Inter-personal Attack Application Detection via Feature and Graph Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Inter-personal attack applications, such as stalkerware and spyware, are difficult to detect and can be used for malicious surveillance and harassment, posing a significant threat to user privacy and security, as they often have legitimate uses but can be misused by non-expert users.

Innovation Solution

A system and method that utilizes natural language processing and machine learning to create feature vectors and profiling vectors from application information, combining them with bi-partite graph information to identify potentially malicious functionalities and determine the extent of maliciousness, enabling detection and warning users of suspicious applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If inter-personal attack applications are designed with legitimate functionalities, then the applications can be used for lawful purposes such as child safety and family locating, but the applications become difficult to detect and may be misused for malicious surveillance and harassment

Engineering Contradiction:
Improvelegitimate use capabilityVSAvoiddetection difficulty
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary analysis of application features, installation information, and behavioral patterns before the application can cause harm. By pre-establishing detection models and analyzing applications during installation or initial execution, the system identifies malicious intent before legitimate functionalities are compromised for surveillance purposes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary detection system that acts as a mediator between the application and the user device. This intermediary analyzes application behaviors, monitors system calls, and intercepts suspicious activities without requiring direct access to the application's core functionalities, thereby detecting malicious use while allowing legitimate operations to proceed.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive analysis methods are used to detect malicious applications, then detection accuracy improves, but the complexity of the detection system increases

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The detection system is segmented into multiple independent modules, each responsible for analyzing specific aspects of applications such as feature analysis, installation information processing, behavioral monitoring, and machine learning classification. This modular approach maintains high detection accuracy while managing system complexity through division of labor.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal detection framework that handles multiple types of applications and malicious behaviors through a single integrated system. The machine learning model and analysis engine are designed to be multi-functional, capable of detecting various categories of malware including inter-personal attack applications, spyware, and stalkerware using the same core infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11556653B1Systems and methods for detecting inter-personal attack applications
Publication Date: 2023.01.17 GEN DIGITAL INC
  • US11556653B1 patent drawing
  • US11556653B1 patent drawing
  • US11556653B1 patent drawing

AI summary

The disclosed computer-implemented method for detecting inter-personal attack applications may include (i) receiving application marketplace information describing application feature information, (ii) creating, by performing natural language processing on the feature information, a feature vector identifying a potentially malicious functionality of the application, (iii) creating a profiling vector that is a categorical feature representation of installation information from an application installation file, and (iv) performing a security action including (A) mapping, using a machine learning model, the feature vector and the profiling vector to a multi-dimensional output vector having element corresponding to a malware category and (B) determining a malicious extent of the application by combining the categories identified by the multi-dimensional output vector with bi-partite graph information identifying (I) relations between a plurality of applications and (II) relations between a plurality of computing devices hosting the plurality of applications. Various other methods, systems, and computer-readable media are also disclosed.