deleted by the user but remain in the mobile device (100).

[0064] The analysis module (232) can perform a detailed analysis when the operating system received from the mobile device (100) by the communication unit (210) is a second operating system. The detailed analysis can be performed by analyzing media resource-related files of an iOS mobile device. Photos and videos of iOS are managed in the photos.sqlite db file. The analysis module (232) can check the generated file list in the table that manages media file information, and extract files belonging to the analysis setting time from the file list to perform analysis. It can be checked in the table where transaction logs of a unit generated in relation to the DB are stored. The analysis module (232) can check deleted file information in the table that stores information on DB data changes. In the table that manages media file information linked to the cloud provided by the second operating system, you can check the list of files uploaded to the cloud connected to the device, and by joining these tables, you can check the deleted file creation time and deletion time with accurate data, rather than inferring the deleted data from the trash based on the most recent files before the analysis setting time and files currently existing in the mobile device, which is the general analysis content created above. In addition, detailed analysis can have more accurate deleted file information than general analysis.

[0065] The extraction module (233) can determine whether there is an error in the analysis result generated by the analysis module (232), and if there is no error, can extract the analysis result. The extraction module (233) can determine whether there is an error in the analysis result based on the result of at least one exception handling among whether the mobile device (100) was disconnected in the middle, whether the file being analyzed is a normal file to be analyzed, and whether the analysis system is operating correctly, but is not necessarily limited thereto. The extraction module (233) can extract at least one of the original file and the thumbnail file. The original file is used for storage purposes, and the thumbnail file can be used for the purpose of being added when generating a result report.

[0066] The extraction module (233) uses AFC to open and copy a file from a mobile device (100) to extract the original file. When the extraction module (233) extracts the original file, it also includes MD5 and SHA256 hash values ​​to verify the integrity of the original.

[0067] The extraction module (233) uses AFC to extract thumbnail files, checks whether the thumbnail matches the original file among the file list storing the thumbnail file, and if the original file exists but the thumbnail does not exist, a thumbnail can be generated based on the original file. If the thumbnail exists but the original file does not exist, the result of whether there is an abnormality can be reflected depending on the directory and analysis content.

[0068] The management module (234) can delete files that are detected to be abnormal based on the analysis results generated by the analysis module (232). The management module (234) can create a file list of files that have been leaked or are in violation of security based on the analysis results, and delete them from the mobile device (100). When the management module (234) deletes a file, it can select the location to be deleted between the local PC and the mobile device (100) and delete it, and a deletion reason can be written for deletion management.

[0069] When deletion is completed in the management module (234), the report generation module (235) can generate a result report based on the analysis result generated by the analysis module (232) and the deletion information of the management module (234). The result report may include at least one of analyzed mobile device information, analyst information, analysis result information, a file list including thumbnails, a deleted file list, camera usage information, and timeline summary information, but is not necessarily limited thereto. The result report generated by the report generation module (235) can be extracted as a PDF file.

[0070] The above remote management unit (240) can create a page (web manager) that can remotely check the contents stored in the communication unit (210), the result reports generated by the first operating system unit (220) and the second operating system unit (230), and other stored contents via the web.

[0071]

[0072] Figures 5 and 6 are screens that allow remote confirmation of analysis content and statistics through a web manager according to an embodiment of the present invention and via a mobile device.

[0073] Referring to Figure 5(a), this is the screen where the agent confirms the list after analysis. For each analyzed case, the detailed view function confirms that the original and thumbnail files for files found to be abnormal have been extracted, files have been deleted, and a results report has been generated.

[0074] Referring to Figure 5(b), this is a screen that confirms that the original file and thumbnail file of the file in which an abnormality was found have been extracted, the file has been deleted, and the result report has been generated.

[0075] Referring to Figure 6, the detection server (200) can check at least one of the following: mobile device diagnostic status, recent work activity, and license status, through the web manager's dashboard. Furthermore, it can manage accounts that can grant administrator and user permissions, and manage at least one of the following: analysis content and analysis result reports. If there are multiple agents, the web manager can customize at least one of the following settings: policy settings, analysis settings, gate settings, and report template settings, to suit the operational status of each agent.

