Mobile Cyber Incident Analysis System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems lack effective methods for analyzing mobile cyber incidents, particularly in detecting malicious codes inserted into URLs and automatically executed applications without user consent, with limited collection and analysis capabilities and low adoption of mobile vaccines among users.
Innovation Solution
A system and method involving a mobile incident collection server, a mobile incident analysis server with URL and application analysis modules, and a database for managing analysis information, which checks for malicious behaviors in URLs and applications using real-time search words, text messages, and application market data, employing modules for URL and APK analysis, obfuscation detection, and dynamic analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual analysis of mobile malicious codes is performed, then detection accuracy is improved, but analysis time and resource consumption increase
Solution Approach 1:
The system performs preliminary automated analysis of APK files using multiple vaccine engines and static analysis techniques before manual review. This preliminary action filters out clearly malicious or benign applications, allowing human analyzers to focus only on suspicious cases that require expert judgment, thereby reducing overall analysis time while maintaining high detection accuracy
Solution Approach 2:
The patent introduces an automated analysis system as an intermediary between the APK file and the human analyzer. This intermediary performs initial scanning, behavior monitoring, and pattern recognition, providing pre-processed information and risk assessments to human analysts. The intermediary handles routine detection tasks, allowing human experts to concentrate on complex cases requiring contextual understanding
2Reliability
If multiple vaccine engines are used for analysis, then detection coverage is improved, but system complexity increases
Solution Approach 1:
The system merges multiple vaccine engines and analysis tools into a unified analysis platform. Different vaccine engines are integrated to work together, sharing common infrastructure such as file management, logging, and result aggregation. This combining approach maintains comprehensive detection coverage while reducing operational complexity through centralized control and standardized interfaces
Solution Approach 2:
The analysis system is designed with multi-functional capabilities that serve multiple purposes. The same infrastructure supports static analysis, dynamic monitoring, behavior tracking, and cross-engine result correlation. This universal design allows the system to perform diverse analysis functions without requiring separate specialized systems for each function, thereby managing complexity while maintaining comprehensive detection
3Productivity
If automated analysis systems are implemented, then analysis speed is improved, but detection precision deteriorates
Solution Approach 1:
The analysis process is segmented into different stages: automated preliminary screening, behavior monitoring, and manual expert review. Each segment handles specific types of analysis tasks with appropriate methods. Automated systems perform high-speed initial filtering and pattern recognition, while human experts conduct detailed analysis on flagged cases, combining the speed of automation with the precision of human judgment
Solution Approach 2:
The system implements feedback mechanisms where automated analysis results are continuously refined based on manual review outcomes. Detection patterns and rules are updated based on expert analysis of false positives and negatives. This feedback loop allows the automated system to learn from human expertise, improving detection precision over time while maintaining high analysis speed through automated processing
Data Source
AI summary
A system and method for analyzing mobile cyber incidents that checks whether codes attacking the weaknesses of mobile users are inserted into collected URLs and whether applications are downloaded and automatically executed, without the agreement of users, so that if the mobile cyber incidents are analyzed through the manual analysis of a manager, the applications to be analyzed manually can be reduced.


