Cloud Threat Analysis Platform for Mobile Vulnerability Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices are vulnerable to malicious attacks due to low data security, use of public Wi-Fi networks, outdated operating systems, and installation of unverified applications, leading to difficulties in detecting and preventing such threats effectively.

Innovation Solution

A threat analysis cloud platform that monitors mobile applications, identifies vulnerabilities, and generates a security tool user interface to provide risk assessment scores and recommendations for improving security, including automatic response actions to mitigate future attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If automated threat detection and monitoring is implemented for mobile applications, then security vulnerability identification and response capability are improved, but device complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity vulnerability identification capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud-based threat analysis platform as an intermediary between mobile applications and security analysis resources. The platform receives data from mobile devices, performs complex vulnerability analysis in the cloud, and returns results to users. This mediator approach allows sophisticated security analysis without burdening individual mobile devices with complex local analysis tools.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables mobile applications to automatically report security events and receive vulnerability assessments without requiring manual security analysis. The automated workflow where applications self-report issues and receive automatic analysis results reduces the need for manual security intervention while maintaining high security monitoring capability.

Inventive Principle:
Principle #25Self-service

2Speed

If real-time monitoring of user devices is performed to detect malicious attacks, then threat detection speed is improved, but computing resource utilization increases

Engineering Contradiction:
Improvethreat detection speedVSAvoidcomputing resource utilization
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The system implements periodic sampling and event-triggered monitoring rather than continuous real-time analysis. Security events are monitored and analyzed at appropriate intervals or when specific triggers occur, allowing the system to maintain fast threat detection capability while avoiding constant resource-intensive processing during normal operation.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent extracts computationally intensive security analysis functions from mobile devices and relocates them to cloud-based processing infrastructure. Mobile devices only need to collect and transmit security event data, while the heavy lifting of vulnerability analysis and threat assessment is performed remotely in the cloud, significantly reducing on-device resource consumption.

Inventive Principle:
Principle #2Taking out (Extraction)

3Measurement precision

If comprehensive security analysis is performed on mobile applications, then vulnerability identification accuracy is improved, but analysis time and user wait time increase

Engineering Contradiction:
Improvevulnerability identification accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary security analysis and establishes baseline vulnerability profiles for mobile applications before they are deployed or during off-peak periods. Pre-computed security metrics and pre-established threat intelligence data are cached and readily available, enabling fast accurate vulnerability assessment when security events occur without requiring time-consuming real-time analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies different levels of analysis intensity to different security contexts. Common or low-risk security events receive faster, less intensive analysis, while suspicious or high-risk events trigger comprehensive deep-dive analysis. This differentiated approach ensures high accuracy for critical threats while maintaining quick response for routine security monitoring.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10496826B2Device based automated threat detection and response
Publication Date: 2019.12.03 ACCENTURE GLOBAL SOLUTIONS LTD
  • US10496826B2 patent drawing
  • US10496826B2 patent drawing
  • US10496826B2 patent drawing

AI summary

A device may include one or more processors. The device may communicate with a set of user devices operating a set of mobile applications to obtain data regarding a set of malicious attacks associated with the set of user devices. The device may store the data regarding the set of malicious attacks via a data structure for analysis. The device may process the stored data to identify one or more vulnerabilities associated with the set of user devices or the set of mobile applications. The device may generate a security tool user interface that includes information identifying the one or more vulnerabilities associated with the set of user devices or the set of mobile applications. The device may cause the security tool user interface to be provided for display via a client device based on generating the security tool user interface.