[0076]

[0077] While the invention has been described with reference to the embodiments illustrated in the drawings, these are merely exemplary, and those skilled in the art will appreciate that various modifications and equivalent alternative embodiments are possible. Therefore, the true scope of technical protection of the present invention should be determined by the technical spirit of the appended claims.

Claims

1. In the method for detecting mobile security file leaks, The step where the detection server receives the operating system type from the mobile device; The step where the detection server connects to the mobile device according to the operating system and loads the media file system; A step in which the detection server connected to the mobile device checks the analysis setting time; A step in which the detection server analyzes the media file system to detect any abnormalities; The step where the detection server generates analysis results based on whether there is an abnormality; The detection server checks whether there is an error in the analysis result, and if there is no error, extracts the original file and thumbnail file; A step in which the detection server deletes files that are detected as abnormal based on the analysis results; and The detection server includes a step of generating and storing a result report on the analysis results, The above operating system type is at least one of the first operating system and the second operating system, The step in which the above detection server analyzes the media file system to detect abnormalities is as follows: When the type of operating system input from a mobile device is a first operating system, a step of performing general analysis in which the first operating system unit analyzes directory files, app-specific directories, and deleted data in a media file system; A step in which the first operating system unit performs detailed analysis to analyze the file system and logs in the media file system; A step in which the first operating system performs hidden analysis to analyze DB files, DB logs, and security folders in the media file system; and A method for detecting a mobile security file leak, further comprising detecting anomalies through at least one analysis of general analysis, detailed analysis, and hidden analysis by the first operating system unit.

2. In paragraph 1, The above detection server is characterized in that the criteria for determining whether there is an abnormality are as follows: when the use of a camera is detected during an analysis setting time in a media file system; when the creation and modification of a directory and file are detected during an analysis setting time; when the creation and behavior of a media file different from the pattern is detected by analyzing the usage pattern of a mobile device; and when the presence of an abnormality is determined by extracting necessary data from media-related DB data.

3. In paragraph 1, The step in which the above detection server analyzes the media file system to detect abnormalities is as follows: When the type of operating system input from a mobile device is a second operating system, a step in which the second operating system performs a general analysis to analyze directory files, app-specific directories, and deleted data in the media file system; A step in which the second operating system performs a detailed analysis to analyze media resource files in the media file system; and A method for detecting a mobile security file leak, further comprising detecting whether a second operating system unit detects anomalies through at least one analysis among general analysis and detailed analysis.

4. A mobile device that transmits the operating system type to the detection server and connects to the detection server according to the operating system type; and It includes a detection server that receives the operating system type from a mobile device, connects to the mobile device according to the operating system, loads the media file system, checks the analysis setting time, analyzes the media file system to detect abnormalities, generates analysis results based on the abnormalities, checks if there are errors in the analysis results, extracts the original image and thumbnail image if there are no errors, deletes files detected to be abnormal based on the analysis results, and generates and stores a result report based on the analysis results. When the above detection server analyzes the media file system to detect abnormalities, A mobile security file leak detection system characterized in that, when the type of operating system input from a mobile device is a first operating system, the first operating system performs a general analysis that analyzes directory files, app-specific directories, and deleted data in a media file system, performs a detailed analysis that analyzes file systems and logs in the media file system, and performs a hidden analysis that analyzes DB files, DB logs, and security folders in the media file system, and detects anomalies through at least one analysis result among the general analysis, the detailed analysis, and the hidden analysis.

5. In paragraph 4, The above detection server is a mobile security file leak detection system characterized in that it determines whether there is an abnormality based on the following criteria: when the use of a camera is detected during an analysis setting time in a media file system; when the creation and modification of directories and files are detected during an analysis setting time; when the creation and behavior of media files different from the pattern are detected by analyzing the usage pattern of a mobile device; and when the presence of an abnormality is determined by extracting necessary data from media-related DB data.

Citation Information

Patent Citations

  • Internal data leakage prevention Smartphone operation control security system

    KR101975287B1

  • Security method for protecting the leakage of the information of a company

    KR1020100115451A

  • Integrated security control System and Method for Smartphones

    KR1020130009094A

  • User adaptive method and system for controlling mobile device

    KR1020160097814A

  • Ultrasonic welding condition judging system including vibration measurement sensor and judging method using the same

    KR1020220042684A