Cloud-Based Security Agent for Mobile Malware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional anti-virus programs are ineffective for mobile operating systems due to their closed or 'sandboxed' nature, requiring a new approach for malware detection and removal that does not involve installing security software directly on the device.
Innovation Solution
Implementing a security agent that obtains a list of applications from a centralized repository, compares reputation attributes with a reputation database, and takes action to limit malicious activity without being installed on the device, utilizing existing communication channels or a light application to interact with the user.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional anti-virus programs are installed on mobile devices, then malware detection capability is provided, but the closed/sandboxed nature of mobile operating systems prevents effective operation
Solution Approach 1:
The patent introduces a cloud-based security service as an intermediary between the mobile device and malware detection. Instead of installing traditional anti-virus software on the device, the system uses a remote security server that receives application data from the device, performs analysis, and returns results. This mediator approach bypasses the sandboxing limitations of mobile OSs while maintaining effective malware detection capability.
Solution Approach 2:
The patent transitions the security function from the device dimension (local installation) to the cloud dimension (remote server). By moving malware analysis to a remote environment, the system avoids the constraints of mobile OS sandboxing and performs comprehensive security checks without requiring local software installation on the restricted device.
2Reliability
If security software is installed directly on the device, then local malware protection is achieved, but the need to install additional software on restricted operating systems creates complexity
Solution Approach 1:
The patent extracts the security software component from the device and relocates it to a cloud-based server. The mobile device only retains minimal client functionality for data transmission, while the comprehensive security analysis is performed remotely. This extraction eliminates the need to install and maintain complex security software on restricted operating systems.
Solution Approach 2:
The cloud-based security service provides self-service malware detection and removal capabilities. The system automatically receives application data from the device, analyzes it against malware databases, and executes removal actions without requiring user intervention or local software installation. The service handles security operations autonomously in the cloud environment.
3Reliability
If traditional anti-virus software is used on mobile devices, then security coverage is provided, but the sandboxed environment limits the effectiveness of process monitoring
Solution Approach 1:
The patent uses a cloud-based security server as an intermediary that receives comprehensive application data from the mobile device through standardized APIs. This mediator architecture enables thorough process monitoring and malware detection without requiring direct access to the device's sandboxed environment, overcoming the limitations of local process monitoring on restricted OSs.
Solution Approach 2:
The cloud-based security service provides universal security coverage across different mobile operating systems (iOS, Android, Windows Phone) by using platform-independent communication protocols and standardized data formats. This multi-functional approach enables consistent security monitoring and malware detection across diverse sandboxed environments without requiring OS-specific software installation.
Data Source
AI summary
A method for implementing a security agent on behalf of a device, the method comprising: obtaining a list of applications installed on the device from a remote repository; for each respective application on the list, comparing reputation attributes obtained from a reputation database against attributes of the application installed on the device; and for any of the respective applications for which it is determined from the comparing that the application installed on the device is malicious, taking action to limit malicious activity by the respective application installed on the device.


