Mobile Application Risk Analysis and Remediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices pose risks to networks due to malicious or risk-enhancing applications, which existing technologies fail to effectively assess and mitigate, particularly in enterprise environments where employee-owned devices access corporate systems.

Innovation Solution

A method and system for evaluating applications on mobile devices for privacy, data leakage, and malicious behavior, calculating a risk score, and automatically remediating applications that exceed a threshold, using a risk analysis system integrated with mobile device management to quarantine or retire risky applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If applications are evaluated and risk scores are calculated to identify malicious behavior, then security protection is improved, but system complexity and processing time increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The risk analysis system segments the security evaluation process into distinct modules: application behavior monitoring, risk pattern matching, risk score calculation, and automated remediation. Each module handles specific aspects of security analysis independently, making the complex system manageable and maintainable while providing comprehensive security protection

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary risk assessment by evaluating applications before they can execute malicious operations. By pre-calculating risk scores based on application behaviors and characteristics, the system proactively identifies threats and applies remediation measures before actual security incidents occur, improving reliability without requiring complex real-time response mechanisms

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If comprehensive application behavior monitoring is implemented to detect malicious operations, then detection precision is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvedetection precisionVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies different levels of monitoring intensity to different applications based on their risk profiles. High-risk applications undergo comprehensive behavior analysis with detailed monitoring, while low-risk applications receive minimal monitoring. This localized approach maintains high detection precision for critical threats while reducing overall processing time and computational overhead

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The risk score calculation uses multiple parameters including application behavior patterns, permission requirements, network communication characteristics, and device access patterns. By dynamically adjusting which parameters are monitored based on preliminary assessments, the system achieves high detection precision for malicious behaviors while optimizing processing efficiency through selective parameter evaluation

Inventive Principle:
Principle #35Parameter changes

3Productivity

If automated remediation is implemented for high-risk applications, then security response effectiveness is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity response effectivenessVSAvoidautomation complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system implements self-service automated remediation where the risk analysis system automatically identifies high-risk applications, determines appropriate remediation actions, and executes those actions without human intervention. The system manages its own security response workflow, including quarantining malicious applications and notifying users, which improves response effectiveness while the modular architecture keeps automation complexity manageable

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The automated remediation process incorporates feedback loops where remediation actions are executed and their effectiveness is monitored. The system receives feedback from application behavior changes after remediation and adjusts future risk assessments accordingly. This feedback mechanism improves security response effectiveness by learning from outcomes while maintaining manageable complexity through structured feedback processing

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11336678B2Methods and systems for security analysis of applications on mobile devices brought into an enterprise network environment
Publication Date: 2022.05.17 PROOFPOINT INC
  • US11336678B2 patent drawing
  • US11336678B2 patent drawing
  • US11336678B2 patent drawing

AI summary

Application security analysis including systems and methods for analyzing applications for risk is provided. In an example method, the applications reside on a mobile device configurable to access an enterprise system. The example method includes evaluating each of a plurality of applications variously for privacy, data leakage, and malicious behavior. The example method also includes calculating a risk score for each of the plurality of applications based on the evaluating; and automatically remediating (e.g., quarantining) the applications, of the plurality of applications, for which the risk score meets or exceeds a risk score threshold. The method may evaluate all of the applications residing on a mobile device. The method may include grouping application behaviors, for each of the applications, that indicate an increased risk into groups comprising two or more of privacy risk, a data leakage risk, an account takeover risk, a device takeover risk, and a malware risk.