Mobile Client Honeypot for Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security measures for mobile devices are inadequate in preventing malware attacks, as they drain resources, are ineffective against unknown threats, and lack mechanisms for privilege separation, while existing honeypot systems require malware signature updates and are limited by user mobility.

Innovation Solution

A mobile client honeypot system that monitors events on mobile devices, emulates human-like interaction with applications, and detects anomalous behavior without requiring malware signature awareness or emulating a network server, allowing for standalone operation and reduced resource overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If host-based security systems are implemented on mobile terminals, then security protection capability is improved, but resource consumption increases and battery life is reduced

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidbattery life
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent introduces a network-based security analysis system that acts as an intermediary between mobile terminals and security threats. Instead of running heavy security analysis locally on resource-constrained mobile devices, the system captures security events locally and transmits them to a powerful remote analysis platform, thereby providing comprehensive security protection without draining mobile device resources or battery life.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conventional anti-virus solutions are used on mobile devices, then protection against well-known viruses is improved, but effectiveness against unknown threats and application-level attacks deteriorates

Engineering Contradiction:
Improveprotection against well-known virusesVSAvoideffectiveness against unknown threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements preliminary action by proactively capturing security events and system state information before malware can execute harmful actions. The system monitors and records events such as application installations, file modifications, and system changes in real-time, creating a forensic trail that enables detection and analysis of both known and unknown threats, including zero-day attacks and application-level vulnerabilities.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If honeypot systems are deployed to detect malware, then malware detection capability is improved, but the systems require continuous malware signature updates and are limited by user mobility

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidrequirement for signature updates
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent inverts the traditional honeypot approach by making the mobile terminal itself the honeypot environment. Instead of deploying centralized honeypot servers that require continuous updates and have mobility limitations, the system transforms each mobile device into a self-contained honeypot that can detect and analyze malware locally, eliminating the need for external signature updates and maintaining full user mobility while enhancing detection capabilities.

Inventive Principle:
Principle #13The other way round (Inversion)

4Reliability

If mobile devices are used as honeypots, then malware detection during early propagation stages is improved, but resource constraints of mobile devices limit the security analysis capability

Engineering Contradiction:
Improvemalware detection during early propagationVSAvoidcomputing performance
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The patent applies segmentation by dividing the security system into two distinct components: a lightweight local agent on the mobile terminal that captures security events and basic analysis, and a powerful remote analysis server that performs comprehensive malware detection and forensics. This segmentation allows the mobile device to function as an effective honeypot for early malware detection while offloading computationally intensive security analysis to the remote server, thereby overcoming mobile device resource constraints.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2005350B1Method and system for mobile network security, related network and computer program product
Publication Date: 2018.08.15 TELECOM ITALIA SPA
  • EP2005350B1 patent drawingFigure 1
  • EP2005350B1 patent drawingFigure 2
  • EP2005350B1 patent drawingFigure 3

AI summary

A system for identifying malicious messages transmitted over a mobile communication network includes: sentinel modules associated with respective mobile terminals in the network for monitoring messages passing therethrough, wherein the sentinel modules identify as a candidate malicious message, any message passing through the mobile terminals and failing to comply with a first set of patterns and issue a corresponding sentinel identification message; a set of probe modules for monitoring messages transmitted over the network, wherein the probe modules identify as a candidate malicious message any message transmitted over the network and failing to comply with a second set of patterns and issue a corresponding probe identification message; and preferably at least one client honeypot module for receiving and processing any messages sent thereto to produce corresponding processing results, wherein the client honeypot module identifies as a candidate malicious message any message producing a processing result failing to comply with a third set of patterns and issues a corresponding client honeypot identification message.