On-Device Adaptive Security Using Threat Intelligence

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security solutions for client computing devices, such as mobile and wireless devices, are inadequate in protecting against new and emerging threats due to their reliance on periodic software updates and patches, which are often delayed and can introduce new vulnerabilities, leaving devices vulnerable to hackers and malware.

Innovation Solution

A method where client computing devices collaborate with server devices to quickly identify and respond to emerging threats by receiving threat profiles, analyzing device behavior, and implementing customized security measures before permanent solutions are available, using on-device security systems to devise and implement responses based on threat scores and vulnerability assessments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security solutions rely on periodic software updates and patches, then security maintenance is simplified, but response time to new threats increases and devices remain vulnerable longer

Engineering Contradiction:
Improvesecurity protectionVSAvoidresponse time to threats
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary security actions by deploying emergency security responses before permanent patches are available. When a vulnerability is detected, the system immediately implements temporary mitigations (such as disabling vulnerable components or applying workarounds) to protect against exploitation, rather than waiting for the official vendor patch. This preliminary protective action bridges the critical time gap between vulnerability discovery and permanent resolution.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary layer between the vulnerability and the device's security response. The emergency security response acts as a mediator that translates the raw vulnerability information into actionable protective measures. This intermediary component enables rapid response by pre-processing vulnerability data and generating appropriate countermeasures before the full security update is ready.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If client devices implement customized security responses based on threat profiles, then security adaptability improves, but device complexity increases

Engineering Contradiction:
Improvesecurity response customizationVSAvoidsecurity system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The security system is segmented into distinct functional modules: threat intelligence collection, vulnerability assessment, emergency response generation, and security patch management. Each module operates independently and handles a specific aspect of security. This segmentation allows the system to achieve high adaptability through modular customization without overwhelming complexity, as each module can be optimized and managed separately.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes parameters of existing security components rather than creating entirely new systems. By adjusting parameters such as detection thresholds, response timing, and mitigation strategies based on threat profiles, the system achieves customized security responses. This parameter-based approach maintains simplicity while enabling adaptability, as modifications are made to existing structures rather than building complex new architectures.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If emergency security responses are deployed before patches are available, then threat protection improves, but potential for introducing new vulnerabilities increases

Engineering Contradiction:
Improvethreat protectionVSAvoidnew vulnerabilities introduced
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system implements feedback mechanisms that continuously monitor the effectiveness of emergency security responses and the device's overall security state. After deploying a temporary mitigation, the system observes whether the vulnerability is successfully closed off and whether the response introduces any unintended consequences. This feedback loop allows the system to adjust or revoke emergency responses if they prove harmful, thereby reducing the risk of introducing new vulnerabilities while maintaining protection.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system applies beforehand cushioning by implementing conservative emergency responses that prioritize safety over functionality. When deploying temporary mitigations, the system uses precautionary measures that may limit device functionality but ensure protection against known threats. This cushioning approach creates a safety buffer that prevents over-aggressive responses from introducing new vulnerabilities, while still providing adequate protection during the transition period before permanent patches are applied.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS10333965B2Methods and systems for on-device real-time adaptive security based on external threat intelligence inputs
Publication Date: 2019.06.25 QUALCOMM INC
  • US10333965B2 patent drawing
  • US10333965B2 patent drawing
  • US10333965B2 patent drawing

AI summary

Methods, and computing devices implementing the methods, that enable client computing devises to work in conjunction with a server device to identify and temporarily defend against non-benign applications (e.g., malware, etc.) and other threats before a more permanent solution or defense (e.g., a patch or software upgrade) becomes available and installed on the client computing device. The server device may be configured to receive reports from the client computing devices, receive threat feeds from third-party servers (e.g., threat intelligence servers, etc.), and use information included in the received threat feed and information included in the received reports to analyze, in the server computing device, a software application that is operating on a client device in multiple passes. The server may generate threat scores (e.g., one for each pass, etc.), and the threat scores to the client computing device for use in devising a customized security response.