IP Library Granted Patent US 10,820,205
Granted Patent B1
US 10,820,205 · App. 16/287,165 · Granted Oct 27, 2020

Systems and methods for performing reputation-based identification of applications on unmanaged mobile devices

Inventor: Josh Opos (Studio City, CA)
Assignee: NortonLifeLock, Inc.
H04W12/08H04L67/26H04W12/0027G06F21/00G06N20/00H04L9/00H04W12/00505
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,820,205
App. No.
16/287,165
Granted
Oct 27, 2020
Kind
B1
Abstract

The disclosed computer-implemented method for performing reputation-based identification of applications on unmanaged mobile devices may include (i) receiving screen content displayed on an unmanaged mobile device, (ii) analyzing, by a machine-learning algorithm, the screen content to identify a set of applications stored on the unmanaged mobile device, (iii) querying a reputation service for reputation data associated with each of the applications, the reputation data including a security classification describing potential threats against the unmanaged mobile device, (iv) associating the reputation data with each of the applications, and (v) generating a notification comprising a list of the applications and the associated reputation data for utilization by the unmanaged mobile device to perform one or more protective actions against the potential threats. Various other methods, systems, and computer-readable media are also disclosed.

Claims (39)

1. A computer-implemented method for performing reputation-based identification of applications on unmanaged mobile devices, at least a portion of the method being performed by a computing device comprising at least one processor, the method comprising:

receiving, by the one or more computing devices, screen content displayed on an unmanaged mobile device, wherein receiving the screen content comprises receiving a broadcast of the screen content from a device scan initiated by a client application executing on the unmanaged mobile device;

analyzing, by a machine-learning algorithm executing on the one or more computing devices, the screen content to identify a set of applications stored on the unmanaged mobile device;

querying, by the one or more computing devices, a reputation service for reputation data associated with each of the applications, the reputation data including a security classification describing potential threats against the unmanaged mobile device;

associating, by the one or more computing devices, the reputation data with each of the applications; and

generating, by the one or more computing devices, a notification comprising a list of the applications and the associated reputation data for utilization by the unmanaged mobile device to perform one or more protective actions against the potential threats.

2. The computer-implemented method of claim 1 , wherein analyzing the screen content comprises:

analyzing a media stream comprising the screen content; and

identify the applications stored on the unmanaged mobile device from the screen content in the media stream.

3. The computer-implemented method of claim 1 , wherein generating the notification comprises creating a push message comprising the list of the applications and the associated reputation data for displaying on the unmanaged mobile device.

4. The computer-implemented method of claim 1 , wherein the reputation data comprises data describing a malware threat associated with one or more of the applications.

5. The computer-implemented method of claim 1 , wherein the reputation data comprises data describing a device power resource threat associated with one or more of the applications.

6. The computer-implemented method of claim 1 , wherein the reputation data comprises data describing a safe application status associated with one or more of the applications.

7. The computer-implemented method of claim 1 , wherein the screen content comprises one or more application icons scanned from at least one page of a home display screen on the unmanaged mobile device.

8. The computer-implemented method of claim 1 , wherein the screen content comprises a list of applications loaded on the unmanaged mobile device scanned from a settings menu displayed on the unmanaged mobile device.

9. The computer-implemented method of claim 1 , wherein the unmanaged mobile device comprises a client computing device excluding one or more mobile device management features.

10. A system for performing reputation-based identification of applications on unmanaged mobile devices, the system comprising:

at least one physical processor;

physical memory comprising a plurality of modules and computer-executable instructions that, when executed by the physical processor, cause the physical processor to:

receive, by a receiving module, screen content displayed on an unmanaged mobile device, wherein the receiving module receives the screen content by receiving a broadcast of the screen content from a device scan initiated by a client application executing on the unmanaged mobile device;

analyze, by an analysis module executing a machine learning algorithm, the screen content to identify a set of applications stored on the unmanaged mobile device;

query, by a query module, a reputation service for reputation data associated with each of the applications, the reputation data including a security classification describing potential threats against the unmanaged mobile device;

associate, by the query module, the reputation data with each of the applications; and

generate, by a security module, a notification comprising a list of the applications and the associated reputation data for utilization by the unmanaged mobile device to perform one or more protective actions against the potential threats.

11. The system of claim 10 , wherein the analysis module analyzes the screen content by:

analyzing a media stream comprising the screen content; and

identify the applications stored on the unmanaged mobile device from the screen content in the media stream.

12. The system of claim 10 , wherein the security module generates the notification by creating a push message comprising the list of the applications and the associated reputation data for displaying on the unmanaged mobile device.

13. The system of claim 10 , wherein the reputation data comprises data describing a malware threat associated with one or more of the applications.

14. The system of claim 10 , wherein the reputation data comprises data describing a device power resource threat associated with one or more of the applications.

15. The system of claim 10 , wherein the reputation data comprises data describing a safe application status associated with one or more of the applications.

16. The system of claim 10 , wherein the screen content comprises one or more application icons scanned from at least one page of a home display screen on the unmanaged mobile device.

17. The system of claim 10 , wherein the screen content comprises a list of applications loaded on the unmanaged mobile device scanned from a settings menu displayed on the unmanaged mobile device.

18. A non-transitory computer-readable medium comprising one or more computer-executable instructions that, when executed by at least one processor of a computing device, cause the computing device to:

receive screen content displayed on an unmanaged mobile device, wherein the screen content is received by receiving a broadcast of the screen content from a device scan initiated by a client application executing on the unmanaged mobile device;

analyze, by a machine-learning algorithm executing on the computing device, the screen content to identify applications stored on the unmanaged mobile device;

query a reputation service for reputation data associated with each of the applications, the reputation data including a security classification describing potential threats against the unmanaged mobile device;

associate the reputation data with each of the applications; and

generate a notification comprising a list of the applications and the associated reputation data for utilization by the unmanaged mobile device to perform one or more protective actions against the potential threats.

Assignments (6)
CHANGE OF NAME Recorded Feb 6, 2023
From: NORTONLIFELOCK INC.
To: GEN DIGITAL INC.
Reel/Frame 062714/0605 →
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Feb 14, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 051935/0228 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2019
From: OPOS, JOSH
To: SYMANTEC CORPORATION
Reel/Frame 048463/0040 →
Cited By (1)
US 12,688,305