System for continuous validation and threat protection of mobile applications

US10986113B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10986113-B2
Application numberUS-201816199128-A
CountryUS
Kind codeB2
Filing dateNov 23, 2018
Priority dateJan 24, 2018
Publication dateApr 20, 2021
Grant dateApr 20, 2021

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Described is a low power system for mobile devices that provides continuous, behavior-based security validation of mobile device applications using neuromorphic hardware. A mobile device comprises a neuromorphic hardware component that runs on the mobile device for continuously monitoring time series related to individual mobile device application behaviors, detecting and classifying pattern anomalies associated with a known malware threat in the time series related to individual mobile device application behaviors, and generating an alert related to the known malware threat. The mobile device identifies pattern anomalies in dependency relationships of mobile device inter-application and intra-applications communications, detects pattern anomalies associated with new malware threats, and isolates a mobile device application having a risk of malware above a predetermined threshold relative to a risk management policy.

First claim

Opening claim text (preview).

What is claimed is: 1. A mobile device, comprising: a neuromorphic chip mounted in the mobile device that runs continuously on the mobile device, wherein the neuromorphic chip performs operations of: monitoring time series related to individual mobile device application behaviors; detecting and classifying pattern anomalies associated with a known malware threat in the time series related to individual mobile device application behaviors; generating at least one alert related to the known malware threat; receiving the at least one alert related to the known malware threat from the neuromorphic chip; in an associative transfer entropy (ATE) stage, identifying pattern anomalies in dependency relationships of mobile device inter-application and intra-applications communications using an ATE measure; in a zero-shot learning (ZSL) stage, detecting pattern anomalies associated with new malware threats using a ZSL component; and isolating a mobile device application having a risk of malware above a predetermined threshold according to a risk management policy. 2. The mobile device as set forth in claim 1 , wherein the one or more processors further perform an operation of filtering out any false alarms of malware threats to prevent unnecessary isolation of mobile device applications in the ATE stage. 3. The mobile device as set forth in claim 1 , where in detecting pattern anomalies associated with new malware threats, the one or more processors further perform an operation of using the ZSL component for augmenting the ATE measure using semantic knowledge transfer. 4. The mobile device as set forth in claim 3 , wherein the ZSL component transfers new malware threat knowledge among a plurality of mobile devices. 5. The mobile device as set forth in claim 1 , where in identifying pattern anomalies in dependency relationships, the one or more processors further perform an operation of generating a network representation of mobile application behavior from an amount of directional information transfer between mobile device applications and effects of the directional information transfer obtained with the ATE measure. 6. A computer implemented method for continuous monitoring of mobile device applications on a mobile device, the method comprising an act of: causing a neuromorphic chip mounted in the mobile device that runs continuously on the mobile device to perform operations of: monitoring time series related to individual mobile device application behaviors; detecting and classifying pattern anomalies associated with a known malware threat in the time series related to individual mobile device application behaviors; generating at least one alert related to the known malware threat; receiving the at least one alert related to the known malware threat from the neuromorphic chip; in an associative transfer entropy (ATE) stage, identifying pattern anomalies in dependency relationships of mobile device inter-application and intra-applications communications using an ATE measure; in a zero-shot learning (ZSL) stage, detecting pattern anomalies associated with new malware threats using a ZSL component; and isolating a mobile device application having a risk of malware above a predetermined threshold according to a risk management policy. 7. The method as set forth in claim 6 , wherein the one or more processors further perform an operation of filtering out any false alarms of malware threats to prevent unnecessary isolation of mobile device applications in the ATE stage. 8. The method as set forth in claim 6 , where in detecting pattern anomalies associated with new malware threats, the one or more processors further perform an operation of using the ZSL component for augmenting the ATE measure using semantic knowledge transfer. 9. The method as set forth in claim 8 , wherein the ZSL component transfers new malware threat knowledge among a plurality of mobile devices. 10. The method as set forth in claim 6 , where in identifying pattern anomalies in dependency relationships, the one or more processors further perform an operation of generating a network representation of mobile application behavior from an amount of directional information transfer between mobile device applications and effects of the directional information transfer obtained with the ATE measure. 11. A computer program product for continuous monitoring of mobile device applications on a mobile device, the computer program product comprising: a non-transitory computer-readable medium having executable instructions encoded thereon, such that upon execution of the instructions by one or more processors, the one or more processors perform operations of: causing a neuromorphic chip mounted in the mobile device that runs continuously on the mobile device to perform operations of: monitoring time series related to individual mobile device application behaviors; detecting and classifying pattern anomalies associated with a known malware threat in the time series related to individual mobile device application behaviors; and generating at least one alert related to the known malware threat; and causing the mobile device, having one or more processors and a non-transitory computer-readable medium having executable instructions encoded thereon such that when executed, to perform operations of: receiving the at least one alert related to the known malware threat from the neuromorphic chip; in an associative transfer entropy (ATE) stage, identifying pattern anomalies in dependency relationships of mobile device inter-application and intra-applications communications using an ATE measure; in a zero-shot learning (ZSL) stage, detecting pattern anomalies associated with new malware threats using a ZSL component; and isolating a mobile device application having a risk of malware above a predetermined threshold according to a risk management policy. 12. The computer program product as set forth in claim 11 , wherein the one or more processors further perform an operation of filtering out any false alarms of malware threats to prevent unnecessary isolation of mobile device applications in the ATE stage. 13. The computer program product as set forth in claim 11 , where in detecting pattern anomalies associated with new malware threats, the one or more processors further perform an operation of using the ZSL component for augmenting the ATE measure using semantic knowledge transfer. 14. The computer program product as set forth in claim 13 , wherein the ZSL component transfers new malware threat knowledge among a plurality of mobile devices. 15. The computer program product as set forth in claim 11 , where in identifying pattern anomalies in dependency relationships, the one or more processors further perform an operation of generating a network representation of mobile application behavior from an amount of directional information transfer between mobile device applications and effects of the directional information transfer obtained with the ATE measure.

Assignees

Inventors

Classifications

  • Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems · CPC title

  • Non-supervised learning, e.g. competitive learning · CPC title

  • Traffic logging, e.g. anomaly detection · CPC title

  • Anti-malware arrangements, e.g. protection against SMS fraud or mobile malware · CPC title

  • using electronic means · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10986113B2 cover?
Described is a low power system for mobile devices that provides continuous, behavior-based security validation of mobile device applications using neuromorphic hardware. A mobile device comprises a neuromorphic hardware component that runs on the mobile device for continuously monitoring time series related to individual mobile device application behaviors, detecting and classifying pattern an…
Who is the assignee on this patent?
Hrl Lab Llc
What technology area does this patent fall under?
Primary CPC classification H04L63/1425. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Apr 20 2021 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).