Mobile Malicious Code Detection via Server-Side Message Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile communication devices lack the computing resources to effectively implement full-service protection against malicious code, leading to inadequate protection from existing antivirus products.
Innovation Solution
A method and system that utilize a message analysis server to analyze mobile messages for malicious code, where messages sent to specific numbers are analyzed for signatures or executed in an isolated environment, and responses are sent to users or devices with instructions or executables for removal.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If full-service antivirus products are implemented on mobile devices, then protection effectiveness against malicious code is improved, but device performance and user experience deteriorate due to limited computing resources
Solution Approach 1:
The patent introduces a server as an intermediary between mobile devices and malicious code threats. The server performs the computationally intensive antivirus analysis functions, while mobile devices only need to send messages and receive responses. This mediator approach allows full-service protection without burdening the limited mobile device resources.
Solution Approach 2:
The patent shifts the antivirus processing from the mobile device dimension to the server dimension. Instead of running antivirus software locally on the mobile device, the system analyzes malicious code on a remote server with sufficient computing resources, then communicates results back to the mobile device through messaging services.
2Productivity
If stripped-down antivirus products are used on mobile devices, then device performance is maintained, but protection effectiveness against malicious code deteriorates
Solution Approach 1:
The server acts as an intermediary that provides the missing protection capabilities. Mobile devices use lightweight clients that communicate with the server, which performs the comprehensive antivirus analysis. This resolves the contradiction by maintaining device performance while achieving full protection through the server intermediary.
3Measurement precision
If comprehensive antivirus analysis is performed locally on mobile devices, then detection accuracy is improved, but computing resource consumption increases beyond available capacity
Solution Approach 1:
The server serves as an intermediary that handles the computationally intensive detection and analysis tasks. Mobile devices only perform lightweight operations of sending messages and receiving analysis results, thereby maintaining high detection accuracy through server-based analysis while keeping local computing resource consumption minimal.
4Reliability
If mobile devices have sufficient computing resources for full-service antivirus, then protection effectiveness is improved, but device cost and complexity increase
Solution Approach 1:
The server acts as an intermediary that provides full-service antivirus capabilities externally. Mobile devices only need basic messaging functionality and minimal client software to communicate with the server, avoiding the need for expensive hardware upgrades or complex local antivirus implementations while still achieving effective protection.
Data Source
AI summary
Various methods and systems for collecting and analyzing mobile messages for malicious code are disclosed. In one embodiment, a method involves receiving a first message sent to a telephone number by a sender and determining whether the message contains malicious code. The first message is sent to the telephone number (e.g., a common short code), which is associated with a message analysis server, using a wireless messaging service such as EMS or MMS. The first message can be sent from a mobile communication device (e.g., by a user or by an application, such as an antivirus program, executing on the mobile communication device).


