Application Cooperation Control via Access History Map
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional techniques fail to detect unauthorized cooperation among applications on user terminals without updating fixed rule files or threshold information, making it impossible to prevent sensitive information leakage unless new information is obtained from a server.
Innovation Solution
An information processing apparatus with a network control unit, installation control unit, process control unit, access-history map updating unit, and unauthorized-cooperation control unit that uses an access-history map and application authorizing list to detect and prevent unauthorized cooperation by controlling application execution, eliminating the need for server updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If fixed unauthorized rule files or threshold information are used for malware detection, then the detection system is simple to implement, but it cannot detect unauthorized cooperation among newly installed applications without server updates
Solution Approach 1:
The system performs preliminary actions by building an access history map and application authorizing list during normal operation, storing access relationships and authority information before unauthorized cooperation occurs. This preliminary data collection enables immediate detection of unauthorized cooperation among newly installed applications without requiring server updates or fixed rule files.
Solution Approach 2:
The patent introduces an intermediary mechanism (access history map and application authorizing list) that mediates between the application layer and the detection logic. This intermediary structure captures and stores access relationships independently, allowing the system to detect unauthorized cooperation by comparing actual access patterns against stored authority information, rather than relying on fixed rules or continuous server communication.
2Reliability
If the system continuously updates rule files from a server to detect new malware, then detection accuracy improves, but the system loses autonomy and requires constant network connectivity
Solution Approach 1:
The system practices self-service by autonomously building and maintaining its own detection databases (access history map and application authorizing list) from observed application behavior and manifest information. This self-service capability enables the system to detect unauthorized cooperation among newly installed applications independently, without requiring continuous server updates or network connectivity, thus maintaining both detection accuracy and system autonomy.
3Reliability
If the system monitors all application access relationships in real-time, then unauthorized cooperation is detected immediately, but the processing overhead and system resource consumption increase
Solution Approach 1:
The system performs preliminary action by pre-building the access history map and application authorizing list during normal operation, storing access relationships and authority information as applications are installed and executed. This preliminary data collection enables immediate detection of unauthorized cooperation by simple comparison against stored data, rather than requiring complex real-time analysis, thus achieving timely detection with minimal processing overhead.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An information processing terminal (40) includes: a network control unit (250); an installation control unit (260); a process control unit (200) for starting up an application and establishing cooperation among applications including the application; an access-history map updating unit (290) for updating an access-history map (281) which represents history information on an access relationship among the applications when a request is made to start up the application or to establish cooperation among the applications; and an unauthorized-cooperation-of-applications control unit (220) for (i) determining whether or not an unauthorized cooperation, which is directed at sensitive information kept secret, is established among the applications with reference to information obtained from the access-history map (281) and an application authorizing list (271), and (ii) controlling execution of the application using an application execution control technique in the case where a result of the determination shows that the unauthorized cooperation is established.