Mobile App Security Assessment Server Using Segmented Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile application marketplaces face challenges in categorizing and managing applications effectively, distinguishing between desirable and undesirable ones, due to the rapid growth of mobile apps and the inability of current server-client security models to provide adequate assessment and security for mobile communication devices.
Innovation Solution
A system and method utilizing a server to analyze and provide security assessments for mobile communication devices, collecting and processing device and application data to identify and remediate potentially harmful applications, while minimizing network traffic and resource usage, through hashing, incremental data transmission, and behavioral analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If comprehensive application analysis is performed to improve security assessment accuracy, then measurement precision improves, but device complexity and processing time increase
Solution Approach 1:
The patent segments the application analysis process into multiple independent components: static analysis of application code, dynamic analysis of runtime behavior, analysis of user reviews and ratings, and analysis of developer credentials. Each component can be processed independently and contributes to the overall security assessment, making the complex system manageable and scalable
Solution Approach 2:
The system performs preliminary analysis actions before the user actually installs or runs an application. Security assessments, including static code analysis and preliminary behavioral analysis, are conducted in advance so that users receive security information before exposure to potential threats, reducing the need for complex real-time analysis
2Measurement precision
If detailed application data is collected and transmitted to server, then assessment accuracy improves, but network traffic and resource usage increase
Solution Approach 1:
The patent extracts only the essential and relevant data elements needed for security assessment from the application, such as permission requests, API calls, and behavioral patterns, rather than transmitting complete application code or all runtime data. This selective extraction reduces network traffic while maintaining assessment accuracy
Solution Approach 2:
The system implements incremental analysis where only sufficient data is collected to achieve accurate assessment without excessive data gathering. The analysis depth is adjusted based on risk levels and available resources, performing partial analysis when full analysis is unnecessary
3Reliability
If real-time security assessment is provided, then reliability improves, but processing speed and response time worsen
Solution Approach 1:
The system performs security assessments in advance before applications are installed or executed on user devices. Applications are analyzed on the server side prior to distribution, so security information is already available when users want to install applications, providing both reliability and speed
Solution Approach 2:
The patent merges multiple analysis techniques including static analysis, dynamic analysis, and reputation-based assessment into a unified security evaluation system. This combination provides comprehensive security assurance while the pre-computed nature of much of this analysis maintains fast response times for users
Data Source
AI summary
Application programs for mobile communication devices are stored in a data store. The applications may be collected from any number of different sources such as through an application programming interface (API), from web crawling, from users, or combinations of these. The applications are analyzed and the analysis results reported. The applications may be “continuously” analyzed so that any changes in assessments can be reported. If an application for which an analysis is sought is not in the data store, information about a different, but related application may be provided.


