Mobile Malware Detection via Power Signature Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current malware detection frameworks for mobile devices face challenges in detecting energy-greedy anomalies and malware variants due to resource constraints and high false-positive and false-negative rates, with existing methods like signature-based and behavioral detection being inefficient in battery-powered handhelds.

Innovation Solution

A system that includes a power monitoring module and a data analysis module to measure and analyze power consumption patterns, comparing them to known power signatures to identify anomalies and initiate protective operations, while minimizing resource usage through efficient data processing and compression techniques.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If signature-based detection is used for malware mitigation, then detection capability is improved, but resource consumption (CPU, memory, battery power) increases significantly

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidbattery power consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts only the essential detection functionality needed for malware identification, separating it from the resource-intensive signature matching processes. By taking out only the critical power consumption patterns and comparing against simplified signatures, the system maintains detection capability while dramatically reducing CPU and battery usage on resource-constrained mobile devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system changes the detection parameter from comprehensive signature analysis to power consumption pattern analysis. Instead of analyzing full malware signatures which require significant computational resources, the patent monitors and compares power consumption patterns, transforming the detection approach to one that is far more energy-efficient while remaining effective against malware variants.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If anomaly-based detection is used to identify malicious activities, then detection coverage is improved, but false-negative rate increases due to inadvertent inclusion of malicious activity in profile

Engineering Contradiction:
Improvedetection coverageVSAvoidfalse-negative rate
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments the detection process into two distinct phases: profile creation using anomaly-based detection for broad coverage, and verification using power signature matching for precision. This segmentation allows the system to benefit from both approaches - the comprehensive coverage of anomaly detection and the precision of signature-based verification, thereby reducing false-negatives while maintaining high detection coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Power consumption patterns serve as an intermediary between anomaly detection and final malware identification. The system first detects anomalies broadly, then uses power signature analysis as an intermediate verification step to confirm malicious activity, reducing false-negatives by adding this intermediate validation layer without sacrificing the broad coverage of anomaly-based detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If behavioral detection with generic worm propagation model is used, then detection versatility is improved, but false-positive rate increases due to insufficient complexity to reflect real-world computing activities

Engineering Contradiction:
Improvedetection versatilityVSAvoidfalse-positive rate
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent applies local quality by making the detection system adaptive to different malware types while maintaining precision for each specific category. Instead of using a single generic behavioral model that causes false-positives, the system develops specialized power consumption profiles for different malware categories (worms, viruses, spyware, etc.), allowing versatile detection across malware types while maintaining high precision through category-specific analysis.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts detection thresholds and parameters based on the specific malware type being detected. Rather than using static generic behavioral signatures that lead to false-positives, the patent implements dynamic power consumption analysis that adapts to different malware behaviors, maintaining versatility across malware types while reducing false-positives through context-aware threshold adjustment.

Inventive Principle:
Principle #15Dynamics

4Measurement precision

If power monitoring is performed continuously to detect malware, then detection accuracy is improved, but battery drain increases

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidbattery consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent implements periodic power monitoring at strategically chosen intervals rather than continuous monitoring. By sampling power consumption at key moments when malware activity is most likely to occur and comparing against pre-established power signatures, the system achieves high detection accuracy while dramatically reducing overall battery consumption compared to continuous monitoring approaches.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS8332945B2System and method for detecting energy consumption anomalies and mobile malware variants
Publication Date: 2012.12.11 THE RGT UNIV OF MICHIGAN
  • US8332945B2 patent drawing
  • US8332945B2 patent drawing
  • US8332945B2 patent drawing

AI summary

A system is presented for detecting malware applications residing on a mobile device powered by a battery. The system includes a power monitoring module, a data analysis module and a data store that stores a plurality of known power signatures signifying a power consumption anomaly. The power monitoring module measures power drawn from the battery and the data analysis module extracts a power history signature from the power measures. The data analysis module then compares the power history signature with the plurality of known power signatures and initiates a protective operation if the power history signature is closely correlated to one or more of the known power signatures.