IP Library Patent Application 17238854
Patent Application
App. No. 17/238,854

ANOMALY DETECTION AND CHARACTERIZATION IN APP PERMISSIONS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/238,854
Abstract

Anomalous or unexpected system permissions in applications in a computing environment are identified by generating a statistical model at least in part from application permissions granted across a plurality of application types. One or more of the application permissions granted across a plurality of application types are identified as potentially unexpected dangerous permissions. The statistical model is used to determine whether a target application has at least one potentially dangerous permission that is not statistically likely for a target application type of the target application.

Claims (28)

1 . A method of identifying anomalous system permissions in applications in a computing environment, comprising:

generating a statistical model at least in part from application permissions granted across a plurality of application types;

identifying one or more of the application permissions granted across a plurality of application types as potentially dangerous permissions; and

determining, using the generated statistical model, whether a target application has at least one potentially dangerous permission that is not statistically likely for a target application type of the target application.

2 . The method of identifying anomalous system permissions in applications in a computing environment of claim 1 , further comprising indicating to a user the determination of whether a target application has at least one potentially dangerous permission that is not statistically likely.

3 . The method of identifying anomalous system permissions in applications in a computing environment of claim 2 , wherein indicating to a user the determination of whether a target application has at least one potentially dangerous permission that is not statistically likely comprises indicating a metric or score indicating the degree of statistically unlikely dangerous permissions for the target application.

4 . The method of identifying anomalous system permissions in applications in a computing environment of claim 2 , wherein indicating to a user the determination of whether a target application has at least one potentially dangerous permission that is not statistically likely comprises providing an explanation indicating one or more statistically unlikely dangerous permissions for the target application.

5 . The method of identifying anomalous system permissions in applications in a computing environment of claim 1 , wherein determination of whether a dangerous permission is statistically likely for a target application type of a target application comprises determining whether a threshold probability of the dangerous permission being present in the target application type is met or exceeded.

6 . The method of identifying anomalous system permissions in applications in a computing environment of claim 1 , wherein generating a statistical model comprises observing the presence or absence of the plurality of application permissions in the plurality of application types.

7 . The method of identifying anomalous system permissions in applications in a computing environment of claim 1 , wherein generating a statistical model comprises observing the top or most likely requested permissions for the plurality of application types.

8 . The method of identifying anomalous system permissions in applications in a computing environment of claim 1 , wherein generating a statistical model comprises calculating a term frequency-inverse document frequency (TF-IDF) score for the plurality of application permissions in the plurality of application types.

9 . The method of identifying anomalous system permissions in applications in a computing environment of claim 1 , wherein the target application type of the target application comprises a determined application type, the determined application type determined by using the statistical model to evaluate application permissions of the target application.

10 . The method of identifying anomalous system permissions in applications in a computing environment of claim 9 , further comprising using the statistical model to determine whether the determined application type of the target application differs from a claimed application type of the target application.

11 . The method of identifying anomalous system permissions in applications in a computing environment of claim 9 , wherein determining the determined application type by using the statistical model to evaluate application permissions of the target application comprises determining one or more application types that are most statistically similar to the target application based on the generated statistical model of application permissions in application types.

12 . A computing device operable to detect anomalous system permissions in applications, comprising:

a processor and a memory; and

a machine-readable medium with instructions stored thereon, the instructions when executed on the processor operable to cause the computing device to:

generate a statistical model at least in part from application permissions granted across a plurality of application types;

identify one or more of the application permissions granted across a plurality of application types as potentially dangerous permissions; and

determine, using the generated statistical model, whether a target application has at least one potentially dangerous permission that is not statistically likely for a target application type of the target application.

13 . The computing device of claim 12 , the instructions when executed further operable to cause the computing device to indicate to a user the determination of whether a target application has at least one potentially dangerous permission that is not statistically likely.

14 . The computing device of claim 13 , wherein indicating to a user the determination of whether a target application has at least one potentially dangerous permission that is not statistically likely comprises at least one of indicating a metric or score indicating the degree of statistically unlikely dangerous permissions for the target application and providing an explanation indicating one or more statistically unlikely dangerous permissions for the target application.

15 . The computing device of claim 12 , wherein determination of whether a dangerous permission is statistically likely for a target application type of a target application comprises determining whether a threshold probability of the dangerous permission being present in the target application type is met or exceeded.

16 . The computing device of claim 12 , wherein generating a statistical model comprises at least one of observing the presence or absence of the plurality of application permissions in the plurality of application types and observing the top or most likely requested permissions for the plurality of application types.

17 . The computing device of claim 12 , wherein generating a statistical model comprises calculating a term frequency-inverse document frequency (TF-IDF) score for the plurality of application permissions in the plurality of application types.

18 . The computing device of claim 12 , wherein the target application type of the target application comprises a determined application type, the determined application type determined by using the statistical model to evaluate application permissions of the target application.

19 . The computing device of claim 18 , the instructions when executed further operable to cause the computing device to determine, using the statistical model, whether the determined application type of the target application differs from a claimed application type of the target application.

20 . The computing device of claim 18 , wherein determining the determined application type by using the statistical model to evaluate application permissions of the target application comprises determining one or more application types that are most statistically similar to the target application based on the generated statistical model of application permissions in application types.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2025
From: GEN DIGITAL AMERICAS S.R.O.
To: GEN DIGITAL INC.
Reel/Frame 071771/0767 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2025
From: AVAST SOFTWARE S.R.O.
To: GEN DIGITAL AMERICAS S.R.O.
Reel/Frame 071777/0341 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 23, 2021
From: ALPEROVICH, GALINA; JASEK, OTAKAR
To: AVAST SOFTWARE S.R.O.
Reel/Frame 056022/0913 →