Mobile Threat Detection With Dynamically Chained Security Primitives
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile devices are vulnerable to malicious threats due to the time gap between threat identification and the application of new detection processes, as updating mobile applications often takes several weeks, leaving devices exposed to risks.
Innovation Solution
A mobile device maintains a file of primitives, each performing a security function, which can be dynamically chained based on instructions from a security service to form a detection process for newly identified threats, reducing the need for application updates and ensuring compatibility and efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If mobile applications are updated to apply new detection processes for newly identified threats, then detection capability is improved, but the time delay of several weeks leaves devices vulnerable
Solution Approach 1:
The patent segments the detection process into independent primitives that can be individually updated and dynamically chained together. Each primitive represents a modular detection component that can be updated separately, allowing the system to apply new detection capabilities without requiring a complete application update, thus reducing deployment delay while maintaining detection reliability
Solution Approach 2:
The patent implements dynamic chaining of primitives where the detection process can be reconfigured in real-time based on new threats. The system dynamically assembles detection pipelines by chaining primitives together at runtime, enabling rapid response to newly identified threats without the static constraints of traditional application updates, thereby reducing deployment delay
2Productivity
If primitives are dynamically chained to form detection processes, then deployment speed is improved, but system complexity increases
Solution Approach 1:
The patent creates a universal primitive framework where a small set of reusable detection primitives can be combined to form various detection processes. These primitives serve multiple functions and can be chained in different configurations to address different threats, reducing the need for numerous specialized components and thereby managing system complexity while enabling rapid deployment of new detection capabilities
Solution Approach 2:
The patent introduces a primitive chaining mechanism that acts as an intermediary layer between the security service and the detection execution. This intermediary manages the complexity of assembling detection processes by providing standardized interfaces for chaining primitives, simplifying the system architecture while enabling flexible and rapid deployment of detection workflows
3Reliability
If application updates are performed to ensure security, then detection stability is improved, but the weeks-long update cycle creates security gaps
Solution Approach 1:
The patent performs preliminary actions by pre-approving and storing detection primitives in a primitive repository before they are needed. The security service can prepare and validate detection primitives in advance, and they are immediately available for chaining when threats are identified, eliminating the delay between threat identification and detection deployment while maintaining stability through pre-validation
Solution Approach 2:
The system enables self-service by allowing the mobile device to dynamically assemble detection processes using locally stored primitives without requiring external application updates. The device can independently respond to new threats by chaining existing primitives, maintaining detection stability while eliminating security gaps caused by update delays
Data Source
AI summary
System and methods are disclosed herein for dynamic detection of malicious activities on a mobile device. The mobile device maintains a file that is executable on the mobile device. The file includes a plurality of primitives, with each primitive comprising a piece of detection logic that, when executed, performs a security function on the mobile device. The mobile device receives instructions from a security service to chain a subset of primitives. The subset of primitives, when chained together, forms a detection process for a malicious activity newly identified by the security service. The system and methods then chain the subset of primitives based on instructions received from the security service and identify the malicious activity by executing the chained subset of primitives.


