Tokenized Content Validation for Mobile Malware Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional signature-based methods for identifying malware in mobile networks are becoming ineffective due to the rapid emergence of new malware variants, leading to increased bandwidth usage and security issues as malware infects mobile devices and requires frequent signature updates.

Innovation Solution

An anti-malware mobile content data management system that tokenizes content data, applies a predetermined policy, validates it against predefined rules, and regenerates it into a secure format, ensuring only known-good content is transmitted over wireless networks, while optimizing bandwidth and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If signature-based methods are used to identify malware, then malware detection capability is maintained, but bandwidth is consumed by frequent signature updates and malware transmission

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidbandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system performs preliminary tokenization and validation of content data before it is transmitted over the network. By converting content to a generic tagged representation and validating it against known-good patterns in advance, the system prevents malware from being transmitted in the first place, eliminating the need for continuous signature updates and reducing bandwidth consumption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary validation process between content creation and network transmission. The content management engine acts as a mediator that translates content into a generic tagged format and validates it against predefined rules, serving as a security barrier that protects the network without requiring traditional signature-based detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional malware protection is implemented, then security against known threats is provided, but new malware variants can still infect mobile devices

Engineering Contradiction:
Improveprotection against known threatsVSAvoideffectiveness against new malware variants
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Instead of trying to identify and block malware by its characteristics (traditional approach), the system inverts the approach by only allowing content that conforms to known-good patterns and structures. Any content that does not match the validated generic representation is blocked, making the system inherently resistant to new malware variants that would not conform to legitimate content patterns.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The system changes the fundamental parameter of malware detection from pattern-matching (trying to identify malicious characteristics) to pattern-validation (ensuring only legitimate patterns are present). By validating content against predefined rules and known-good structures, the system adapts to new threats without requiring updates to signature databases.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If content data is transmitted without validation, then network bandwidth is utilized efficiently, but malware can be transmitted and infect mobile devices

Engineering Contradiction:
Improvenetwork bandwidth utilizationVSAvoidmalware transmission risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system extracts and removes potentially malicious content from the data stream by validating each piece of content against known-good patterns before transmission. The validation process identifies and excludes harmful elements while allowing legitimate content to pass through, achieving security without significantly impacting bandwidth utilization.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If frequent signature updates are performed, then detection of new malware variants is improved, but precious wireless network bandwidth is consumed

Engineering Contradiction:
Improvedetection of new malware variantsVSAvoidwireless network bandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system performs preliminary validation of content data before transmission, preventing malware from being sent in the first place. This proactive approach eliminates the need for reactive signature updates, as the validation process inherently blocks new malware variants without requiring network bandwidth for update transmissions.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3053318B1Anti-malware mobile content data management apparatus and method
Publication Date: 2019.04.10 GLASSWALL IP
  • EP3053318B1 patent drawingFigure 1
  • EP3053318B1 patent drawingFigure 2
  • EP3053318B1 patent drawingFigure 3

AI summary

There is provided an anti-malware mobile content data management apparatus, for use in managing content data within an input electronic file containing content data to be sent over a wireless network comprising at least one mobile device being served by the wireless network, comprising at least one tokeniser to tokenise the content data contained within the input electronic file into a tagged generic representation of the content data, a content management engine to apply a predetermined content management policy to the tagged generic representation of the content data to form content-managed tagged generic content data and a validator to create validated content-managed content data by being arranged to ensure the content-managed content data represented in the content-managed tagged generic representation conforms to any predefined limits and rules applied to each form of content data appearing in the content data of the input electronic file, wherein an output of the validator is operably coupled to the wireless network, and arranged to provide a substitute output electronic file derived from the validated content- managed content data. There is also provides an anti-malware mobile content data management method, wireless network and mobile device.