Mobile Application Security Evaluation via Server-Side Execution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for evaluating the security of mobile applications are inadequate, as they rely on user knowledge and permissions information that is only available during installation, making it difficult for users to make informed decisions about application security, and fail to differentiate between hardware, operating system, or application issues.
Innovation Solution
A system and method for evaluating application security through user feedback analysis, which aggregates and classifies applications based on user reports, determines operating characteristics, and communicates security ratings to users and developers, allowing for informed decisions about installation and removal of applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If application security evaluation relies on user knowledge and permissions information during installation, then users can be informed about permissions, but users cannot make informed decisions about application security
Solution Approach 1:
The system performs security evaluation actions before the application is installed on user devices. A server system receives applications, evaluates their security characteristics by analyzing behavior during execution in a controlled environment, and stores evaluation results in advance. This allows users to access pre-computed security information without needing to perform complex analysis themselves during installation.
Solution Approach 2:
An intermediary server system acts as a mediator between application developers and end users. The server receives applications, performs security evaluations, and distributes results to multiple users. This intermediary handles the complex security analysis centrally, freeing users from needing expert knowledge while providing accurate security information to all users uniformly.
2Reliability
If manual verification of application integrity is performed, then security can be assessed, but the process becomes too onerous for large numbers of applications
Solution Approach 1:
The system implements automated self-service evaluation where the server system automatically receives applications, executes them in a controlled environment, analyzes their behavior, and generates security evaluations without human intervention. This automated process handles large volumes of applications efficiently while maintaining consistent security assessment standards.
Solution Approach 2:
Manual security verification processes are replaced with automated computational analysis. The server system uses software agents to execute applications, monitor their behavior, and automatically assess security characteristics. This substitution of manual mechanical verification with automated electronic analysis dramatically increases throughput while maintaining reliability.
3Loss of information
If permissions information is provided during installation, then users are informed about requested permissions, but this information is only available once the user has selected the application for downloading and installation
Solution Approach 1:
The server system computes and stores security evaluations and permissions information in advance, before users search for or select applications. When users query the system, pre-computed security data is immediately available for display alongside application information, eliminating the need to wait until installation time to see permissions details.
4Ease of operation
If users are equipped with knowledge about permissions, then they can evaluate application security, but the complexity of user knowledge requirements increases
Solution Approach 1:
The server system serves as an intermediary that performs complex security analysis and translates it into simple, user-friendly security ratings and permission summaries. Users interact with the simplified interface provided by the server rather than directly with complex security parameters, reducing the knowledge burden on users while maintaining evaluation capability.
Data Source
AI summary
Systems and methods are provided for application security evaluation. Applications may be managed in a server, the managing may include obtaining one or more security parameters associated with an application executable on a mobile communication device; evaluating the one or more security parameters; and generating or updating, based on evaluating the one or more security parameters, a security profile for the application. The application may be selected based on application related data, which may include feedback data provided by mobile communication devices. The application may be operated within the server, to obtain at least one of the one or more security parameters. The application may be operated using a script. Identification information for the application may be generating based on the security profile, with the identification information including information relating to or enabling assessing security of the application.
