Network Traffic Signature Analysis for Altered Application Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for detecting repackaged applications rely on binary analysis, which is computationally intensive and requires access to application codes, making it difficult to scale for thousands of applications and identify infected devices without code access.
Innovation Solution
A method that uses network traffic data to determine network traffic signatures for applications, monitoring traffic patterns to identify altered applications by comparing the signatures of endpoint devices, without needing access to application codes or knowledge of the application's name or purpose.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If binary analysis is used to detect repackaged applications, then detection accuracy is improved, but computational complexity and resource requirements increase significantly
Solution Approach 1:
The patent replaces the mechanical/computational system of binary analysis with a network-based observation system. Instead of analyzing application codes directly through computational methods, the system passively monitors network traffic patterns generated by applications. This substitution dramatically reduces computational complexity while maintaining detection capability, as network traffic analysis requires significantly fewer resources than binary code comparison and analysis.
2Reliability
If binary analysis is used to detect repackaged applications, then detection capability is improved, but scalability deteriorates when dealing with thousands of applications
Solution Approach 1:
The patent replaces resource-intensive binary analysis with lightweight network traffic monitoring, enabling the system to scale to thousands of applications. Network traffic data is naturally available and requires minimal processing resources, allowing simultaneous monitoring of numerous applications without proportional increases in computational burden.
Solution Approach 2:
The patent introduces network traffic data as an intermediary between the detection system and the applications being monitored. Instead of directly analyzing application binaries, the system observes the indirect evidence of application behavior through network communications. This intermediary approach enables scalable monitoring without requiring direct access to or intensive processing of application codes.
3Measurement precision
If binary analysis is used to detect repackaged applications, then detection precision is improved, but ease of operation deteriorates due to requiring access to application codes
Solution Approach 1:
The patent uses network traffic data as an intermediary that provides detection capabilities without requiring direct access to application codes. Network traffic is naturally observable and accessible through standard network monitoring techniques, eliminating the operational complexity of obtaining, accessing, and analyzing application binaries while maintaining effective detection of repackaged applications.
Data Source
AI summary
A method, computer readable medium and apparatus for detecting an altered application are disclosed. Network traffic data is obtained for a number of endpoint devices to determine a network traffic signature for a first application. The signature comprises a set of flows within a time window. Network traffic data is monitored to determine a network traffic signature for a second application. The signature for the second application comprises the network traffic signature of the first application plus a flow to an additional address. The method determines a ratio of endpoint devices having network traffic data that matches the signature for the second application as compared to a percentage of endpoint devices having network traffic data that matches the signature for the first application. When the percentage satisfies a threshold, the method determines that the second application is the altered application comprising an altered version of the first application.


