In-line Filtering of Mobile App Communications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing number and variability of mobile apps pose challenges for enterprises in managing and monitoring app usage on devices that access corporate resources, as traditional anti-malware solutions are inadequate due to resource constraints and the inability to perform effective on-device malware detection, especially on iOS devices, which lack a device-based app inventory solution.

Innovation Solution

Implementing an in-line filtering system that intercepts app requests and communications, using a cloud-based platform to assess app risks based on behavior and policy violations, integrating with network devices to block insecure or unwanted data, and providing a holistic approach to screening apps for malware, vulnerabilities, and privacy risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional anti-malware solutions are deployed on mobile devices, then malware detection capability is provided, but resource constraints on mobile devices prevent effective operation

Engineering Contradiction:
Improvemalware detection capabilityVSAvoiddevice resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent introduces a network device as an intermediary that performs malware detection and filtering functions externally. The mobile device communicates app information to the network device, which then analyzes the apps and blocks malicious ones, eliminating the need for resource-intensive anti-malware software on the mobile device itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The malware detection and filtering functionality is extracted from the mobile device and relocated to a network device. This extraction allows the mobile device to maintain its resource constraints while still benefiting from comprehensive security analysis performed on more powerful external infrastructure.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If on-device malware detection is implemented, then security monitoring is provided, but iOS devices lack device-based app inventory solution

Engineering Contradiction:
Improvesecurity monitoringVSAvoidplatform compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The network device serves as a universal platform that handles security analysis for multiple mobile device types including both iOS and Android devices. It performs multiple functions including app inventory management, malware detection, and communication filtering, making it adaptable to different platform requirements without requiring device-specific implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If comprehensive app screening is performed, then malware and vulnerability detection is improved, but the complexity of the filtering system increases

Engineering Contradiction:
Improveapp screening effectivenessVSAvoidfiltering system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security system is segmented into distinct functional modules: app information collection, communication interception, malware analysis, and filtering decision-making. Each module performs a specific function, and they work together in a coordinated manner through the network device, making the overall complex system manageable and maintainable.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10482260B1In-line filtering of insecure or unwanted mobile device software components or communications
Publication Date: 2019.11.19 CA TECH INC
  • US10482260B1 patent drawing
  • US10482260B1 patent drawing
  • US10482260B1 patent drawing

AI summary

Techniques for in-line filtering of insecure or unwanted mobile components or communications (e.g., insecure or unwanted behaviors associated with applications for mobile devices (“apps”), updates for apps, communications to/from apps, operating system components/updates for mobile devices, etc.) for mobile devices are disclosed. In some embodiments, in-line filtering of apps for mobile devices includes intercepting a request for downloading an application to a mobile device; and modifying a response to the request for downloading the application to the mobile device. In some embodiments, the response includes a notification that the application cannot be downloaded due to an application risk policy violation.