System and Method for Managing Malware Protection on Mobile Devices
A system and method for providing malware protection on client mobile platforms in a mobile network. The system and method manages the malware scanning agents of the client mobile platforms from a management server using a device independent secure management protocol. The management server downloads new malware definitions to client mobile platforms and remotely initiates malware scanning on the client mobile platforms.
1 . A method of providing malware protection on one or more client mobile platforms in communication with a management server, said method comprising:
selecting a client mobile platform having a malware scanning agent; and,
managing said malware scanning agent of said client mobile platform using a device independent secure management protocol.
2 . The method of claim 1 , wherein said managing further comprises:
selecting one or more malware definitions to be pushed to said malware scanning agent of said client mobile platform; and,
pushing said malware definitions to said client mobile platform using said device independent secure management protocol.
3 . The method of claim 2 , wherein one or more of said malware definitions is selected from the group consisting of: a malware signature, a hash of a first portion of a malware signature, a splatter set of a first portion of a malware signature, a rigorous hash of a second portion of a malware signature, a feature set from a non-executable portion of an application, a rule for applying a feature set, a data store of feature sets and rules, a probability model, a checksum, and a search string from a compressed code portion of an executable.
4 . The method of claim 2 , wherein said pushing further comprises:
synchronizing said malware definitions on said client mobile platform with a set of malware definitions on an operational support system server using a synchronization operation of said device independent secure management protocol.
5 . The method of claim 1 , wherein said managing further comprises:
initiating a malware scanning operation on said client mobile platform by the management server.
6 . The method of claim 1 , wherein said managing further comprises:
receiving a report by the management server from said client mobile platform relating to a malware-infected executable on said client mobile platform.
7 . The method of claim 6 , wherein said managing further comprises:
receiving said malware-infected executable by the management server from said client mobile platform.
8 . The method of claim 6 , further comprising:
initiating a response to said report, wherein said response is selected from the group consisting of reporting said malware-infected executable to an operational support system, and initiating a malware cleaning operation on said client mobile platform by the management server.
9 . The method of claim 1 , wherein said client mobile platform is a mobile telephone.
10 . The method of claim 1 , wherein said device independent secure management protocol is supported in firmware of said client mobile platform.
11 . A system for detecting malware on one or more client mobile platforms in communication with a management server, comprising:
a first selection means for selecting a client mobile platform having a malware scanning agent; and,
a managing means for managing said malware scanning agent of said client mobile platform using a device independent secure management protocol.
12 . The system of claim 11 , wherein said managing means further comprises:
a second selecting means for selecting one or more malware definitions to be pushed to said malware scanning agent of said client mobile platform; and,
a pushing means for pushing said malware definitions to said client mobile platform using said device independent secure management protocol.
13 . The system of claim 11 , wherein one or more of said malware definitions is selected from the group consisting of a malware signature, a hash of a first portion of a malware signature, a splatter set of a first portion of a malware signature, a rigorous hash of a second portion of a malware signature, a feature set from a non-executable portion of an application, a feature set, a rule for applying a feature set, a data store of feature sets and rules, a probability model, a checksum, and a search string from a compressed code portion of an executable.
14 . The system of claim 12 , wherein said pushing means further comprises:
a synchronizing means for synchronizing said malware definitions on said client mobile platform with a set of malware definitions on an operational support system server using a synchronization operation of said device independent secure management protocol.
15 . The system of claim 11 , wherein said managing means further comprises:
a first initiating means for initiating a malware scanning operation on said client mobile platform by the management server.
16 . The system of claim 11 , wherein said managing means further comprises:
a first receiving means for receiving a report by the management server from said client mobile platform relating to a malware-infected executable on said one client mobile platform.
17 . The system of claim 16 , wherein said managing means further comprises:
a second receiving means for receiving said malware-infected executable by the management server from said client mobile platform.
18 . The system of claim 16 , wherein said managing means further comprises:
a second initiating means for initiating a response to said report, wherein said response is selected from the group consisting of reporting said malware-infected executable to an operational support system, and initiating a malware cleaning operation on said client mobile platform by the management server.
19 . The system of claim 11 , wherein said client mobile platform is a mobile telephone.
20 . The system of claim 11 , wherein said device independent secure management protocol is supported in firmware of said client mobile platform.
21 . The system of claim 11 , further comprising:
an operational support system in communication with the management server.