Server-Based Mobile Malware Protection via Remote Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile communications devices lack a universal, platform-agnostic system for efficiently monitoring, scanning, and protecting against malware, as existing solutions are device-specific and resource-constrained, and current network-level protections are inadequate for managing diverse applications and encrypted services.

Innovation Solution

A server-based system that provides real-time malware protection and analysis for multiple mobile devices, collecting and analyzing device and application data to identify and remediate malicious software, using hashing and metadata to reduce network traffic and optimize data collection, and aggregating data from multiple devices to provide comprehensive security assessments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a universal, platform-agnostic malware protection system is implemented, then malware detection capability is improved, but device complexity and resource consumption increase

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a server-based intermediary system that handles the complex malware analysis and detection tasks remotely. The server receives data from mobile devices, performs sophisticated malware scanning and behavior analysis, then returns results to the devices. This mediator approach allows universal malware protection without burdening individual device resources or increasing device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces local mechanical scanning processes on mobile devices with remote server-based analysis. Instead of running resource-intensive antivirus software directly on mobile devices, the system substitutes this with network-based scanning where the server performs the heavy lifting of malware detection, returning only essential results to the device.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If comprehensive application monitoring and data collection is performed, then security assessment accuracy is improved, but network traffic and data transmission increase

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidnetwork traffic
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The patent extracts only the essential and minimal set of data elements needed for accurate malware detection and security assessment. Rather than transmitting all application data, the system identifies and extracts specific metadata, file hashes, and behavioral indicators that are sufficient for reliable security evaluation, thereby reducing network traffic while maintaining assessment accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements partial monitoring where the server collects and analyzes only the portion of application data that is necessary for malware detection. The system performs selective data gathering focused on security-relevant attributes rather than comprehensive monitoring of all application activities, optimizing the balance between detection accuracy and network efficiency.

Inventive Principle:
Principle #16Partial or excessive action

3Speed

If real-time malware analysis and remediation is provided, then protection speed is improved, but server processing load and resource consumption increase

Engineering Contradiction:
Improveprotection speedVSAvoidserver processing load
Core Design Contradiction:
SpeedVSPower

Solution Approach 1:

The patent implements preliminary malware analysis by pre-scanning applications before they are fully installed or executed on mobile devices. The server performs initial security assessments, risk evaluations, and behavioral analysis in advance, so that when applications are deployed, the majority of security checks have already been completed, enabling rapid real-time protection with minimal server load during actual operation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9294500B2System and method for creating and applying categorization-based policy to secure a mobile communications device from access to certain data objects
Publication Date: 2016.03.22 LOOKOUT INC
  • US9294500B2 patent drawing
  • US9294500B2 patent drawing
  • US9294500B2 patent drawing

AI summary

A server creates categorization-based application policies and selects a specific policy to send to a mobile communications device. In one embodiment, the mobile communication device applies the categorization-based application policy received from the server to information about a data object (e.g., application) that the device wants to access (or has accessed). Based on the application of the categorization-based policy, the device may be permitted to access the data object or the device may not be permitted to access the data object.