Cloud-Based Security Agent for Mobile Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional anti-virus programs are ineffective for mobile operating systems due to their closed or 'sandboxed' nature, requiring a new approach for malware detection and removal that does not involve installing security software directly on the device.

Innovation Solution

Implementing a security agent that obtains a list of applications from a centralized repository, compares reputation attributes with a reputation database, and takes action to limit malicious activity without being installed on the device, utilizing existing communication channels or a light application to interact with the user.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional anti-virus programs are installed on mobile devices, then malware detection capability is provided, but the closed/sandboxed nature of mobile operating systems prevents effective operation

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidcompatibility with mobile OS sandboxing
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a cloud-based security service as an intermediary between the mobile device and malware detection. Instead of installing traditional anti-virus software on the device, the system uses a remote security server that receives application data from the device, performs analysis, and returns results. This mediator approach bypasses the sandboxing limitations of mobile OSs while maintaining effective malware detection capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transitions the security function from the device dimension (local installation) to the cloud dimension (remote server). By moving malware analysis to a remote environment, the system avoids the constraints of mobile OS sandboxing and performs comprehensive security checks without requiring local software installation on the restricted device.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If security software is installed directly on the device, then local malware protection is achieved, but the need to install additional software on restricted operating systems creates complexity

Engineering Contradiction:
Improvelocal malware protectionVSAvoidsoftware installation requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security software component from the device and relocates it to a cloud-based server. The mobile device only retains minimal client functionality for data transmission, while the comprehensive security analysis is performed remotely. This extraction eliminates the need to install and maintain complex security software on restricted operating systems.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The cloud-based security service provides self-service malware detection and removal capabilities. The system automatically receives application data from the device, analyzes it against malware databases, and executes removal actions without requiring user intervention or local software installation. The service handles security operations autonomously in the cloud environment.

Inventive Principle:
Principle #25Self-service

3Reliability

If traditional anti-virus software is used on mobile devices, then security coverage is provided, but the sandboxed environment limits the effectiveness of process monitoring

Engineering Contradiction:
Improvesecurity coverageVSAvoidprocess monitoring effectiveness
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent uses a cloud-based security server as an intermediary that receives comprehensive application data from the mobile device through standardized APIs. This mediator architecture enables thorough process monitoring and malware detection without requiring direct access to the device's sandboxed environment, overcoming the limitations of local process monitoring on restricted OSs.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The cloud-based security service provides universal security coverage across different mobile operating systems (iOS, Android, Windows Phone) by using platform-independent communication protocols and standardized data formats. This multi-functional approach enables consistent security monitoring and malware detection across diverse sandboxed environments without requiring OS-specific software installation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8918888B2Agent based application reputation system for operating systems
Publication Date: 2014.12.23 WITHSECURE CORP (A K A WITHSECURE OYJ)
  • US8918888B2 patent drawing
  • US8918888B2 patent drawing
  • US8918888B2 patent drawing

AI summary

A method for implementing a security agent on behalf of a device, the method comprising: obtaining a list of applications installed on the device from a remote repository; for each respective application on the list, comparing reputation attributes obtained from a reputation database against attributes of the application installed on the device; and for any of the respective applications for which it is determined from the comparing that the application installed on the device is malicious, taking action to limit malicious activity by the respective application installed on the device.