Cloud-Based ML Detection of Malicious Mobile Applications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing machine learning tools for detecting malicious mobile applications lack real-time training data from user traffic, leading to ineffective detection and security vulnerabilities in Bring Your Own Device (BYOD) scenarios.

Innovation Solution

A cloud-based system with traffic forwarding and machine learning model architecture that trains in real-time using vast amounts of mobile app data from multiple users, enabling zero-hour protection and quick detection of new malicious apps.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing ML tools use static and/or dynamic analysis to detect malicious apps, then detection capability is provided, but detection accuracy is insufficient due to lack of real user traffic for training

Engineering Contradiction:
Improvedetection accuracyVSAvoidtraining data effectiveness
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent transitions from traditional static/dynamic analysis in isolation to a cloud-based architecture that aggregates mobile traffic data across multiple dimensions (multiple users, multiple devices, multiple app instances) to train ML models, thereby improving detection accuracy through multi-dimensional real-world traffic patterns

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The cloud-based system serves multiple functions: it acts as both a traffic forwarding proxy and an ML training platform simultaneously. The same infrastructure that routes user traffic also captures and utilizes that traffic for model training, creating a multi-functional system that addresses both detection and training data needs

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If traditional IT security controls are enforced on corporate PCs, then security policy compliance is achieved, but BYOD scenario security enforcement is not viable due to device ownership and usage complexity

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidBYOD scenario compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a cloud-based proxy as an intermediary between users and applications. This intermediary captures mobile traffic, forwards it appropriately, and enables security analysis without requiring direct control of user devices, thus bridging the gap between security enforcement needs and BYOD usage freedom

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements continuous feedback loops where mobile traffic data is captured, used to train ML models, and the improved models subsequently enhance detection capabilities. This feedback mechanism allows the system to adapt and improve security enforcement over time without disrupting user workflows

Inventive Principle:
Principle #23Feedback

3Productivity

If ML models are trained without real user traffic, then training can proceed with available data, but training effectiveness is reduced leading to ineffective detection

Engineering Contradiction:
Improvetraining speedVSAvoiddetection accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system enables continuous ML model training by continuously capturing real user mobile traffic through the cloud-based proxy. Rather than periodic batch training with static datasets, the system maintains continuous data collection and model improvement, ensuring the ML models remain effective against evolving threats

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS12445459B2Detecting malicious mobile applications using machine learning in a cloud-based system
Publication Date: 2025.10.14 ZSCALER INC
  • US12445459B2 patent drawing
  • US12445459B2 patent drawing
  • US12445459B2 patent drawing

AI summary

Systems and methods for detecting malicious mobile applications using machine learning in a cloud-based system utilize a traffic forwarding technique and a cloud-based Machine Learning (ML) model to assess the security of apps installed on a user device. This architecture enables the cloud-based system to have visibility of user devices, train the ML model in real-time with a vast amount of mobile app data from multiple users, and enforce security on the user devices from the cloud-based system. Advantageously, the ML model is trained with a vast amount of mobile traffic, leading to better accuracy of prediction. The cloud-based system can be multi-tenant (enterprise), have a large user base, be spread over a large geographic area, etc. This provides a great opportunity for training data. Feedback from live production data can be fed back into the ML model.