Malware Risk Assessment for Mobile Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anti-malware detection methods, relying on signature-based scanners and Mobile Device Management (MDM) systems, are inadequate for timely identification of malware-infected mobile devices, especially for external users, leading to potential data breaches and rapid malware propagation.

Innovation Solution

A computer-implemented method that assesses malware risk data to identify at-risk mobile devices and their connections, using weighted parameters such as application riskiness, social media reputation, and activity anomalies, to notify and remediate potentially compromised devices, even outside managed environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If signature-based anti-malware scanning is used, then known malware can be detected, but new malware cannot be detected timely and the detection process is time-consuming

Engineering Contradiction:
Improvemalware detection accuracyVSAvoiddetection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by proactively identifying devices at risk of malware infection before actual infection occurs. It uses malware risk data, application risk assessments, and connection analysis to preemptively flag vulnerable devices, enabling preventive remediation rather than reactive detection after infection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary approach by using third-party malware risk data and connection relationship data as mediators to assess device risk. Instead of directly scanning each device for malware, it uses intermediate indicators (risk data, application reputations, connection patterns) to identify at-risk devices, significantly reducing detection time.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If MDM system is used to update anti-malware software, then internal devices can be protected, but external user devices cannot be managed and protected

Engineering Contradiction:
Improvedevice protection coverageVSAvoidapplicability to different user types
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system achieves universality by designing a solution that works for both internal employees and external users (customers, partners) without requiring MDM enrollment. It uses universally accessible data sources (public malware risk data, social media connection data, application store information) to assess risk across diverse device types and user categories, making the protection mechanism universally applicable.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables self-service by allowing external user devices to be assessed and notified of risks without requiring enrollment in a corporate MDM system. Devices are automatically evaluated based on their connections and risk profiles, and users receive notifications directly, eliminating the need for centralized device management control.

Inventive Principle:
Principle #25Self-service

3Reliability

If connections of at-risk devices are investigated, then malware propagation risk can be identified, but the complexity of analyzing user connections increases

Engineering Contradiction:
Improvemalware propagation detectionVSAvoidconnection analysis complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts only the essential connection information needed for risk assessment from complex social media networks. It identifies and extracts key attributes (connection relationships, interaction frequencies, shared applications) from the broader social graph, focusing analysis on the most relevant connection data rather than attempting to analyze all possible connection attributes.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system applies local quality by differentiating connection analysis based on specific risk contexts. Not all connections are analyzed with the same depth - the system adjusts the level of connection analysis based on the risk profile of the device and the nature of connections, applying more rigorous analysis only where necessary to identify propagation risks.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11095676B2Identifying and remediating malware-compromised devices
Publication Date: 2021.08.17 KYNDRYL INC
  • US11095676B2 patent drawing
  • US11095676B2 patent drawing
  • US11095676B2 patent drawing

AI summary

Systems and methods for identifying and remediating malware-compromised mobile devices are disclosed. A computer-implemented method includes accessing, by a computing device, malware risk data; determining, by the computing device, a mobile device is at risk from malware based on the malware risk data; identifying, by the computing device, a set of connections of a user of the mobile device, wherein each connection in the set of connections is associated with a user computer device; identifying, by the computing device, at least one user computer device from the set of connections at risk from the malware; and outputting, by the computer device, a malware notification for the mobile device at risk and at least one user computer device at risk.