Distributed Mobile Traffic Management for Malware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The surge in mobile malware incidence due to the prevalence of mobile application sharing and the ease of repackaging malware into applications on communal marketplaces poses a significant challenge for mobile device security, as existing solutions do not effectively address the detection and filtering of malicious traffic in distributed mobile traffic management systems.
Innovation Solution
A distributed mobile traffic management system that employs a local proxy and server-side proxy to categorize traffic, apply caching strategies, and detect malware by monitoring traffic patterns, allowing for the caching of content with a 'freshness' value determination and adaptive caching policies to optimize network resource utilization and enhance user experience.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If mobile applications are shared and downloaded from communal marketplaces, then application availability and variety increase, but malware incidence and security risks surge
Solution Approach 1:
The patent introduces a traffic management system with local and server-side proxies as intermediaries between mobile devices and application marketplaces. These proxies monitor, analyze, and filter network traffic to detect malware while allowing legitimate applications to be downloaded and shared, thus maintaining application availability while reducing malware incidence
Solution Approach 2:
The system performs preliminary analysis of application traffic patterns before malware can execute harmful actions. By monitoring traffic in advance and establishing baseline behavior profiles, the system can detect suspicious patterns and block malware downloads before they compromise devices, preventing rather than just responding to security incidents
2Measurement precision
If traffic monitoring and malware detection are implemented, then security detection capability improves, but system complexity and processing overhead increase
Solution Approach 1:
The patent divides the malware detection system into multiple independent components: local proxies on mobile devices, server-side proxies, traffic analysis modules, and pattern recognition systems. Each component performs a specific function in the detection chain, allowing the complex detection task to be distributed and managed more efficiently, reducing the complexity burden on any single device
Solution Approach 2:
The system employs self-learning capabilities where the traffic management system automatically analyzes traffic patterns, establishes baselines, and updates detection rules without requiring manual configuration. The system serves itself by continuously improving its detection algorithms based on observed traffic data, reducing the need for complex manual setup and maintenance
3Productivity
If content caching is implemented to optimize network resources, then network efficiency improves, but content freshness and update timeliness may be compromised
Solution Approach 1:
The patent implements dynamic caching policies where the system continuously monitors content update patterns and adjusts caching behavior in real-time. When content is determined to be static or infrequently updated, aggressive caching is applied to maximize network efficiency. When updates are detected or suspected, the system automatically invalidates or refreshes cached content to maintain freshness, creating a dynamic balance between efficiency and reliability
Solution Approach 2:
The system employs feedback mechanisms where traffic patterns and content update information are continuously monitored and fed back to the caching management module. This feedback loop allows the system to learn from actual content behavior and adjust caching strategies accordingly, ensuring that cached content remains fresh while maximizing network resource utilization through intelligent caching decisions
Data Source
Figure 1A
Figure 1B
Figure 1C
AI summary
Systems and methods for detections and filtering of malware based on traffic observations made in a distributed mobile traffic management system are disclosed. One embodiment of a method which can be implemented on a system includes, collecting information about a request or information about a response to the request initiated at the mobile device and using the information collected about the request or the response to identify or to detect malicious traffic. The information that is collected about the request or response received for the request initiated at the mobile device can be further used to determine cacheability of the response.