Mobile Malware Detection via Cross-Device Application Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile operating systems lack the ability to detect and prevent malicious applications from subscribing users to premium services without their consent, leading to unwanted financial obligations and decreased device performance due to the lack of security software to intercept or block suspicious SMS and phone activities.
Innovation Solution
A computer-implemented method that identifies malware by receiving event data from mobile devices, comparing application lists across devices, and assigning a confidence score to identify potentially malicious applications responsible for suspicious activities such as premium SMS and phone activities, using a detection module to collect and analyze data on suspicious behaviors like premium rate service subscriptions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security software is installed to detect and block malicious applications, then device security and user protection improve, but device functionality and performance decrease due to interception and blocking operations
Solution Approach 1:
The patent introduces an intermediary detection system that monitors application behavior indirectly through SMS event logs rather than directly intercepting or blocking communications. This mediator approach allows security monitoring without the performance overhead of active interception, resolving the contradiction between security reliability and device productivity
Solution Approach 2:
The patent replaces the mechanical approach of intercepting and blocking SMS communications with a data analysis approach that examines event logs to identify malicious patterns. This substitution eliminates the performance penalty of active communication blocking while maintaining security detection capabilities
2Measurement precision
If comprehensive monitoring of SMS and phone activities is implemented, then detection accuracy of malicious applications improves, but device complexity increases due to extensive data collection and analysis requirements
Solution Approach 1:
The patent extracts only the essential event data needed for detection (SMS send/receive events, application lists, device identifiers) from the complex stream of mobile device activities. This extraction approach maintains high detection accuracy while minimizing the complexity of data collection and processing by focusing only on relevant indicators
Solution Approach 2:
The patent creates a universal detection framework that analyzes standardized event data structures across multiple devices and carriers. This multi-functional approach allows the same detection logic to identify malicious applications regardless of device type or carrier, reducing overall system complexity through standardization
Data Source
AI summary
A computer-implemented method for identifying malware is described. Event data is received from a mobile device. The event data including events performed on the mobile device and a list of one or more applications. The list of the one or more applications is compared with at least one additional list of applications received from at least one additional mobile device. An application in common across the lists of applications is identified. The identification of the application in common to is transmitted to the mobile device.


