Tokenized Content Validation for Mobile Malware Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional signature-based methods for identifying malware in mobile networks are becoming ineffective due to the rapid emergence of new malware variants, leading to increased bandwidth usage and security issues as malware infects mobile devices and requires frequent signature updates.
Innovation Solution
An anti-malware mobile content data management system that tokenizes content data, applies a predetermined policy, validates it against predefined rules, and regenerates it into a secure format, ensuring only known-good content is transmitted over wireless networks, while optimizing bandwidth and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If signature-based methods are used to identify malware, then malware detection capability is maintained, but bandwidth is consumed by frequent signature updates and malware transmission
Solution Approach 1:
The system performs preliminary tokenization and validation of content data before it is transmitted over the network. By converting content to a generic tagged representation and validating it against known-good patterns in advance, the system prevents malware from being transmitted in the first place, eliminating the need for continuous signature updates and reducing bandwidth consumption.
Solution Approach 2:
The patent introduces an intermediary validation process between content creation and network transmission. The content management engine acts as a mediator that translates content into a generic tagged format and validates it against predefined rules, serving as a security barrier that protects the network without requiring traditional signature-based detection.
2Reliability
If traditional malware protection is implemented, then security against known threats is provided, but new malware variants can still infect mobile devices
Solution Approach 1:
Instead of trying to identify and block malware by its characteristics (traditional approach), the system inverts the approach by only allowing content that conforms to known-good patterns and structures. Any content that does not match the validated generic representation is blocked, making the system inherently resistant to new malware variants that would not conform to legitimate content patterns.
Solution Approach 2:
The system changes the fundamental parameter of malware detection from pattern-matching (trying to identify malicious characteristics) to pattern-validation (ensuring only legitimate patterns are present). By validating content against predefined rules and known-good structures, the system adapts to new threats without requiring updates to signature databases.
3Productivity
If content data is transmitted without validation, then network bandwidth is utilized efficiently, but malware can be transmitted and infect mobile devices
Solution Approach 1:
The system extracts and removes potentially malicious content from the data stream by validating each piece of content against known-good patterns before transmission. The validation process identifies and excludes harmful elements while allowing legitimate content to pass through, achieving security without significantly impacting bandwidth utilization.
4Reliability
If frequent signature updates are performed, then detection of new malware variants is improved, but precious wireless network bandwidth is consumed
Solution Approach 1:
The system performs preliminary validation of content data before transmission, preventing malware from being sent in the first place. This proactive approach eliminates the need for reactive signature updates, as the validation process inherently blocks new malware variants without requiring network bandwidth for update transmissions.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
There is provided an anti-malware mobile content data management apparatus, for use in managing content data within an input electronic file containing content data to be sent over a wireless network comprising at least one mobile device being served by the wireless network, comprising at least one tokeniser to tokenise the content data contained within the input electronic file into a tagged generic representation of the content data, a content management engine to apply a predetermined content management policy to the tagged generic representation of the content data to form content-managed tagged generic content data and a validator to create validated content-managed content data by being arranged to ensure the content-managed content data represented in the content-managed tagged generic representation conforms to any predefined limits and rules applied to each form of content data appearing in the content data of the input electronic file, wherein an output of the validator is operably coupled to the wireless network, and arranged to provide a substitute output electronic file derived from the validated content- managed content data. There is also provides an anti-malware mobile content data management method, wireless network and mobile device.