Mobile App Identification via Resource Profiling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The uncontrolled supply of smartphone applications makes it difficult to identify malfunctioning or malicious apps, especially since existing methods require prior knowledge of app behavior and can't effectively monitor across various terminal types.
Innovation Solution
A method and system that monitor and compare user device and network resource utilization data to identify significant differences, allowing for the identification of applications without prior knowledge of their traffic behavior, even if malicious behavior starts after installation or at different times on different devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a priori testing and verification of applications is performed, then application security and reliability are improved, but the ability to identify malicious behavior after installation is worsened
Solution Approach 1:
The system performs preliminary profiling of application behavior during installation by monitoring resource utilization patterns. This creates a baseline profile that enables future detection of malicious behavior without requiring complete a priori verification of all applications.
Solution Approach 2:
The system continuously monitors resource utilization and compares it against stored profiles, providing feedback that enables real-time detection of deviations from normal behavior. This feedback mechanism allows post-installation identification of malicious applications.
2Measurement precision
If comprehensive monitoring of all terminal types is performed, then detection accuracy is improved, but system complexity and resource requirements are worsened
Solution Approach 1:
Instead of implementing complex monitoring systems on each terminal type, the system creates simplified profiles that capture essential behavior patterns. These profiles serve as copies of the monitoring function, enabling detection across diverse terminals without replicating full monitoring complexity on each device.
Solution Approach 2:
The system designs profiles and monitoring mechanisms that work universally across different terminal types by focusing on common resource utilization patterns rather than terminal-specific implementations. This multi-functional approach enables broad detection capability without increasing individual terminal complexity.
3Loss of time
If resource utilization monitoring is performed continuously, then real-time identification of malicious applications is improved, but energy consumption and processing overhead are worsened
Solution Approach 1:
The system performs monitoring and comparison operations periodically rather than continuously, checking resource utilization at intervals against stored profiles. This periodic approach enables timely detection of malicious behavior while reducing energy consumption and processing overhead compared to continuous monitoring.
Solution Approach 2:
The system monitors only the most significant resource utilization parameters that are indicative of malicious behavior, rather than all possible system resources. This partial monitoring approach provides sufficient detection capability while minimizing energy consumption and processing requirements.
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
A method for identifying (432) an application installed in a user device (402) of a communication system, is disclosed. Based on user device and network resources (416; 420) utilized by the user device and installation information about applications installed application (412), an identification (432) of an application can be performed. An advantage with embodiments of this invention is that an application can be identified, without prior information how the application affects user device and network resources. Malicious and noxious applications can hereby be identified. Also, a resource consumption reporting service offered to the subscribers by the operator is enabled.