Malware Detection via Sensor Context Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current malware detection methods are reactive and resource-intensive, often failing to detect infections until they have already compromised numerous devices, leading to significant financial and human resource expenditures for network and service providers.

Innovation Solution

A system utilizing sensor data from devices to determine context and detect malware and anomalies by analyzing data from accelerometers, gyroscopes, compasses, light sensors, and proximity sensors, allowing for real-time identification of suspicious activity and potential malware infections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If deep packet inspection technologies are used to detect infected devices, then detection effectiveness is improved, but resource consumption and complexity increase

Engineering Contradiction:
Improvemalware detection effectivenessVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces sensor data as an intermediary indicator that indirectly reflects device state and potential malware infection. Instead of directly inspecting packet contents, the system uses sensor readings (accelerometer, gyroscope, light sensor, etc.) as mediators to infer whether the device is being used normally or compromised by malware, thereby reducing the complexity of direct traffic analysis while maintaining detection effectiveness

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical/system-level approach of deep packet inspection with a sensor-based contextual analysis approach. By substituting direct network traffic examination with sensor data analysis, the system achieves malware detection with lower computational overhead and reduced complexity, as sensor data processing is less resource-intensive than deep packet inspection

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If deep packet inspection is implemented for malware detection, then detection accuracy improves, but energy consumption increases

Engineering Contradiction:
Improvemalware detection accuracyVSAvoiddevice energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

Sensor data serves as an energy-efficient intermediary that provides indirect evidence of device state without requiring intensive processing. The system monitors sensor readings (accelerometer, gyroscope, compass, light sensor, proximity sensor) that consume minimal power compared to deep packet inspection, while still enabling accurate inference of device usage patterns and potential malware infection

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent utilizes low-cost, high-frequency sensor data that can be collected continuously with minimal energy impact. These sensor readings are inexpensive to acquire and process compared to deep packet inspection, allowing for continuous monitoring that maintains detection accuracy while consuming significantly less energy

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Productivity

If reactive malware detection is used, then resource expenditure is reduced initially, but financial loss increases when infections occur

Engineering Contradiction:
Improvedetection response efficiencyVSAvoidfinancial and human resource loss
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The patent implements preliminary detection by continuously analyzing sensor data to identify anomalies before they result in significant damage. By proactively monitoring device context and detecting unusual patterns early, the system enables timely intervention and mitigation, preventing the escalation of infections that would otherwise require expensive reactive responses

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system establishes a feedback loop where sensor data continuously informs device state assessment, which then triggers appropriate responses. This real-time feedback mechanism allows the system to adapt and respond to emerging threats dynamically, improving detection efficiency while reducing overall resource loss through early intervention

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9680854B2Malware and anomaly detection via activity recognition based on sensor data
Publication Date: 2017.06.13 AT&T INTELLECTUAL PROPERTY I L P
  • US9680854B2 patent drawing
  • US9680854B2 patent drawing
  • US9680854B2 patent drawing

AI summary

A system for malware and anomaly detection via activity recognition based on sensor is disclosed. The system may analyze sensor data collected during a selected time period from one or more sensors that are associated with a device. Once the sensor data is analyzed, the system may determine a context of the device when the device is in a connected state. The system may determine the context of the device based on the sensor data collected during the selected time period. The system may also determine if traffic received or transmitted by the device during the connected state is in a white list. Furthermore, the system may transmit an alert if the traffic is determined to not be in the white list or if the context determined for the device indicates that the context does not correlate with the traffic.