Mobile App Behavior Analysis via OS Execution State Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile device solutions fail to efficiently identify and address the complex factors contributing to performance and power degradation over time, as they are resource-intensive and limited to detecting known viruses and malware, neglecting other performance-degrading factors.
Innovation Solution
A method that monitors operating system execution states of software applications to generate behavior vectors, determining whether activities are malicious or benign by associating them with relevant execution states, using classifier models to focus operations and conserve resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing mobile device solutions monitor all software activities to detect malware, then detection capability is improved, but resource consumption increases
Solution Approach 1:
The patent applies local quality by monitoring only specific execution states (foreground, background, killed) rather than all software activities uniformly. The system focuses monitoring resources on state transitions that are more indicative of malicious behavior, thereby reducing overall resource consumption while maintaining detection effectiveness.
Solution Approach 2:
The system changes the parameter of monitoring scope by selectively observing certain execution states and their transitions. By parameterizing which states to monitor based on their relevance to malicious behavior, the system optimizes the balance between detection capability and resource usage.
2Measurement precision
If comprehensive behavioral monitoring is implemented to identify performance-degrading factors, then identification accuracy is improved, but device complexity increases
Solution Approach 1:
The patent extracts and focuses on specific execution state transitions (foreground to background, background to killed, etc.) that are most relevant to identifying malicious and performance-degrading behaviors. By taking out only the critical state transitions for monitoring, the system maintains high identification accuracy while avoiding the complexity of comprehensive monitoring.
Solution Approach 2:
The monitoring system is segmented into specific observation points corresponding to different execution state transitions. Rather than implementing a monolithic comprehensive monitoring system, the patent divides monitoring into discrete state transition events, reducing overall system complexity while preserving detection accuracy.
3Reliability
If traditional antivirus scanning is performed continuously to detect known malware, then detection reliability is improved, but processing time increases
Solution Approach 1:
The system employs periodic action by monitoring execution state transitions at specific intervals (when state changes occur) rather than performing continuous scanning. This event-driven periodic monitoring reduces processing time while maintaining detection reliability by focusing on critical moments when malicious behavior is most likely to manifest.
Solution Approach 2:
The system performs preliminary action by establishing monitoring of execution state transitions in advance, so that when suspicious activities occur, the system is already positioned to detect them immediately. This eliminates the need for time-consuming on-demand scanning while maintaining continuous detection capability.
Data Source
AI summary
Methods, systems and devices use operating system execution states while monitoring applications executing on a mobile device to perform comprehensive behavioral monitoring and analysis include configuring a mobile device to monitor an activity of a software application, generate a shadow feature value that identifies an operating system execution state of the software application during that activity, generate a behavior vector that associates the monitored activity with the shadow feature value, and determine whether the activity is malicious or benign based on the generated behavior vector, shadow feature value and/or operating system execution states. The mobile device may also be configured to intelligently determine whether the operating system execution state of a software application is relevant to determining whether any of the monitored mobile device behaviors are malicious or suspicious, and monitor only the operating system execution states of the software applications for which such determinations are relevant.


