Mobile Text Message Attribute Analysis for Malicious App Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Malicious premium-text applications on mobile devices exploit users by sending illegitimate text messages to premium-rate numbers, evading detection due to polymorphic techniques, which conventional anti-malware solutions struggle to identify.
Innovation Solution
A system and method that analyze attributes of outgoing text messages, such as physical orientation, operating mode, language, and content payload, to determine illegitimacy and identify suspicious text-messaging applications, performing security actions to prevent further illegitimate messages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional signature-based security systems are used to detect malicious applications, then detection simplicity is maintained, but detection effectiveness deteriorates due to polymorphic techniques employed by malware
Solution Approach 1:
The patent changes the detection parameters from static signature matching to dynamic behavioral analysis. Instead of checking for known malware signatures, the system monitors text message attributes (recipient numbers, timing patterns, content characteristics) and device state parameters (orientation, locked mode, input method) to detect malicious behavior patterns, thereby overcoming polymorphic evasion techniques
Solution Approach 2:
The patent replaces the mechanical signature-matching system with a behavioral analysis system that monitors and evaluates multiple parameters simultaneously. This substitution enables detection of previously undetectable polymorphic malware by focusing on operational characteristics rather than static code signatures
2Measurement precision
If comprehensive attribute analysis of text messages is performed to identify illegitimate messages, then detection accuracy is improved, but processing time increases
Solution Approach 1:
The patent applies partial action by selectively analyzing only the most critical attributes of text messages and device states. Rather than examining every possible parameter in equal depth, the system focuses on key indicators such as recipient number patterns, message timing, and device orientation, achieving high detection accuracy with reduced processing overhead
Solution Approach 2:
The system performs preliminary analysis of text message attributes as messages are being created or queued for sending. By detecting suspicious patterns before final transmission, the system reduces the need for extensive post-hoc analysis and enables faster intervention to prevent illegitimate messages
3Measurement precision
If multiple attributes of text messages and device states are analyzed to identify suspicious applications, then identification accuracy is improved, but system complexity increases
Solution Approach 1:
The patent implements a multi-functional analysis system that simultaneously evaluates text message attributes, device state parameters, and application behavior patterns using a unified framework. This universal approach allows the same system components to handle multiple detection tasks, improving identification accuracy without proportionally increasing overall system complexity
Solution Approach 2:
The patent merges the analysis of diverse parameters (message content, recipient patterns, timing, device orientation, input method state) into a cohesive detection framework. By combining these previously separate analysis functions into an integrated system, the patent achieves high identification accuracy while managing complexity through unified processing logic
Data Source
AI summary
A computer-implemented method for identifying suspicious text-messaging applications on mobile devices may include (1) identifying at least one outgoing text message on a mobile device, (2) analyzing at least one attribute of the outgoing text message identified on the mobile device, (3) determining that the outgoing text message is illegitimate based at least in part on analyzing the attribute of the outgoing text message, (4) identifying, in response to the determination, a suspicious text-messaging application that created the illegitimate outgoing text message on the mobile device, and then (5) performing, in response to the determination, at least one security action on the suspicious text-messaging application to prevent the suspicious text-messaging application from creating additional illegitimate text messages on the mobile device. Various other methods, systems, and computer-readable media are also disclosed.


