Application Security Assessment via Server-Side Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Portable electronic devices lack effective security measures to protect against malware and unauthorized applications, as they lack the processing power for antivirus software and are vulnerable to software piracy and hacking in app marketplaces.

Innovation Solution

A crawler program collects and analyzes applications from various sources, using comparisons and correlations to identify and warn users about pirated or malicious applications, determining legitimacy by measuring similarity between metadata and comparing differences between applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If antivirus software is installed on portable electronic devices, then security protection is improved, but the device lacks sufficient processing power to run such software effectively

Engineering Contradiction:
Improvesecurity protectionVSAvoidprocessing power
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The patent introduces a server as an intermediary that performs the computationally intensive antivirus analysis and application security checks. The portable device sends application data to the server, which then returns security assessments. This mediator approach allows security protection without burdening the device's limited processing power.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical approach of running antivirus software locally on the device with a network-based system where the server performs all security analysis computations. This substitution moves the computational burden from the device's CPU to the server's processing resources.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If application marketplaces allow third-party applications, then application variety and user choice are improved, but vulnerability to malware and unauthorized applications increases

Engineering Contradiction:
Improveapplication varietyVSAvoidmalware vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security assessment of applications before they are made available to users. The server analyzes applications upfront, creating security profiles and assessments that are stored and used to protect users from malware before they can be installed on devices.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors and updates security assessments based on new threat intelligence and user reports. When new malware patterns are detected, the server updates its security databases and reassesses applications, providing ongoing feedback to maintain security while preserving application variety.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If application comparison and analysis are performed to detect pirated applications, then security detection accuracy is improved, but the complexity of the system increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates digital copies and hashes of legitimate applications to use as reference standards for comparison. By generating fingerprint templates from authorized applications, the system can accurately detect pirated or modified versions through pattern matching without requiring complex analysis algorithms on the device.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9563749B2Comparing applications and assessing differences
Publication Date: 2017.02.07 LOOKOUT INC
  • US9563749B2 patent drawing
  • US9563749B2 patent drawing
  • US9563749B2 patent drawing

AI summary

An analysis including a comparison is performed of first and second applications and a determination is made regarding whether the first is a counterfeit version of the second application, or vice-versa. Based on the analysis and comparison, and based on an assessment of the first application, an assessment of the second application may be generated.