Mobile Terminal IMEI Blocking for Malware Damage Limitation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for limiting damage from malware-infected mobile devices, such as smartphones, often restrict the use of SIM cards, causing inconvenience and allowing temporary use of infected devices to send harmful messages, while not effectively preventing integration into botnets.
Innovation Solution
Implement a method and system that block data traffic for infected mobile devices based on their IMEI, allowing the SIM card to be used across multiple devices without restriction, and provide zero-rated services for cleaning the malware, while maintaining service availability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Object-affected harmful factors
If SMS-MO blocking is implemented on infected devices, then malware propagation is prevented, but legitimate user communication is restricted
Solution Approach 1:
The patent segments the blocking mechanism by introducing a whitelist of allowed destinations. Instead of a complete SMS-MO block, only communications to non-whitelisted numbers are prevented. This allows legitimate user communication (to whitelisted contacts) to continue while blocking malware propagation to unknown destinations, thus resolving the contradiction between preventing harm and maintaining ease of operation.
2Object-affected harmful factors
If complete SIM blocking is implemented, then malware integration into botnets is prevented, but legitimate services are unavailable to users
Solution Approach 1:
The patent applies local quality by implementing selective blocking rather than complete SIM blocking. The system differentiates between legitimate communications (to whitelisted destinations) and malicious communications (to non-whitelisted destinations). This localized approach prevents botnet integration while maintaining service availability for legitimate purposes, resolving the contradiction between preventing harm and ensuring reliability.
3Difficulty of detecting and measuring
If data traffic monitoring is implemented to detect malware, then infection detection capability is improved, but network resource consumption increases
Solution Approach 1:
The patent applies partial action by monitoring only specific data traffic patterns indicative of malware behavior rather than analyzing all data traffic comprehensively. The system focuses on detecting unusual communication patterns, high-volume data transfers, and connections to known malicious IPs. This selective monitoring approach improves infection detection capability while minimizing network resource consumption compared to comprehensive traffic analysis.
Data Source
Figure 1a~1f
AI summary
The invention relates to a solution for damage limitation after the infection of a mobile communication-enabled terminal equipped with computer functionalities, namely a Mobile Terminal MT (1), with malware. An infection of the MT (1) with malware is detected by specially designed network facilities (2) of the mobile network operator, for whose use a subscriber identification module (SIM) used with the MT (1) authorizes the user of the MT (1). In the event that an infection has been detected in an MT (1), data traffic is blocked for the MT (1) affected by the malware infection, according to the proposed solution, by using the International Mobile Device Identification Number (IMEI) determined for this MT (1) by the network facilities (2) of the network operator.This means that for this MT (1) an IMEI-based blocking of outgoing and incoming data traffic takes place, namely the data traffic bound to an available data volume.