Mobile Behavior Analysis Engine with Multi-Provider Model Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile device solutions fail to efficiently identify and address the complex factors contributing to performance degradation and power utilization issues over time, as they often rely on computationally intensive scanning engines that consume resources and are limited to detecting known viruses and malware, neglecting the interactions that combine to degrade mobile device performance.
Innovation Solution
The method involves a mobile device configured to work with cloud services and networks to intelligently identify performance-degrading factors by using an observer module to collect behavior information, an analyzer module to classify it, and an interfaces module to communicate with multiple networks and services, enabling the download and updating of behavior models from various sources to monitor and correct suspicious or malicious behaviors without excessive resource consumption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If computationally intensive scanning engines are used to detect viruses and malware, then detection capability is improved, but power consumption and resource utilization increase
Solution Approach 1:
The patent segments the malware detection system into multiple specialized analyzer components (static analyzer, dynamic analyzer, heuristic analyzer, behavior analyzer) that work in parallel. Each analyzer processes different aspects of malware detection independently, allowing the system to distribute computational load and reduce peak power consumption while maintaining comprehensive detection capability.
Solution Approach 2:
The patent implements a multi-tiered analysis approach where not all analyzers are activated for every file. Instead, the system performs initial screening with lighter analyzers and only activates more computationally intensive analyzers when suspicious patterns are detected, thereby reducing overall power consumption while maintaining high detection reliability.
2Productivity
If comprehensive behavior monitoring is implemented to identify performance degradation factors, then system performance improvement is achieved, but device complexity increases
Solution Approach 1:
The patent creates a universal behavior analysis platform that monitors multiple aspects of system performance (CPU usage, memory consumption, battery drain, network activity) through a single integrated framework. The behavior analyzers serve multiple functions by analyzing different performance metrics using similar computational approaches, thereby improving system performance without proportionally increasing device complexity.
Solution Approach 2:
The patent introduces behavior models as intermediary components that mediate between raw system metrics and performance conclusions. These models abstract complex performance data into interpretable behavior patterns, simplifying the analysis process and reducing the complexity burden while enabling comprehensive performance monitoring.
3Measurement precision
If multiple analyzer models from different providers are integrated, then detection accuracy is improved, but system complexity and resource requirements increase
Solution Approach 1:
The patent merges multiple analyzer models from different providers into a unified behavior analysis platform. The system integrates static analyzers, dynamic analyzers, heuristic analyzers, and behavior analyzers from various sources, combining their detection capabilities into a coordinated system that improves overall detection accuracy while managing system complexity through unified architecture.
Solution Approach 2:
The patent implements a modular analyzer architecture where detection models can be copied and deployed as independent components. Each analyzer model operates as a self-contained unit that can be independently updated, managed, and configured, reducing system complexity while enabling the integration of multiple detection approaches for improved accuracy.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
Methods, systems and devices for generating data models in a client-cloud communication system may include applying machine learning techniques to generate a first family of classifier models that describe a cloud corpus of behavior vectors. Such vectors may be analyzed to identify factors in the first family of classifier models that have the highest probability of enabling a mobile device to better determine whether a mobile device behavior is malicious or benign. Based on this analysis, a second family of classifier models may be generated that identify significantly fewer factors and data points as being relevant for enabling the mobile device to better determine whether the mobile device behavior is malicious or benign based on the determined factors. A mobile device classifier module based on the second family of classifier models may be generated and made available for download by mobile devices, including devices contributing behavior vectors.