Systems and methods for identifying malware

US8984632B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-8984632-B1
Application numberUS-201213619978-A
CountryUS
Kind codeB1
Filing dateSep 14, 2012
Priority dateSep 14, 2012
Publication dateMar 17, 2015
Grant dateMar 17, 2015

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A computer-implemented method for identifying malware is described. Event data is received from a mobile device. The event data including events performed on the mobile device and a list of one or more applications. The list of the one or more applications is compared with at least one additional list of applications received from at least one additional mobile device. An application in common across the lists of applications is identified. The identification of the application in common to is transmitted to the mobile device.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method for identifying malware, comprising: receiving event data from a first mobile device, the event data from the first mobile device comprising events performed on the first mobile device and a list of one or more applications executing when the events on the first mobile device are performed, wherein the events performed on the first mobile device comprise a deletion of a first record indicating a transmission or receipt of a first short message service (SMS) message at the first mobile device, and wherein the list of applications comprise applications that initiated an installation process within a predetermined time period before the events are performed on the first mobile device; receiving event data from a second mobile device, the event data from the second mobile device comprising events performed on the second mobile device and a list of one or more applications executing when the events on the second mobile device are performed, wherein the events performed on the second mobile device comprise a deletion of a second record indicating a transmission or receipt of a SMS message at the second mobile device; comparing the list of the one or more applications received from the first mobile device with the list of the one or more applications received from the second mobile device; determining whether deletion of the first record and the second record occurs upon transmission or receipt of each respective SMS message; upon determining deletion of the first record and the second record occurs upon transmission or receipt of each respective SMS message, identifying an application in common across the lists of applications; and transmitting the identification of the application in common to the first mobile device. 2. The method of claim 1 , wherein the events performed on the first mobile device comprise a transmission or reception of a SMS message. 3. The method of claim 1 , wherein the events performed on the mobile device comprise an alteration to a log of activities performed on the first mobile device. 4. The method of claim 1 , wherein the list of applications comprises applications that are installed within a predetermined time period before the events are performed on the first mobile device. 5. The method of claim 1 , further comprising assigning a confidence score to the identified application based in part on a number of additional mobile devices that transmitted event data. 6. The method of claim 1 , further comprising assigning a confidence score to the identified application based in part on a past history of behavior of the first mobile device. 7. A computing device configured to identify malware, comprising: a processor; memory in electronic communication with the processor; instructions stored in the memory, the instructions being executable by a processor to: receive event data from a first mobile device, the event data from the first mobile device comprising events performed on the first mobile device and a list of one or more applications executing when the events on the first mobile device are performed, wherein the events performed on the first mobile device comprise a deletion of a first record indicating a transmission or receipt of a first short message service (SMS) message at the first mobile device, and wherein the list of applications comprise applications that initiated an installation process within a predetermined time period before the events are performed on the first mobile device; receive event data from a second mobile device, the event data from the second mobile device comprising events performed on the second mobile device and a list of one or more applications executing when the events on the second mobile device are performed, wherein the events performed on the second mobile device comprise a deletion of a second record indicating a transmission or receipt of a SMS message at the second mobile device; compare the list of the one or more applications received from the first mobile device with the list of the one or more applications received from the second mobile device; determine whether deletion of the first record and the second record occurs upon transmission or receipt of each respective SMS message; upon determining deletion of the first record and the second record occurs upon transmission or receipt of each respective SMS message, identify an application in common across the lists of applications; and transmit the identification of the application in common to the first mobile device. 8. The computing device of claim 7 , wherein the events performed on the first mobile device comprise a transmission or reception of a message. 9. The computing device of claim 7 , wherein the events performed on the first mobile device comprise an alteration to a log of activities performed on the mobile device. 10. The computing device of claim 7 , wherein the list of applications comprises applications that are installed within a predetermined time period before the events are performed on the first mobile device. 11. The computing device of claim 7 , wherein the instructions are further executable by the processor to assign a confidence score to the identified application based in part on a number of additional mobile devices that transmitted event data. 12. The computing device of claim 7 , wherein the instructions are further executable by the processor to assign a confidence score to the identified application based in part on a past history of behavior of the first mobile device. 13. A computer-program product for identifying malware, the computer-program product comprising a non-transitory computer-readable medium having instructions thereon, the instructions being executable by a processor to: receive event data from a first mobile device, the event data from the first mobile device comprising events performed on the first mobile device and a list of one or more applications executing when the events on the first mobile device are performed, wherein the events performed on the first mobile device comprise a deletion of a first record indicating a transmission or receipt of a first short message service (SMS) message at the first mobile device, and wherein the list of applications comprise applications that initiated an installation process within a predetermined time period before the events are performed on the first mobile device; receive event data from a second mobile device, the event data from the second mobile device comprising events performed on the second mobile device and a list of one or more applications executing when the events on the second mobile device are performed, wherein the events performed on the second mobile device comprise a deletion of a second record indicating a transmission or receipt of a SMS message at the second mobile device; compare the list of the one or more applications received from the first mobile device with the list of the one or more applications received from the second mobile device; determine whether deletion of the first record and the second record occurs upon transmission or receipt of each respective SMS message; upon determining deletion of the first record and the second record occurs upon transmission or receipt of each respective SMS message, identify an application in common across the lists of applications; and transmit the identification of the application in common to the first mobile device. 14. The computer-program product of claim 13 , wherein the events performed on the first mobile device comprise a transmission or reception of a SMS message.

Assignees

Inventors

Classifications

  • Tracking the activity of the user (network monitoring arrangements H04L43/00; recording of computer activity G06F11/34) · CPC title

  • H04W4/14Primary

    Short messaging services, e.g. short message services [SMS] or unstructured supplementary service data [USSD] · CPC title

  • Anti-malware arrangements, e.g. protection against SMS fraud or mobile malware · CPC title

  • Traffic logging, e.g. anomaly detection · CPC title

  • involving the movement of software or configuration parameters  (network booting or remote initial program loading [RIPL] G06F9/4416) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US8984632B1 cover?
A computer-implemented method for identifying malware is described. Event data is received from a mobile device. The event data including events performed on the mobile device and a list of one or more applications. The list of the one or more applications is compared with at least one additional list of applications received from at least one additional mobile device. An application in common …
Who is the assignee on this patent?
Laffoon Barry, Wawda Abubakar, Mao Jun, and 2 more
What technology area does this patent fall under?
Primary CPC classification H04W4/14. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Mar 17 2015 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).