Distributed Mobile Traffic Management for Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The surge in mobile malware incidence due to the prevalence of mobile application sharing and the ease of repackaging malware into applications on communal marketplaces poses a significant challenge for mobile device security, as existing solutions do not effectively address the detection and filtering of malicious traffic in distributed mobile traffic management systems.

Innovation Solution

A distributed mobile traffic management system that employs a local proxy and server-side proxy to categorize traffic, apply caching strategies, and detect malware by monitoring traffic patterns, allowing for the caching of content with a 'freshness' value determination and adaptive caching policies to optimize network resource utilization and enhance user experience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If mobile applications are shared and downloaded from communal marketplaces, then application availability and variety increase, but malware incidence and security risks surge

Engineering Contradiction:
Improveapplication availabilityVSAvoidmalware incidence
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a traffic management system with local and server-side proxies as intermediaries between mobile devices and application marketplaces. These proxies monitor, analyze, and filter network traffic to detect malware while allowing legitimate applications to be downloaded and shared, thus maintaining application availability while reducing malware incidence

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary analysis of application traffic patterns before malware can execute harmful actions. By monitoring traffic in advance and establishing baseline behavior profiles, the system can detect suspicious patterns and block malware downloads before they compromise devices, preventing rather than just responding to security incidents

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If traffic monitoring and malware detection are implemented, then security detection capability improves, but system complexity and processing overhead increase

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent divides the malware detection system into multiple independent components: local proxies on mobile devices, server-side proxies, traffic analysis modules, and pattern recognition systems. Each component performs a specific function in the detection chain, allowing the complex detection task to be distributed and managed more efficiently, reducing the complexity burden on any single device

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system employs self-learning capabilities where the traffic management system automatically analyzes traffic patterns, establishes baselines, and updates detection rules without requiring manual configuration. The system serves itself by continuously improving its detection algorithms based on observed traffic data, reducing the need for complex manual setup and maintenance

Inventive Principle:
Principle #25Self-service

3Productivity

If content caching is implemented to optimize network resources, then network efficiency improves, but content freshness and update timeliness may be compromised

Engineering Contradiction:
Improvenetwork efficiencyVSAvoidcontent freshness
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements dynamic caching policies where the system continuously monitors content update patterns and adjusts caching behavior in real-time. When content is determined to be static or infrequently updated, aggressive caching is applied to maximize network efficiency. When updates are detected or suspected, the system automatically invalidates or refreshes cached content to maintain freshness, creating a dynamic balance between efficiency and reliability

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system employs feedback mechanisms where traffic patterns and content update information are continuously monitored and fed back to the caching management module. This feedback loop allows the system to learn from actual content behavior and adjust caching strategies accordingly, ensuring that cached content remains fresh while maximizing network resource utilization through intelligent caching decisions

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3324665B1Detection and filtering of malware based on traffic observations made in a distributed mobile traffic management system
Publication Date: 2022.03.30 SEVEN NETWORKS INC
  • EP3324665B1 patent drawingFigure 1A
  • EP3324665B1 patent drawingFigure 1B
  • EP3324665B1 patent drawingFigure 1C

AI summary

Systems and methods for detections and filtering of malware based on traffic observations made in a distributed mobile traffic management system are disclosed. One embodiment of a method which can be implemented on a system includes, collecting information about a request or information about a response to the request initiated at the mobile device and using the information collected about the request or the response to identify or to detect malicious traffic. The information that is collected about the request or response received for the request initiated at the mobile device can be further used to determine cacheability of the response.