Behavioral Analysis System for Mobile Device Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security solutions for mobile and wireless devices are inadequate in identifying and addressing the complex factors contributing to performance degradation and power utilization issues, as they often rely on detecting known viruses and malware, and do not effectively balance performance and security, especially in resource-constrained devices.

Innovation Solution

The implementation of a behavioral monitoring and analysis system that uses user-persona information to dynamically determine relevant device features to monitor, generate behavior vectors, and apply them to classifier models to identify and prevent non-benign device behaviors, such as malicious software, by leveraging machine learning techniques and user-specific classifier models.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive monitoring of device features is implemented to improve security detection accuracy, then security reliability is improved, but device power consumption and processing overhead increase

Engineering Contradiction:
Improvesecurity detection accuracyVSAvoiddevice power consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the security analysis system into multiple components: a behavior monitoring module that collects device features, a user persona generation module that creates behavioral profiles, and a classifier model that evaluates behaviors. This segmentation allows the system to process only relevant features for each user context, reducing overall power consumption while maintaining detection accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adapts the monitoring scope and classification depth based on user persona information. When a user's behavioral pattern is well-established, the system reduces monitoring intensity for known benign behaviors, thereby saving power. The classifier model dynamically adjusts which device features to evaluate based on the specific user context and detected behavior patterns.

Inventive Principle:
Principle #15Dynamics

2Reliability

If comprehensive monitoring of device features is implemented to improve security detection accuracy, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides complex security analysis into manageable segments: device feature collection, user persona generation, behavior vector creation, and classification evaluation. Each segment handles a specific aspect of security analysis, making the overall complex system more manageable and maintainable while improving detection accuracy through specialized processing at each stage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediate data structures and processing layers, including user persona information as an intermediary between raw device features and security decisions. Behavior vectors serve as intermediaries that translate complex device state into standardized formats for classification. These intermediaries simplify the decision-making process by pre-processing and organizing information before final security evaluation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If user-specific classifier models are generated and applied to evaluate device behaviors, then security detection accuracy is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvebehavior classification accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by generating user persona information and establishing baseline behavioral patterns during periods when the device is idle or when users are actively interacting. Pre-computed user profiles and behavior vectors are stored and readily available for rapid classification during security evaluation, reducing real-time processing requirements while maintaining high accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The classifier model dynamically adjusts evaluation parameters based on user persona information. For well-known benign user patterns, the system reduces the number of evaluation criteria and thresholds, speeding up classification. For uncertain or potentially malicious behaviors, the system intensifies evaluation with more parameters. This adaptive parameter adjustment balances accuracy requirements with processing speed.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9703962B2Methods and systems for behavioral analysis of mobile device behaviors based on user persona information
Publication Date: 2017.07.11 QUALCOMM INC
  • US9703962B2 patent drawing
  • US9703962B2 patent drawing
  • US9703962B2 patent drawing

AI summary

A computing device processor may be configured with processor-executable instructions to implement methods of using behavioral analysis and machine learning techniques to identify, prevent, correct, or otherwise respond to malicious or performance-degrading behaviors of the computing device. As part of these operations, the processor may generate user-persona information that characterizes the user based on that user's activities, preferences, age, occupation, habits, moods, emotional states, personality, device usage patterns, etc. The processor may use the user-persona information to dynamically determine the number of device features that are monitored or evaluated in the computing device, to identify the device features that are most relevant to determining whether the device behavior is not consistent with a pattern of ordinary usage of the computing device by the user, and to better identify or respond to non-benign behaviors of the computing device.