Self-Protecting Code via Embedded Security Modules
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile devices are vulnerable to viruses, malware, and spyware due to security flaws in apps, making it difficult to detect and protect against malicious software, especially as many apps contain embedded malicious code that can access sensitive user information without user knowledge.
Innovation Solution
A system and method for providing self-protecting code through embedded security modules in apps that perform automated and dynamic scans to detect and remove malicious code, using identification engines and scanning engines to identify and protect apps within a secured formation, ensuring the integrity of each app and safeguarding user information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional scanning software is used to detect malicious code, then detection capability is provided, but detection accuracy is insufficient and many malicious apps remain undetected
Solution Approach 1:
The patent divides the detection system into multiple specialized engines: identification engine to recognize app identities and relationships, scanning engine to detect malicious code, and behavior engine to analyze app behaviors. Each engine focuses on specific detection tasks, improving overall detection accuracy compared to traditional single-system scanning approaches.
Solution Approach 2:
The system dynamically adjusts detection strategies based on real-time analysis. The behavior engine monitors app executions and dynamically identifies suspicious patterns, while the system adapts its scanning depth and methods based on risk assessment, enabling more accurate detection of sophisticated malware that static analysis would miss.
2Reliability
If comprehensive scanning of all apps is performed, then detection capability is improved, but device performance and user experience deteriorate
Solution Approach 1:
The system performs partial scanning by focusing resources on high-risk apps identified through the identification engine and behavior analysis. Instead of uniformly scanning all apps, it applies intensive detection only where needed based on risk assessment, maintaining security while preserving device performance.
Solution Approach 2:
The system implements periodic scanning schedules with varying intensity. Low-risk apps are scanned less frequently or with lighter methods, while high-risk apps undergo more thorough periodic checks. This periodic approach maintains security coverage without continuously burdening device resources.
3Difficulty of detecting and measuring
If static analysis is used to review app source code, then detection of malicious code is provided, but detection accuracy varies greatly and many exploits remain undetected
Solution Approach 1:
The system transitions from static analysis to dynamic behavior analysis. The behavior engine executes apps in a controlled environment and monitors their actual runtime behaviors, capturing malicious actions that static code review cannot detect. This dynamic approach significantly improves detection accuracy for sophisticated malware.
Solution Approach 2:
The patent introduces a behavior analysis layer as an intermediary between the app and the detection system. This behavior engine acts as a mediator that observes app executions and translates complex malicious behaviors into detectable patterns, improving the system's ability to identify sophisticated exploits that direct static analysis would miss.
4Reliability
If users manually install and perform security scans, then some protection is provided, but most users lack awareness to install and perform necessary security checks
Solution Approach 1:
The system is designed to operate autonomously without requiring user intervention. The identification engine automatically identifies apps, the scanning engine autonomously detects threats, and the behavior engine self-manages analysis. This self-service capability ensures continuous protection even when users lack security awareness or do not actively engage with security features.
Solution Approach 2:
The system implements continuous feedback loops where detection results automatically trigger response actions. When threats are detected, the system automatically notifies users and can initiate remediation without requiring users to understand security concepts or manually perform scans. This feedback mechanism bridges the gap between sophisticated detection capabilities and average user capabilities.
Data Source
AI summary
Embodiments of the presently disclosed invention provide a method and system for providing self-protecting code. In particular, embodiments provide security modules that may be embedded in a plurality of apps installed on one or more devices. In one embodiment, a central app security system is provided that facilitates the deployment and management of the formation of apps embedded with the security module. With the help of the embedded security modules, the plurality of apps, which may be referred hereinafter as a “secured formation” of apps, perform automated and dynamic scans of other apps within the same formation to ensure the integrity of each app is maintained. Each app in the secured formation may also detect viruses, malware, spyware, and other malicious software contained in the secured formation and perform curative operations in response. In this manner, the apps in any given secured formation collectively ensure that sensitive user information is protected.


