IP Library Granted Patent US 9,596,257
Granted Patent B2
US 9,596,257 · App. 14/851,619 · Granted Mar 14, 2017

Detection and prevention of installation of malicious mobile applications

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,596,257
App. No.
14/851,619
Granted
Mar 14, 2017
Kind
B2
Abstract

A combination of shim and back-end server applications may be used to identify and block the installation of malicious applications on mobile devices. In practice, a shim application registers with a mobile device's operating system to intercept application installation operations. Upon intercepting an attempted installation operation, the shim application identifies the application seeking to be installed, generates a key uniquely identifying the application, and transmits the key over a network connection to a back-end server. The back-end server may be configured to crawl the Internet to identify malicious applications and compile and maintain a database of such applications. Upon receiving a key from the shim application, the back-end server can search its database to locate a matching application and, if found, respond to the mobile device with the application's status (e.g., malicious or not). The shim application can utilize this information to allow or block installation of the application.

Claims (40)

1. At least one non-transitory computer readable medium comprising computer executable instructions stored thereon that, when executed, cause at least one processor to:

receive an application identifier from a mobile device over a network connection, the application identifier comprising a key uniquely identifying an application for which a call to an installation operation has been intercepted on the mobile device, wherein the key is a hash computed from at least a portion of a mobile application setup file associated with the application;

utilize at least a portion of the application identifier to determine a status of the application from a database of records including statuses of a plurality of analyzed applications, wherein the application identifier comprises metadata associated with the application; and

send the status of the application and one or more properties of the application to the mobile device over the network connection, wherein the one or more properties indicate functionality of the application to be enabled when the application is installed on the mobile device.

2. The at least one non-transitory computer readable medium of claim 1 , wherein the computer executable instructions, when executed, cause the at least one processor to:

search the database for a record corresponding to the key to determine the status of the application.

3. The at least one non-transitory computer readable medium of claim 1 , wherein the computer executable instructions, when executed, cause the at least one processor to:

utilize the metadata to determine the status of the application from the records in the database if no record corresponding to the key exists in the database.

4. The at least one non-transitory computer readable medium of claim 3 , wherein the metadata indicates a source of the application, wherein the computer executable instructions, when executed, cause the at least one processor to:

determine the application is malicious based, at least in part, on a threshold corresponding to other applications associated with the source and known to be malicious.

5. The at least one non-transitory computer readable medium of claim 1 , wherein the computer executable instructions, when executed, cause the at least one processor to:

extract, from the application identifier, the key and the metadata associated with the application.

6. The at least one non-transitory computer readable medium of claim 5 , wherein the extracting is to include decrypting the application identifier.

7. The at least one non-transitory computer readable medium of claim 1 , wherein the application identifier is received via a short message service (SMS) to a predefined telephone number.

8. The at least one non-transitory computer readable medium of claim 1 , wherein the application identifier is received via one of dual-tone multi-frequency signaling or interactive voice response (IVR) messaging if communication is initiated between the mobile device and a predefined telephone number.

9. An apparatus, the apparatus comprising:

at least one hardware processor; and

a server application coupled to the at least one hardware processor and when running on the at least one hardware processor, the server application is to:

receive an application identifier from a mobile device over a network connection, the application identifier comprising a key uniquely identifying an application for which a call to an installation operation has been intercepted on the mobile device, wherein the key is a hash computed from at least a portion of a mobile application setup file associated with the application;

utilize at least a portion of the application identifier to determine a status of the application from a database of records including statuses of a plurality of analyzed applications, wherein the application identifier comprises metadata associated with the application; and

send the status of the application and one or more properties of the application to the mobile device over the network connection, wherein the one or more properties indicate a functionality of the application to be enabled when the application is installed on the mobile device.

10. The apparatus of claim 9 , wherein when running on the at least one hardware processor, the server application is to:

search the database for a record corresponding to the key to determine the status of the application.

11. The apparatus of claim 9 , wherein when running on the at least one hardware processor, the server application is to:

utilize the metadata to determine the status of the application from the records in the database if no record corresponding to the key exists in the database.

12. The apparatus of claim 11 , wherein when running on the at least one hardware processor, the server application is to:

determine the application is malicious based, at least in part, on a threshold corresponding to other applications known to be malicious and associated with a source of the application, wherein the metadata indicates the source of the application.

13. The apparatus of claim 9 , wherein when running on the at least one hardware processor, the server application is to:

extract, from the application identifier, the key and the metadata associated with the application.

14. The apparatus of claim 13 , wherein the extracting is to include decrypting the application identifier.

15. A method, comprising:

receiving, at a server application utilizing at least one hardware processor, an application identifier from a mobile device over a network connection, the application identifier comprising a key uniquely identifying an application for which a call to an installation operation has been intercepted on the mobile device, wherein the key is a hash computed from at least a portion of a mobile application setup file associated with the application;

utilizing at least a portion of the application identifier to determine a status the application from a database of records including statuses of a plurality of analyzed applications, wherein the application identifier comprises metadata associated with the application; and

sending the status of the application and one or more properties of the application to the mobile device over the network connection, wherein the one or more properties indicate a functionality of the application to be enabled when the application is installed on the mobile device.

16. The method of claim 15 , further comprising:

searching the database for a record corresponding to the key to determine the status of the application.

17. The method of claim 15 , further comprising:

utilizing the metadata to determine the status of the application from the records in the database if no record corresponding to the key exists in the database.

18. The method of claim 17 , further comprising:

determining the application is malicious based, at least in part, on a threshold corresponding to other applications known to be malicious and associated with a source of the application, wherein the metadata indicates the source of the application.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →