Mobile App Risk Analysis via Segmented Static and Dynamic Evaluation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current malware detection systems fail to provide a comprehensive and accurate assessment of the maliciousness or risk associated with mobile applications on endpoint devices, leaving them vulnerable to attacks and compromising enterprise networks.
Innovation Solution
A Mobile Application Risk Analysis System (RAS) that includes a mobile agent on endpoint devices, a management server, and an analysis cloud, which collects and analyzes data on application installations, usage, network traffic, and device configurations to determine threat levels through static and dynamic analysis, using a webview emulator to assess embedded browsers and network traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If current malware detection systems are used, then basic malware detection is provided, but comprehensive and accurate assessment of mobile application risk is not achieved
Solution Approach 1:
The system segments the risk assessment process into multiple independent analysis components: static analysis of application code, dynamic analysis of application behavior, network traffic analysis, and device configuration analysis. Each component operates independently and contributes to the overall risk assessment, enabling comprehensive evaluation without overwhelming complexity in a single detection mechanism.
Solution Approach 2:
The mobile application risk analysis system performs multiple functions through a unified platform: it analyzes application code for vulnerabilities, monitors application behavior at runtime, captures and analyzes network traffic patterns, and assesses device configuration security. This multi-functional approach provides comprehensive risk assessment that no single detection system can achieve.
2Adaptability or versatility
If mobile applications are installed on endpoint devices, then application functionality is enhanced, but vulnerability to malware attacks increases
Solution Approach 1:
The system performs preliminary risk assessment of mobile applications before they are installed on endpoint devices. By analyzing application code, permissions, and behavior patterns in advance, the system can identify potentially malicious applications and prevent their installation, thereby protecting devices before malware can cause harm.
Solution Approach 2:
The system continuously monitors application behavior, network traffic, and device configuration after installation and provides feedback to security administrators. This feedback mechanism enables real-time detection of malicious activity and allows for dynamic response actions, creating a closed-loop security system that adapts to changing threat conditions.
3Measurement precision
If comprehensive analysis of mobile applications is performed, then risk identification is improved, but system complexity increases
Solution Approach 1:
The analysis system is divided into distinct functional modules: static analysis module for code examination, dynamic analysis module for behavior monitoring, network analysis module for traffic inspection, and device configuration module for security assessment. Each module handles specific aspects of risk analysis independently, making the overall complex task manageable through modular architecture.
Solution Approach 2:
The system introduces an intermediary analysis platform that sits between mobile applications and endpoint devices, orchestrating the comprehensive analysis process. This intermediary layer coordinates the various analysis modules, manages data flow between components, and synthesizes results into comprehensive risk assessments, thereby reducing the complexity burden on individual components.
Data Source
AI summary
An electronic device comprising one or more processors; a storage medium communicatively coupled to the one or more processors, the storage medium having stored thereon logic that, upon execution by the one or more processors, performs operations comprising: (1) receiving, via a first electrical signal, application data from a mobile agent installed on a mobile device, (2) querying, via a second electrical signal, a database for a risk level of each of one or more applications of the mobile device listed in the application data, and (3) determining a threat level for the mobile device based on one or more of: (i) the risk level of at least one of the one or more applications, (ii) usage information of the at least one of the one or more applications, or (iii) configuration information of the mobile device is shown.


