Behavior-Based Security System for Mobile Device Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices are increasingly vulnerable to malware and cyber attacks due to their role in storing sensitive information and executing complex applications, with existing security solutions failing to adequately protect resource-constrained computing devices from performance degradation and power utilization issues.

Innovation Solution

A behavior-based security system that uses machine learning and behavioral analysis techniques to identify and prevent non-benign behaviors by generating artificial attack software to simulate cyber attacks and assess the security system's response, with a dead-man signal sent if the system fails to respond adequately, allowing for corrective actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security solutions are implemented on mobile devices, then security protection is provided, but processing resources and energy are excessively consumed

Engineering Contradiction:
Improvesecurity protectionVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent replaces traditional signature-based malware detection (mechanical scanning approach) with behavior-based detection using machine learning classifiers. The system monitors application behaviors and uses trained classifiers to identify malicious patterns, significantly reducing processing overhead and energy consumption while maintaining security effectiveness.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables mobile devices to autonomously detect and respond to malware threats using locally deployed machine learning classifiers. The device self-monitors its own behavior patterns and security state without requiring constant cloud connectivity or resource-intensive external scanning, allowing security operations to occur efficiently on-device.

Inventive Principle:
Principle #25Self-service

2Reliability

If traditional malware detection methods are used, then malware identification is achieved, but device performance degrades due to resource-intensive scanning

Engineering Contradiction:
Improvemalware identification accuracyVSAvoiddevice performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent substitutes resource-intensive signature matching and full-file scanning with lightweight behavior monitoring and machine learning classification. By analyzing behavioral patterns rather than scanning entire binaries, the system maintains high malware detection accuracy while preserving device performance and user experience.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

Instead of performing complete malware scans of all applications, the system selectively monitors specific behaviors and applies classifiers only to suspicious patterns. This partial action approach focuses computational resources on high-risk areas, achieving effective malware identification without overall performance degradation.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If comprehensive security monitoring is implemented, then threat detection capability is improved, but power utilization increases excessively

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidpower utilization
Core Design Contradiction:
ReliabilityVSUse of energy by stationary object

Solution Approach 1:

The patent replaces continuous active scanning with passive behavior monitoring and event-triggered classification. The system listens for specific security-relevant events and applies machine learning classifiers only when triggered, dramatically reducing power utilization while maintaining comprehensive threat detection capability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system implements periodic behavior sampling rather than continuous monitoring, collecting security-relevant data at intervals and applying classifiers periodically. This approach maintains threat detection effectiveness while reducing power consumption by keeping the system in low-power states between monitoring cycles.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS9357397B2Methods and systems for detecting malware and attacks that target behavioral security mechanisms of a mobile device
Publication Date: 2016.05.31 QUALCOMM INC
  • US9357397B2 patent drawing
  • US9357397B2 patent drawing
  • US9357397B2 patent drawing

AI summary

A behavior-based security system of a computing device may be protected from non-benign behavior, malware, and cyber attacks by configuring the device to work in conjunction with another component (e.g., a server) to monitor the accuracy and performance of the security system, and determine whether the system is working correctly, efficiently, or as expected. This may be accomplished via the server generating artificial attack software, sending the generated artificial attack software to the mobile device to simulate non-benign behavior in the mobile device, such as a cyber attack, and determining whether the behavior-based security system of the mobile device responded adequately to the simulated non-benign behavior. The sever may send a dead-man signal to the mobile device in response to determining that the behavior-based security system of the mobile device did not respond adequately to the simulated non-benign behavior.