Mobile Malware Detection via Cross-Device Application Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile operating systems lack the ability to detect and prevent malicious applications from subscribing users to premium services without their consent, leading to unwanted financial obligations and decreased device performance due to the lack of security software to intercept or block suspicious SMS and phone activities.

Innovation Solution

A computer-implemented method that identifies malware by receiving event data from mobile devices, comparing application lists across devices, and assigning a confidence score to identify potentially malicious applications responsible for suspicious activities such as premium SMS and phone activities, using a detection module to collect and analyze data on suspicious behaviors like premium rate service subscriptions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security software is installed to detect and block malicious applications, then device security and user protection improve, but device functionality and performance decrease due to interception and blocking operations

Engineering Contradiction:
Improvedevice securityVSAvoiddevice functionality
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces an intermediary detection system that monitors application behavior indirectly through SMS event logs rather than directly intercepting or blocking communications. This mediator approach allows security monitoring without the performance overhead of active interception, resolving the contradiction between security reliability and device productivity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical approach of intercepting and blocking SMS communications with a data analysis approach that examines event logs to identify malicious patterns. This substitution eliminates the performance penalty of active communication blocking while maintaining security detection capabilities

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If comprehensive monitoring of SMS and phone activities is implemented, then detection accuracy of malicious applications improves, but device complexity increases due to extensive data collection and analysis requirements

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts only the essential event data needed for detection (SMS send/receive events, application lists, device identifiers) from the complex stream of mobile device activities. This extraction approach maintains high detection accuracy while minimizing the complexity of data collection and processing by focusing only on relevant indicators

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a universal detection framework that analyzes standardized event data structures across multiple devices and carriers. This multi-functional approach allows the same detection logic to identify malicious applications regardless of device type or carrier, reducing overall system complexity through standardization

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8984632B1Systems and methods for identifying malware
Publication Date: 2015.03.17 CA TECH INC
  • US8984632B1 patent drawing
  • US8984632B1 patent drawing
  • US8984632B1 patent drawing

AI summary

A computer-implemented method for identifying malware is described. Event data is received from a mobile device. The event data including events performed on the mobile device and a list of one or more applications. The list of the one or more applications is compared with at least one additional list of applications received from at least one additional mobile device. An application in common across the lists of applications is identified. The identification of the application in common to is transmitted to the mobile device.