Mobile App Security Score Calculation via Automated Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile applications often lack comprehensive security assessments, relying primarily on user feedback that may not adequately address potential security risks, such as data monitoring and malicious activities, which can harm mobile devices and users.
Innovation Solution
Implementing an automated predictive analytics system that generates a security score for mobile applications based on data from application distribution platforms and additional sources, using predictive models to evaluate authenticity, reliability, safety, and privacy, providing users with a score to assess the security of applications before installation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If user feedback ratings are used to assess mobile application quality, then user satisfaction and feature quality can be evaluated, but security risks such as data monitoring and malicious activities cannot be adequately identified
Solution Approach 1:
The security assessment system segments the evaluation into multiple independent components: static analysis of application code, dynamic analysis during runtime, reputation-based scoring from multiple sources, and permission-based risk assessment. Each component generates separate security metrics that are then aggregated into an overall security score, allowing comprehensive security evaluation without requiring a single complex monolithic system
Solution Approach 2:
The patent introduces an intermediary automated security assessment system that acts as a mediator between application developers and users. This intermediary analyzes applications before distribution and provides security scores to users, eliminating the need for users to directly evaluate security aspects themselves while providing objective security information that complements user feedback on features and usability
2Reliability
If comprehensive security analysis is performed on mobile applications, then security risks can be identified, but the time and resources required for analysis increase significantly
Solution Approach 1:
The system performs preliminary security analysis actions at multiple stages: during application submission to the distribution platform, before making the application available to users, and continuously in the background after deployment. Static analysis of code and permissions is performed beforehand to identify obvious security issues, while dynamic analysis runs selectively based on triggers such as permission changes or suspicious behaviors, reducing the need for continuous full-scale analysis
Solution Approach 2:
The assessment system dynamically adjusts analysis parameters based on risk levels and application characteristics. High-risk applications requiring sensitive permissions undergo more thorough analysis, while low-risk applications receive streamlined assessment. The system changes analysis depth, sampling rates, and monitoring intensity based on detected security indicators, optimizing the balance between comprehensive security checking and resource consumption
Data Source
AI summary
The security or other attributes of mobile applications may be assessed and assigned a security score. In one implementation, a device may obtain information relating to the mobile applications, and may determine, for each of the mobile applications, a number of security scores. Each of the security scores may define a level of risk for a security category relating to a mobile application. The device may further combine the security scores, for each of the mobile applications, to obtain, for each of the mobile applications, a final security score.


