Stalkerware Detection via Window Overlay Interception

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Stalkerware applications, used for surveillance and stalking, are difficult to detect and mitigate as they often operate in stealth mode, disabling antivirus protection, and existing security measures may alert attackers rather than effectively notifying users.

Innovation Solution

A computer-implemented method and system that detects stalkerware applications running in the foreground and overlays them with a window, intercepting user inputs to prevent configuration, using a security configuration that extends accessibility services and installs system permissions, while delaying notifications to avoid alerting attackers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If stalkerware applications operate in stealth mode to avoid detection, then the application can monitor users without being noticed, but security software cannot detect and mitigate the stalkerware

Engineering Contradiction:
Improvestealth capabilityVSAvoiddetection difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent changes the visual appearance of the stalkerware application window by overlaying a transparent or translucent window with a different color scheme or visual characteristics, making the hidden application visible to users while maintaining the underlying surveillance functionality

Inventive Principle:
Principle #32Color changes

Solution Approach 2:

The patent introduces a window overlay as an intermediary layer between the user and the stalkerware application, which acts as a mediator to alert users about the hidden surveillance without directly exposing the stalkerware's malicious nature

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If security software issues immediate notifications upon detecting stalkerware, then users are informed of the threat, but attackers are alerted and may remove the security software

Engineering Contradiction:
Improveuser notificationVSAvoidattacker retaliation
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary action by first visually alerting users through window overlay before issuing formal notifications, allowing users to become aware of the threat in a gradual manner that reduces attacker suspicion

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses periodic or staged notification approaches, where alerts are issued in stages rather than all at once, allowing users to become aware of the threat while minimizing the risk of triggering attacker retaliation

Inventive Principle:
Principle #19Periodic action

3Reliability

If stalkerware applications are made completely invisible to users, then surveillance is undetectable, but users cannot be notified of the monitoring

Engineering Contradiction:
Improvestealth mode effectivenessVSAvoiduser awareness
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies visual changes to the application window using transparent or translucent overlays with distinct color schemes that make the hidden surveillance application visible to users while maintaining the underlying monitoring functionality

Inventive Principle:
Principle #32Color changes

Solution Approach 2:

The patent adds a new visual dimension by overlaying a semi-transparent window layer on top of the stalkerware application, creating a multi-layered interface that simultaneously maintains stealth functionality and provides user awareness

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11366903B1Systems and methods to mitigate stalkerware by rendering it useless
Publication Date: 2022.06.21 GEN DIGITAL INC
  • US11366903B1 patent drawing
  • US11366903B1 patent drawing
  • US11366903B1 patent drawing

AI summary

The disclosed computer-implemented method for mitigating stalkerware by rendering it useless is performed, at least in part, by a computing device comprising at least one processor. The method includes detecting, by the at least one processor in accordance with a security configuration of the computing device, a stalkerware application running in a foreground of the computing device. The method also includes overlaying, by the at least one processor in accordance with the security configuration, the stalkerware application with a window in response to the detecting. The method further includes performing a security action by intercepting one or more user inputs to the stalkerware application via the window, thereby preventing user configuration of the stalkerware application. Various other methods, systems, and computer-readable media are also disclosed.