Behavior-Based Security System for Mobile Device Malware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile devices are increasingly vulnerable to malware and cyber attacks due to their role in storing sensitive information and executing complex applications, with existing security solutions failing to adequately protect resource-constrained computing devices from performance degradation and power utilization issues.
Innovation Solution
A behavior-based security system that uses machine learning and behavioral analysis techniques to identify and prevent non-benign behaviors by generating artificial attack software to simulate cyber attacks and assess the security system's response, with a dead-man signal sent if the system fails to respond adequately, allowing for corrective actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing security solutions are implemented on mobile devices, then security protection is provided, but processing resources and energy are excessively consumed
Solution Approach 1:
The patent replaces traditional signature-based malware detection (mechanical scanning approach) with behavior-based detection using machine learning classifiers. The system monitors application behaviors and uses trained classifiers to identify malicious patterns, significantly reducing processing overhead and energy consumption while maintaining security effectiveness.
Solution Approach 2:
The system enables mobile devices to autonomously detect and respond to malware threats using locally deployed machine learning classifiers. The device self-monitors its own behavior patterns and security state without requiring constant cloud connectivity or resource-intensive external scanning, allowing security operations to occur efficiently on-device.
2Reliability
If traditional malware detection methods are used, then malware identification is achieved, but device performance degrades due to resource-intensive scanning
Solution Approach 1:
The patent substitutes resource-intensive signature matching and full-file scanning with lightweight behavior monitoring and machine learning classification. By analyzing behavioral patterns rather than scanning entire binaries, the system maintains high malware detection accuracy while preserving device performance and user experience.
Solution Approach 2:
Instead of performing complete malware scans of all applications, the system selectively monitors specific behaviors and applies classifiers only to suspicious patterns. This partial action approach focuses computational resources on high-risk areas, achieving effective malware identification without overall performance degradation.
3Reliability
If comprehensive security monitoring is implemented, then threat detection capability is improved, but power utilization increases excessively
Solution Approach 1:
The patent replaces continuous active scanning with passive behavior monitoring and event-triggered classification. The system listens for specific security-relevant events and applies machine learning classifiers only when triggered, dramatically reducing power utilization while maintaining comprehensive threat detection capability.
Solution Approach 2:
The system implements periodic behavior sampling rather than continuous monitoring, collecting security-relevant data at intervals and applying classifiers periodically. This approach maintains threat detection effectiveness while reducing power consumption by keeping the system in low-power states between monitoring cycles.
Data Source
AI summary
A behavior-based security system of a computing device may be protected from non-benign behavior, malware, and cyber attacks by configuring the device to work in conjunction with another component (e.g., a server) to monitor the accuracy and performance of the security system, and determine whether the system is working correctly, efficiently, or as expected. This may be accomplished via the server generating artificial attack software, sending the generated artificial attack software to the mobile device to simulate non-benign behavior in the mobile device, such as a cyber attack, and determining whether the behavior-based security system of the mobile device responded adequately to the simulated non-benign behavior. The sever may send a dead-man signal to the mobile device in response to determining that the behavior-based security system of the mobile device did not respond adequately to the simulated non-benign behavior.


