Device-Specific Security Model for Application Risk Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The dynamic and time-variant nature of communication device data, including changes in installed applications and data formats, complicates the creation of universal risk models, making it difficult to effectively determine the security of applications on these devices.
Innovation Solution
A communication device collects metadata associated with an application, embeds it into vectorized data, and inputs this data into a machine learning model obtained from a server computer to determine a security value, deciding whether to run or install the application based on this value.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a universal risk model is created based on device information, then security assessment capability is improved, but the model becomes increasingly difficult to maintain due to diverse communication devices and dynamic data changes
Solution Approach 1:
The system segments the universal risk model into device-specific models. Each communication device receives a customized risk model tailored to its specific device type, operating system, and data formats. This segmentation approach maintains security assessment capability for each device while avoiding the complexity of maintaining a single universal model that must accommodate all device variations.
Solution Approach 2:
The system implements dynamic model adaptation where risk models are automatically updated and adjusted based on changing device data, installed applications, and emerging security threats. The model evolves over time to maintain effectiveness without requiring manual intervention for each change, thus improving reliability while managing complexity through automation.
2Measurement precision
If real-time security assessment is performed on each application, then security detection accuracy is improved, but processing time and computational resources increase
Solution Approach 1:
The system performs preliminary security assessment by analyzing application metadata, permissions, and characteristics before the application is fully installed or executed. This preliminary action identifies potential security risks early in the process, allowing for faster decision-making and reducing the time required for complete security verification while maintaining detection accuracy.
Solution Approach 2:
The system uses lightweight, disposable security assessment models that are computationally efficient and can be quickly executed. These simplified models provide adequate security detection for common scenarios without requiring heavy computational resources, thus reducing processing time while maintaining sufficient accuracy for most security threats.
Data Source
AI summary
A method includes receiving, by a server computer, data of a communication device; training, by the server computer, a neural network model based on the data of the communication device and communication device metadata from one or more additional communication devices, to generate a machine learning model configured to determine, based on a metadata associated with an application, a security value related to an indication of a security threat; and transmitting the machine learning model to the communication device. The communication device can use the machine learning model to determine the security value, by inputting the metadata associated with the application, as a vectorized data into the machine learning model. The communication device can determine whether to run or install the application based upon the security value.


