Server-Based Mobile App Assessment for Malware Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile communication devices lack a universal, hardware and software agnostic system for real-time malware protection and monitoring, as existing solutions are device-specific and unable to effectively safeguard against various types of malicious applications and data, especially in network environments with encrypted services.

Innovation Solution

A server-based system that collects and analyzes data from mobile communication devices to provide security services, including identification, analysis, and removal of undesired applications, using device data and application data to assess and remediate threats without relying on local processing resources, allowing for continuous updates and network-level protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a universal platform-agnostic system is implemented for real-time malware protection, then protection coverage and adaptability improve, but device complexity and resource requirements increase

Engineering Contradiction:
Improveprotection coverageVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a server as an intermediary that performs the complex malware analysis and protection functions remotely. The server receives application data from mobile devices, performs comprehensive analysis including behavior monitoring and malware detection, then sends back protection decisions. This mediator approach allows universal protection coverage without burdening individual devices with complex security systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces local mechanical scanning and analysis processes on mobile devices with remote server-based analysis. Instead of requiring devices to run resource-intensive antivirus software locally, the system substitutes this with network-based analysis where the server performs all heavy processing, and devices only need to communicate application data and receive decisions.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Use of energy by moving object

If remote server-based analysis is used instead of local processing, then resource usage on devices decreases, but network dependency increases

Engineering Contradiction:
Improvedevice resource usageVSAvoidnetwork dependency
Core Design Contradiction:
Use of energy by moving objectVSReliability

Solution Approach 1:

The patent extracts the resource-intensive malware analysis and protection functions from mobile devices and relocates them to a remote server. The device's role is reduced to collecting application data, transmitting it to the server, and receiving protection decisions. This extraction dramatically reduces local resource consumption while maintaining comprehensive security analysis capabilities on the server.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9344431B2System and method for assessing an application based on data from multiple devices
Publication Date: 2016.05.17 LOOKOUT INC
  • US9344431B2 patent drawing
  • US9344431B2 patent drawing
  • US9344431B2 patent drawing

AI summary

Disclosed herein is a system and method for efficiently gathering information about applications for mobile communications devices (e.g., smartphones, netbooks, and tablets) and using that information to produce assessments of the applications. To gather information, a server may send a request for application data to a mobile communications device. In response, the server may receive some but not all of the first-requested application data. The server may then a second request for application data to a second mobile communications device that also has access to the application. The server may receive application data from the second mobile communications device, and store the received first- and second-requested application data. The server then uses the stored application data to assess the application.