Network Traffic Signature Analysis for Altered Application Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for detecting repackaged applications rely on binary analysis, which is computationally intensive and requires access to application codes, making it difficult to scale for thousands of applications and identify infected devices without code access.

Innovation Solution

A method that uses network traffic data to determine network traffic signatures for applications, monitoring traffic patterns to identify altered applications by comparing the signatures of endpoint devices, without needing access to application codes or knowledge of the application's name or purpose.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If binary analysis is used to detect repackaged applications, then detection accuracy is improved, but computational complexity and resource requirements increase significantly

Engineering Contradiction:
Improvedetection accuracyVSAvoidcomputational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical/computational system of binary analysis with a network-based observation system. Instead of analyzing application codes directly through computational methods, the system passively monitors network traffic patterns generated by applications. This substitution dramatically reduces computational complexity while maintaining detection capability, as network traffic analysis requires significantly fewer resources than binary code comparison and analysis.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If binary analysis is used to detect repackaged applications, then detection capability is improved, but scalability deteriorates when dealing with thousands of applications

Engineering Contradiction:
Improvedetection capabilityVSAvoidscalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces resource-intensive binary analysis with lightweight network traffic monitoring, enabling the system to scale to thousands of applications. Network traffic data is naturally available and requires minimal processing resources, allowing simultaneous monitoring of numerous applications without proportional increases in computational burden.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces network traffic data as an intermediary between the detection system and the applications being monitored. Instead of directly analyzing application binaries, the system observes the indirect evidence of application behavior through network communications. This intermediary approach enables scalable monitoring without requiring direct access to or intensive processing of application codes.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If binary analysis is used to detect repackaged applications, then detection precision is improved, but ease of operation deteriorates due to requiring access to application codes

Engineering Contradiction:
Improvedetection precisionVSAvoidease of operation
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent uses network traffic data as an intermediary that provides detection capabilities without requiring direct access to application codes. Network traffic is naturally observable and accessible through standard network monitoring techniques, eliminating the operational complexity of obtaining, accessing, and analyzing application binaries while maintaining effective detection of repackaged applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8973139B2Detecting altered applications using network traffic data
Publication Date: 2015.03.03 AT&T INTELLECTUAL PROPERTY I L P
  • US8973139B2 patent drawing
  • US8973139B2 patent drawing
  • US8973139B2 patent drawing

AI summary

A method, computer readable medium and apparatus for detecting an altered application are disclosed. Network traffic data is obtained for a number of endpoint devices to determine a network traffic signature for a first application. The signature comprises a set of flows within a time window. Network traffic data is monitored to determine a network traffic signature for a second application. The signature for the second application comprises the network traffic signature of the first application plus a flow to an additional address. The method determines a ratio of endpoint devices having network traffic data that matches the signature for the second application as compared to a percentage of endpoint devices having network traffic data that matches the signature for the first application. When the percentage satisfies a threshold, the method determines that the second application is the altered application comprising an altered version of the first application.