Mobile Application Risk Analysis and Remediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile devices pose risks to networks due to malicious or risk-enhancing applications, which existing technologies fail to effectively assess and mitigate, particularly in enterprise environments where employee-owned devices access corporate systems.
Innovation Solution
A method and system for evaluating applications on mobile devices for privacy, data leakage, and malicious behavior, calculating a risk score, and automatically remediating applications that exceed a threshold, using a risk analysis system integrated with mobile device management to quarantine or retire risky applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If applications are evaluated and risk scores are calculated to identify malicious behavior, then security protection is improved, but system complexity and processing time increase
Solution Approach 1:
The risk analysis system segments the security evaluation process into distinct modules: application behavior monitoring, risk pattern matching, risk score calculation, and automated remediation. Each module handles specific aspects of security analysis independently, making the complex system manageable and maintainable while providing comprehensive security protection
Solution Approach 2:
The system performs preliminary risk assessment by evaluating applications before they can execute malicious operations. By pre-calculating risk scores based on application behaviors and characteristics, the system proactively identifies threats and applies remediation measures before actual security incidents occur, improving reliability without requiring complex real-time response mechanisms
2Measurement precision
If comprehensive application behavior monitoring is implemented to detect malicious operations, then detection precision is improved, but processing time and computational resources increase
Solution Approach 1:
The system applies different levels of monitoring intensity to different applications based on their risk profiles. High-risk applications undergo comprehensive behavior analysis with detailed monitoring, while low-risk applications receive minimal monitoring. This localized approach maintains high detection precision for critical threats while reducing overall processing time and computational overhead
Solution Approach 2:
The risk score calculation uses multiple parameters including application behavior patterns, permission requirements, network communication characteristics, and device access patterns. By dynamically adjusting which parameters are monitored based on preliminary assessments, the system achieves high detection precision for malicious behaviors while optimizing processing efficiency through selective parameter evaluation
3Productivity
If automated remediation is implemented for high-risk applications, then security response effectiveness is improved, but system complexity increases
Solution Approach 1:
The system implements self-service automated remediation where the risk analysis system automatically identifies high-risk applications, determines appropriate remediation actions, and executes those actions without human intervention. The system manages its own security response workflow, including quarantining malicious applications and notifying users, which improves response effectiveness while the modular architecture keeps automation complexity manageable
Solution Approach 2:
The automated remediation process incorporates feedback loops where remediation actions are executed and their effectiveness is monitored. The system receives feedback from application behavior changes after remediation and adjusts future risk assessments accordingly. This feedback mechanism improves security response effectiveness by learning from outcomes while maintaining manageable complexity through structured feedback processing
Data Source
AI summary
Application security analysis including systems and methods for analyzing applications for risk is provided. In an example method, the applications reside on a mobile device configurable to access an enterprise system. The example method includes evaluating each of a plurality of applications variously for privacy, data leakage, and malicious behavior. The example method also includes calculating a risk score for each of the plurality of applications based on the evaluating; and automatically remediating (e.g., quarantining) the applications, of the plurality of applications, for which the risk score meets or exceeds a risk score threshold. The method may evaluate all of the applications residing on a mobile device. The method may include grouping application behaviors, for each of the applications, that indicate an increased risk into groups comprising two or more of privacy risk, a data leakage risk, an account takeover risk, a device takeover risk, and a malware risk.


