Mobile App Identification via Resource Profiling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The uncontrolled supply of smartphone applications makes it difficult to identify malfunctioning or malicious apps, especially since existing methods require prior knowledge of app behavior and can't effectively monitor across various terminal types.

Innovation Solution

A method and system that monitor and compare user device and network resource utilization data to identify significant differences, allowing for the identification of applications without prior knowledge of their traffic behavior, even if malicious behavior starts after installation or at different times on different devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a priori testing and verification of applications is performed, then application security and reliability are improved, but the ability to identify malicious behavior after installation is worsened

Engineering Contradiction:
Improveapplication securityVSAvoiddetection of malicious behavior
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary profiling of application behavior during installation by monitoring resource utilization patterns. This creates a baseline profile that enables future detection of malicious behavior without requiring complete a priori verification of all applications.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors resource utilization and compares it against stored profiles, providing feedback that enables real-time detection of deviations from normal behavior. This feedback mechanism allows post-installation identification of malicious applications.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If comprehensive monitoring of all terminal types is performed, then detection accuracy is improved, but system complexity and resource requirements are worsened

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

Instead of implementing complex monitoring systems on each terminal type, the system creates simplified profiles that capture essential behavior patterns. These profiles serve as copies of the monitoring function, enabling detection across diverse terminals without replicating full monitoring complexity on each device.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system designs profiles and monitoring mechanisms that work universally across different terminal types by focusing on common resource utilization patterns rather than terminal-specific implementations. This multi-functional approach enables broad detection capability without increasing individual terminal complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of time

If resource utilization monitoring is performed continuously, then real-time identification of malicious applications is improved, but energy consumption and processing overhead are worsened

Engineering Contradiction:
Improvereal-time identificationVSAvoidenergy consumption
Core Design Contradiction:
Loss of timeVSUse of energy by moving object

Solution Approach 1:

The system performs monitoring and comparison operations periodically rather than continuously, checking resource utilization at intervals against stored profiles. This periodic approach enables timely detection of malicious behavior while reducing energy consumption and processing overhead compared to continuous monitoring.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system monitors only the most significant resource utilization parameters that are indicative of malicious behavior, rather than all possible system resources. This partial monitoring approach provides sufficient detection capability while minimizing energy consumption and processing requirements.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP2800024B1System and methods for identifying applications in mobile networks
Publication Date: 2019.02.27 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP2800024B1 patent drawingFigure 1
  • EP2800024B1 patent drawingFigure 2~3
  • EP2800024B1 patent drawingFigure 4

AI summary

A method for identifying (432) an application installed in a user device (402) of a communication system, is disclosed. Based on user device and network resources (416; 420) utilized by the user device and installation information about applications installed application (412), an identification (432) of an application can be performed. An advantage with embodiments of this invention is that an application can be identified, without prior information how the application affects user device and network resources. Malicious and noxious applications can hereby be identified. Also, a resource consumption reporting service offered to the subscribers by the operator is enabled.