Lightweight Agent Malware Detection via SMS Propagation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices are vulnerable to widespread malware propagation via SMS/MMS messaging, making it challenging to detect and monitor infected devices and malware signatures in real time, due to the scale-free nature of SMS/MMS-based malware distribution.

Innovation Solution

Deploying lightweight agents on mobile devices as contacts that communicate with an agent server, allowing malware to unknowingly send messages to the server, which analyzes these messages to generate attack signatures and estimate infection rates, enabling effective mitigation planning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If lightweight agents are deployed on mobile devices to detect malware, then malware detection capability is improved, but device complexity increases

Engineering Contradiction:
Improvemalware detection capabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the malware detection function by deploying lightweight agent components on individual mobile devices while centralizing the analysis server on the network infrastructure. This segmentation allows detection capability to be distributed across many devices without requiring each device to handle complex analysis independently, thus improving reliability while managing device complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces lightweight agents as intermediary components that sit between the malware and the analysis server. These agents intercept malware communications without requiring full detection infrastructure on each device, thereby improving detection capability while adding minimal complexity to individual devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive malware analysis is performed on the network, then malware detection accuracy is improved, but network traffic increases

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidnetwork traffic
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system extracts only the essential communication patterns and signatures from malware interactions with lightweight agents, rather than analyzing all network traffic comprehensively. This extraction approach maintains detection accuracy by focusing on key indicators while significantly reducing the overall network traffic required for analysis.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If more agents are deployed on mobile devices, then malware detection coverage is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvemalware detection coverageVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The lightweight agents are designed to be self-configuring and automatically managed through the contact list infrastructure that already exists on mobile devices. This self-service approach allows comprehensive coverage through multiple agents per device while maintaining ease of operation, as users do not need to manually configure each agent - the system leverages existing contacts and automatic updates.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9064112B2Malware detection for SMS/MMS based attacks
Publication Date: 2015.06.23 AT&T INTELLECTUAL PROPERTY I L P
  • US9064112B2 patent drawing
  • US9064112B2 patent drawing
  • US9064112B2 patent drawing

AI summary

Devices, systems, and methods are disclosed which utilize lightweight agents on a mobile device to detect message-based attacks. In exemplary configurations, the lightweight agents are included as contacts on the mobile device addressed to an agent server on a network. A malware onboard the mobile device, intending to propagate, unknowingly addresses the lightweight agents, sending messages to the agent server. The agent server analyzes the messages received from the mobile device of the deployed lightweight agents. The agent server then generates attack signatures for the malware. Using malware propagation models, the system estimates how many active mobile devices are infected as well as the total number of infected mobile devices in the network. By understanding the malware propagation, the service provider can decide how to deploy a mitigation plan on crucial locations. In further configurations, the mechanism may be used to detect message and email attacks on other devices.