Cloud Sandbox for Mobile App Malicious Content Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices with low processing power are vulnerable to malicious content due to their inability to employ the same antivirus techniques as desktop computers, exacerbated by the ease of downloading mobile applications and the proliferation of unsecure app stores.

Innovation Solution

A method and system that utilize a cloud-based virtual machine sandbox to inspect mobile applications for malicious content, where the application is executed and monitored in a simulated environment, isolating the cloud system from potential threats and allowing for detection of malicious behavior without overburdening the mobile device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If mobile devices use traditional antivirus techniques on-device, then security detection capability is improved, but device processing power and resources are insufficient to support it

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoiddevice processing power
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The patent introduces a cloud-based sandbox environment as an intermediary between the mobile device and the antivirus inspection process. The mobile application is transmitted to a remote server where it executes in an isolated sandbox environment, allowing comprehensive security analysis without consuming the mobile device's limited processing resources. The inspection results are then returned to the mobile device, resolving the contradiction between needing strong detection capabilities and having limited device power.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If mobile devices download and install applications directly, then ease of access to applications is improved, but exposure to malicious content increases

Engineering Contradiction:
Improveapplication download accessibilityVSAvoidmalicious content exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security inspection of mobile applications in a cloud-based sandbox environment before they are installed and executed on the mobile device. The application is first transmitted to a remote server, executed in an isolated sandbox, and thoroughly inspected for malicious behavior. Only after successful inspection does the application proceed to installation on the mobile device, thereby maintaining ease of access while preventing malicious content exposure.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If comprehensive antivirus inspection is performed, then detection accuracy is improved, but inspection time and system resources increase

Engineering Contradiction:
Improvemalicious content detection accuracyVSAvoidinspection time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent creates a virtual copy of the mobile application and executes it in a cloud-based sandbox environment for comprehensive security inspection. Instead of performing resource-intensive analysis directly on the mobile device, the system copies the application to a remote server where it can be thoroughly analyzed in an isolated environment. This approach enables high detection accuracy while the inspection time is efficiently managed through parallel processing and optimized cloud infrastructure.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8966632B1In-the-cloud sandbox for inspecting mobile applications for malicious content
Publication Date: 2015.02.24 TREND MICRO INC
  • US8966632B1 patent drawing
  • US8966632B1 patent drawing
  • US8966632B1 patent drawing

AI summary

A low resource mobile device, such as a smart phone or a tablet running a mobile operating system, requests a cloud computer system to inspect a mobile application for malicious content. The cloud computer system downloads the mobile application from a mobile application source, and installs the mobile application in a virtual machine sandbox. The cloud computer system inspects the mobile application for malicious content while the mobile application executes in the virtual machines sandbox. The result of the inspection is sent to the user in accordance with a setting that may be indicated in a cloud sandbox agent running on the mobile device.