Network Security System Identifying Rogue Applications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems are ineffective in identifying and addressing rogue applications in communications networks, which pose security threats and operational challenges due to their inability to pinpoint specific malicious apps causing suspicious behavior.

Innovation Solution

A network security system that utilizes a combination of Network Behavioural Analysis (NBA) and app inventory data to generate a data structure correlating behavioral signatures with installed apps, filtering common apps, and using machine learning to identify apps most likely responsible for suspicious behavior, thereby isolating rogue applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network operators monitor and analyze device behavior to detect suspicious activities, then network security is improved, but the ability to identify specific rogue applications is insufficient

Engineering Contradiction:
Improvenetwork securityVSAvoididentification of specific rogue applications
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments the identification process into multiple components: device-level behavior monitoring, application-level inventory collection, and correlation analysis. By dividing the monitoring task into device behavior analysis and app inventory matching, the system achieves both broad security coverage and precise rogue app identification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary correlation mechanism that connects device behavior data with application inventory data. This intermediary layer analyzes the relationship between suspicious behaviors and installed applications, enabling precise identification of rogue apps without requiring direct access to application code or secrets.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If operators revoke applications suspected of rogue behavior, then network security is improved, but false revocation of legitimate applications may occur

Engineering Contradiction:
Improvenetwork securityVSAvoidfalse revocation of legitimate applications
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where the system continuously monitors device behavior before, during, and after application revocation. By analyzing whether suspicious behaviors persist or cease after revocation, the system can verify the accuracy of its identification and adjust future revocation decisions, reducing false positives while maintaining security.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If operators manually review applications to determine which should be revoked, then decision accuracy may be improved, but the process becomes too slow to address rapidly spreading threats

Engineering Contradiction:
Improvedecision accuracyVSAvoidresponse speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent enables the system to automatically perform the review and identification process through machine learning algorithms that analyze device behavior patterns and match them with application inventories. The system serves itself by autonomously identifying rogue applications and recommending revocation actions without requiring manual operator intervention for each case, thus maintaining high decision accuracy while achieving rapid response times.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2959707B1Network security system and method
Publication Date: 2020.08.26 ADAPTIVE MOBILE SECURITY
  • EP2959707B1 patent drawingFigure 1
  • EP2959707B1 patent drawingFigure 2
  • EP2959707B1 patent drawingFigure 3

AI summary

The invention provides a network security method and system for use in a communications network, said network comprising a plurality of devices adapted to communicate over the network, at least one device capable of downloading or uploading an application over the network, said system comprises means for data capture on the network by receiving data from a first data source and a second data source; means for analysing comprising means for correlating data arising from network behaviour of at least one device obtained from the first data source and data from a second data source and means for generating a data structure; and based on said analyses of the generated data structure, means for identifying applications on devices which are behaving suspiciously.