Method and system for detecting malicious wireless applications
A method of managing a wireless application executing on terminal device of a wireless network. In accordance with the present invention, execution of the wireless application is monitored to detect symptoms of malicious operation. If one or more symptoms of malicious operation are detected, further operation of the wireless application is inhibited.
1 . A method of managing a wireless application executing on a terminal device of a wireless network, the method comprising steps of:
monitoring execution of the wireless application to detect symptoms of malicious operation; and
if one or more symptoms of malicious operation are detected, inhibiting further operation of the wireless application.
2 . A method as claimed in claim 1 , wherein the step of monitoring execution of the wireless application comprises steps of:
accumulating one or more metrics associated with execution of the wireless application; and
comparing each metric to a respective predetermined threshold value.
3 . A method as claimed in claim 2 , wherein the metrics comprise any one or more of:
a number of messages sent/received;
a number of processing errors;
a type of processing error; and
a message flow rate.
4 . A method as claimed in claim 1 , wherein the step of inhibiting further operation of the wireless application comprises a step of forwarding an alert message to a system administrator.
5 . A method as claimed in claim 1 , wherein the step of inhibiting further operation of the wireless application comprises a step of triggering one or more auto-corrective actions.
6 . A method as claimed in claim 5 , wherein the step of triggering one or more auto-corrective actions comprises any one or more of:
limiting bandwidth allocated to the wireless application;
limiting a maximum permissible message flow rate of the wireless application; and
executing a script on the terminal device to address a known issue of the wireless application.
7 . A method as claimed in claim 1 , wherein the step of inhibiting further operation of the wireless application comprises a step of quarantining the wireless application.
8 . A method as claimed in claim 7 , wherein the step of quarantining the wireless application comprises a step of blocking messages of the wireless application to/from the terminal device.
9 . A method as claimed in claim 8 , wherein the terminal device is hosted by an application gateway executing application logic of the wireless application, and wherein the step of quarantining the wireless application further comprises a step of freezing execution of the application logic on the application gateway.
10 . A method as claimed in claim 9 , further comprising a step of saving queued messages of the wireless application.
11 . A method as claimed in claim 7 , wherein the step of quarantining the wireless application comprises steps of:
determining whether or not an upgrade of the wireless application is available; and
if an upgrade is available, forcing installation of the upgrade on the terminal device.
12 . A method as claimed in claim 11 , further comprising a step of forcing deletion of the wireless application if an upgrade is not available.
13 . A method as claimed in claim 7 , further comprising a step of subsequently un-quarantining the wireless application.