Mobile Text Message Attribute Analysis for Malicious App Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Malicious premium-text applications on mobile devices exploit users by sending illegitimate text messages to premium-rate numbers, evading detection due to polymorphic techniques, which conventional anti-malware solutions struggle to identify.

Innovation Solution

A system and method that analyze attributes of outgoing text messages, such as physical orientation, operating mode, language, and content payload, to determine illegitimacy and identify suspicious text-messaging applications, performing security actions to prevent further illegitimate messages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional signature-based security systems are used to detect malicious applications, then detection simplicity is maintained, but detection effectiveness deteriorates due to polymorphic techniques employed by malware

Engineering Contradiction:
Improvedetection effectivenessVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the detection parameters from static signature matching to dynamic behavioral analysis. Instead of checking for known malware signatures, the system monitors text message attributes (recipient numbers, timing patterns, content characteristics) and device state parameters (orientation, locked mode, input method) to detect malicious behavior patterns, thereby overcoming polymorphic evasion techniques

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces the mechanical signature-matching system with a behavioral analysis system that monitors and evaluates multiple parameters simultaneously. This substitution enables detection of previously undetectable polymorphic malware by focusing on operational characteristics rather than static code signatures

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If comprehensive attribute analysis of text messages is performed to identify illegitimate messages, then detection accuracy is improved, but processing time increases

Engineering Contradiction:
Improveillegitimate message detection accuracyVSAvoidmessage processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies partial action by selectively analyzing only the most critical attributes of text messages and device states. Rather than examining every possible parameter in equal depth, the system focuses on key indicators such as recipient number patterns, message timing, and device orientation, achieving high detection accuracy with reduced processing overhead

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary analysis of text message attributes as messages are being created or queued for sending. By detecting suspicious patterns before final transmission, the system reduces the need for extensive post-hoc analysis and enables faster intervention to prevent illegitimate messages

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If multiple attributes of text messages and device states are analyzed to identify suspicious applications, then identification accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvesuspicious application identification accuracyVSAvoidanalysis system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements a multi-functional analysis system that simultaneously evaluates text message attributes, device state parameters, and application behavior patterns using a unified framework. This universal approach allows the same system components to handle multiple detection tasks, improving identification accuracy without proportionally increasing overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the analysis of diverse parameters (message content, recipient patterns, timing, device orientation, input method state) into a cohesive detection framework. By combining these previously separate analysis functions into an integrated system, the patent achieves high identification accuracy while managing complexity through unified processing logic

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9613211B1Systems and methods for identifying suspicious text-messaging applications on mobile devices
Publication Date: 2017.04.04 GEN DIGITAL INC
  • US9613211B1 patent drawing
  • US9613211B1 patent drawing
  • US9613211B1 patent drawing

AI summary

A computer-implemented method for identifying suspicious text-messaging applications on mobile devices may include (1) identifying at least one outgoing text message on a mobile device, (2) analyzing at least one attribute of the outgoing text message identified on the mobile device, (3) determining that the outgoing text message is illegitimate based at least in part on analyzing the attribute of the outgoing text message, (4) identifying, in response to the determination, a suspicious text-messaging application that created the illegitimate outgoing text message on the mobile device, and then (5) performing, in response to the determination, at least one security action on the suspicious text-messaging application to prevent the suspicious text-messaging application from creating additional illegitimate text messages on the mobile device. Various other methods, systems, and computer-readable media are also disclosed.