System and method for assessing vulnerability of a mobile device

US9467463B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9467463-B2
Application numberUS-201213601409-A
CountryUS
Kind codeB2
Filing dateAug 31, 2012
Priority dateSep 2, 2011
Publication dateOct 11, 2016
Grant dateOct 11, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system and method for assessing vulnerability of a mobile device including at a remote analysis cloud service, receiving at least one vulnerability assessment request that includes an object identifier for an operative object of a mobile computing device, wherein the vulnerability assessment request originates from the mobile computing device; identifying a vulnerability assessment associated with the identifier of the operative object; and communicating the identified vulnerability assessment to the mobile computing device.

First claim

Opening claim text (preview).

We claim: 1. A method for assessing vulnerability of a mobile device comprising: at a vulnerability assessment component (VAC) operable on the mobile device and prior to receiving a vulnerability assessment request at a remote analysis cloud service, compiling at least one object identifier for the vulnerability assessment request, wherein compiling the at least one object identifier includes compiling and sending at least one additional superfluous object identifier; communicating the vulnerability assessment request to the remote analysis cloud service; at the remote analysis cloud service, receiving the at least one vulnerability assessment request that includes the object identifier for an operative object of the mobile computing device, wherein the vulnerability assessment request originates from the mobile computing device; identifying a vulnerability assessment associated with the identifier of the operative object; and communicating the identified vulnerability assessment to the mobile computing device. 2. The method of claim 1 , wherein the object identifier includes at least a portion of executable code, and wherein identifying a vulnerability assessment includes disassembling the executable code into native machine code and detecting unpatched vulnerabilities. 3. The method of claim 2 , wherein detecting unpatched vulnerabilities includes detecting privilege escalation vulnerabilities. 4. The method of 1 , wherein the at least one compiled object identifier is a plurality of object identifiers that includes an executable code segment, a device identifier, and component version identifier. 5. The method of claim 1 , wherein communicating the vulnerability assessment request includes multiplexing a plurality of vulnerability assessment requests into a single communication to the remote analysis cloud service; and wherein receiving at least one vulnerability assessment request at the analysis cloud service includes demultiplexing a vulnerability assessment request into a plurality of vulnerability assessment requests. 6. The method of claim 1 , further comprising at the VAC, receiving an executable probe; and performing at least a partial vulnerability assessment according to the executable probe prior to communicating the vulnerability assessment request to the cloud service. 7. The method of claim 6 , wherein performing at least a partial vulnerability assessment includes checking a cache of vulnerability assessments. 8. The method of claim 1 , further comprising the VAC initiating installation of a vulnerability patch to relevant vulnerabilities identified in the vulnerability assessment results. 9. The method of claim 1 , wherein the VAC is a standalone application controlled by a user. 10. The method of claim 1 , wherein the VAC is a component integrated into an application of the device; and further comprising communicating the identified vulnerability assessment from the VAC to the application of the device. 11. A method for assessing vulnerability of a mobile device comprising: at a vulnerability assessment component (VAC) operable on the mobile device and prior to receiving a plurality of vulnerability assessment requests at a remote analysis cloud service, compiling at least one object identifier for the plurality of vulnerability assessment requests, wherein compiling the at least one object identifier includes compiling and sending at least one additional superfluous object identifier; communicating the plurality of vulnerability assessment requests to the remote analysis cloud service; at the remote analysis cloud service, receiving the plurality of vulnerability assessment requests, wherein the vulnerability assessment request includes the at least one object identifier for an operative object of the mobile computing device, and wherein the vulnerability assessment request originates from the mobile computing device; for each vulnerability assessment request, identifying a vulnerability assessment associated with the identifier of the operative object; and communicating the identified vulnerability assessment to the associated mobile computing device. 12. The method of claim 11 , further comprising in a cloud based storage system, storing identified vulnerability assessments according to the associated object identifier. 13. The method of claim 12 , wherein storing identified vulnerability assessments are stored according to a hash of the associated object identifier. 14. The method of claim 13 , further comprising at a vulnerability assessment component (VAC) operable on a mobile computing device and prior to receiving a vulnerability assessment request at the remote analysis cloud service, compiling a hash of at least one object identifier for the vulnerability assessment request; and communicating a first vulnerability assessment request including the hash to the analysis cloud service; and wherein identifying vulnerability assessment includes querying the cloud based storage system for an identified vulnerability assessment associated with the hash. 15. The method of claim 12 , further comprising at a platform control interface, compiling a mapping of identified vulnerability and associated object identifiers stored in the cloud based storage system and generating collective vulnerability data for the plurality of mobile computing devices. 16. The method of claim 15 , further comprising at the platform control interface, pushing a vulnerability fix to the at least one mobile device in response to generated collective vulnerability data.

Assignees

Inventors

Classifications

  • Vulnerability analysis · CPC title

  • Detection or prevention of fraud · CPC title

  • Anti-malware arrangements, e.g. protection against SMS fraud or mobile malware · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9467463B2 cover?
A system and method for assessing vulnerability of a mobile device including at a remote analysis cloud service, receiving at least one vulnerability assessment request that includes an object identifier for an operative object of a mobile computing device, wherein the vulnerability assessment request originates from the mobile computing device; identifying a vulnerability assessment associated…
Who is the assignee on this patent?
Oberheide Jon, Song Dug, Goodman Adam, and 1 more
What technology area does this patent fall under?
Primary CPC classification H04L63/1433. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Oct 11 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).