Method and a system for identifying compromised devices in an application infrastructure
Methods, a server, and an electronic device for identifying compromised user devices in an application infrastructure. One of the methods comprises: in response to receiving, from a given user device, a data container including a unique identifier of the given user device: updating a then current value of the unique identifier in a database, thereby generating an updated value of the unique identifier; and transmitting the updated value of the unique identifier to the given user device; in response to receiving information of the given user device being compromised: generating a then updated value of the unique identifier, indicative of the given user device being compromised; and transmitting a then updated data container with the then updated value of the unique identifier to the given user device, thereby enabling other servers of the application infrastructure to identify the given user device as being compromised.
1 . A computer-implemented method for identifying compromised user devices in an application infrastructure associated with an application family, the application infrastructure including a first application and a second application installed on the given user device, the first application being associated with a first server, and the second application being associated with a second server, the method comprising:
initiating the first application on the given user device;
initiating the second application on the given user device, determining that the first and second applications are from the application family, the determining comprising:
receiving a list of family applications installed on the given user device;
determining presence of a data container associated with the application family in service data of each one of the first and second applications;
retrieving, from the service data of the first application, the data container including a current value of a unique identifier of the given user device;
transmitting the data container to the first server associated with the first application for updating the current value of the unique identifier, thereby causing the first server to:
generate an updated value of the unique identifier, indicative of the given user device being compromised; and
transmit, to the given user device, the data container including the updated value of the unique identifier of the given user device;
receiving, from the first server, the data container including the updated value of the unique identifier;
storing the data container in the service data of both the first and second applications; and
transmitting, to the second server associated with the second application, the data container including the updated value of the unique identifier of the given user device, to enable the second server to identify the given user device as being compromised.
2 . The method of claim 1 , further comprising excluding system applications from the list of the family applications.
3 . The method of claim 2 , wherein the determining the presence of the data container associated with the application family comprises executing a content provider application associated with the application family.
4 . An electronic device for identifying compromised user devices in an application infrastructure associated with an application family, the electronic device being configured for executing: a first application and a second application installed on the electronic device, the first application being associated with a first server, and the second application being associated with a second server, the electronic device comprising:
at least one processor and at least one non-transitory computer-readable memory storing executable instructions, which, when executed by the at least one processor, cause the electronic device to:
initiate the first application on the electronic device;
initiate the second application on the electronic device;
determine that the first and second applications are from the application family, by:
receiving a list of family applications installed on the electronic device;
determining presence of a data container associated with the application family in service data of each one of the first and second applications;
retrieve, from the service data of the first application, the data container including a current value of a unique identifier of the electronic device;
transmit the data container to the first server associated with the first application for updating the current value of the unique identifier, thereby causing the first server to:
generate an updated value of the unique identifier, indicative of the electronic device being compromised; and
transmit, to the electronic device, the data container including the updated value of the unique identifier of the electronic device;
receive, from the first server, the data container including the updated value of the unique identifier;
store the data container in the service data of both the first and second applications; and
transmit, to the second server associated with the second application, the data container including the updated value of the unique identifier of the electronic device, to enable the second server to identify the electronic device as being compromised.