Inter-personal Attack Application Detection via Feature and Graph Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Inter-personal attack applications, such as stalkerware and spyware, are difficult to detect and can be used for malicious surveillance and harassment, posing a significant threat to user privacy and security, as they often have legitimate uses but can be misused by non-expert users.
Innovation Solution
A system and method that utilizes natural language processing and machine learning to create feature vectors and profiling vectors from application information, combining them with bi-partite graph information to identify potentially malicious functionalities and determine the extent of maliciousness, enabling detection and warning users of suspicious applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If inter-personal attack applications are designed with legitimate functionalities, then the applications can be used for lawful purposes such as child safety and family locating, but the applications become difficult to detect and may be misused for malicious surveillance and harassment
Solution Approach 1:
The system performs preliminary analysis of application features, installation information, and behavioral patterns before the application can cause harm. By pre-establishing detection models and analyzing applications during installation or initial execution, the system identifies malicious intent before legitimate functionalities are compromised for surveillance purposes.
Solution Approach 2:
The patent introduces an intermediary detection system that acts as a mediator between the application and the user device. This intermediary analyzes application behaviors, monitors system calls, and intercepts suspicious activities without requiring direct access to the application's core functionalities, thereby detecting malicious use while allowing legitimate operations to proceed.
2Measurement precision
If comprehensive analysis methods are used to detect malicious applications, then detection accuracy improves, but the complexity of the detection system increases
Solution Approach 1:
The detection system is segmented into multiple independent modules, each responsible for analyzing specific aspects of applications such as feature analysis, installation information processing, behavioral monitoring, and machine learning classification. This modular approach maintains high detection accuracy while managing system complexity through division of labor.
Solution Approach 2:
The patent creates a universal detection framework that handles multiple types of applications and malicious behaviors through a single integrated system. The machine learning model and analysis engine are designed to be multi-functional, capable of detecting various categories of malware including inter-personal attack applications, spyware, and stalkerware using the same core infrastructure.
Data Source
AI summary
The disclosed computer-implemented method for detecting inter-personal attack applications may include (i) receiving application marketplace information describing application feature information, (ii) creating, by performing natural language processing on the feature information, a feature vector identifying a potentially malicious functionality of the application, (iii) creating a profiling vector that is a categorical feature representation of installation information from an application installation file, and (iv) performing a security action including (A) mapping, using a machine learning model, the feature vector and the profiling vector to a multi-dimensional output vector having element corresponding to a malware category and (B) determining a malicious extent of the application by combining the categories identified by the multi-dimensional output vector with bi-partite graph information identifying (I) relations between a plurality of applications and (II) relations between a plurality of computing devices hosting the plurality of applications. Various other methods, systems, and computer-readable media are also disclosed.


