Mobile Security Testing App for Network Vulnerability Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices are vulnerable to network security threats due to weaknesses in communications protocols, web browsers, operating systems, and mobile applications, making them targets for malware and data theft, with existing security defenses often inadequate in detecting and preventing such attacks.

Innovation Solution

A system and method for network and data security testing using a mobile device app that downloads and executes security test cases from a centralized server, attempting to access known malicious web pages and transmitting dummy sensitive data to assess vulnerabilities and risk exposure, with results displayed on the device and uploaded to the server, and dynamically updated to account for new threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If standard security defenses (firewalls, intrusion detection systems, antivirus software) are deployed, then basic protection against known threats is provided, but they fail to detect and prevent new or sophisticated attacks targeting mobile devices

Engineering Contradiction:
Improvesecurity protection effectivenessVSAvoidability to detect new threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary security testing by downloading and executing security test cases before actual attacks occur. The mobile device proactively tests its own security vulnerabilities by attempting to access known malicious web pages and transmitting dummy sensitive data, identifying security weaknesses before they can be exploited by real attackers.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system converts harmful security testing activities (accessing malicious pages, transmitting sensitive data) into beneficial security assessments. By deliberately attempting to access known malicious web pages and transmit dummy sensitive data, the system transforms potentially harmful actions into useful security diagnostics that identify vulnerabilities and improve protection.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

2Ease of operation

If mobile devices access unknown web pages or networks, then connectivity and functionality are maintained, but vulnerability to malware and data theft increases

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system introduces an intermediary security testing layer between the mobile device and external networks. Before accessing unknown web pages or networks, the device executes security test cases that act as intermediaries to detect potential threats, allowing users to maintain network accessibility while filtering out harmful content through proactive security assessments.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If comprehensive security testing is performed on mobile devices, then security vulnerabilities are identified, but the complexity of implementation and maintenance increases

Engineering Contradiction:
Improvesecurity vulnerability detection accuracyVSAvoidtesting system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system uses copied security test cases downloaded from centralized servers rather than implementing complex testing algorithms directly in the mobile device. The test cases are pre-packaged sets of security assessments that can be downloaded and executed locally, providing comprehensive vulnerability detection while keeping the device implementation simple and maintainable through centralized updates.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9681304B2Network and data security testing with mobile devices
Publication Date: 2017.06.13 FORCEPOINT LLC
  • US9681304B2 patent drawing
  • US9681304B2 patent drawing
  • US9681304B2 patent drawing

AI summary

The present invention provides a network and data security testing app for mobile devices such as an Apple iPad, which is connected to the Internet via a wireless network. The app downloads and stores one or more network security or data loss test cases from a centralized server, which are then executed on the mobile device. For example, a test case attempts to access predetermined web pages through the wireless network and then determines whether access was granted. In another example, a test case attempts to transmit sensitive data through the network. Results of the test case are displayed on the mobile device and uploaded to the centralized server. The network and data security testing app also identifies whether access was granted to web pages hosting botnets, malicious web exploits, malicious web obfuscation, malicious iframe redirection, and malware files.