IP Library › Granted Patent US 9,264,445
Granted Patent B2
US 9,264,445 · App. 14/480,234 · Granted Feb 16, 2016

Mobile application security assessment

Inventors: Steven T. Archer (Dallas, TX); Peter S. Tippett (Great Falls, VA); Gregory P. Crawford (Arlington Heights, IL); Paul Hubbard (San Diego, CA); Gina M. Ganley (Millstone Township, NJ); Jo Ann Joels (Tulsa, OK)
Assignee: Verizon Patent and Licensing Inc.
H04L63/1433G06F21/00G06F21/577H04L63/20G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,264,445
App. No.
14/480,234
Granted
Feb 16, 2016
Kind
B2
Abstract

The security of mobile applications may be assessed and used to enhance the security of mobile devices. In one example, a method may include determining security scores of one or more mobile applications, the security scores defining a level of security risk corresponding to the one or more mobile applications. The method may further include receiving a policy relating to mobile applications that are permitted to be used by the mobile device, the policy including a threshold security score value; and receiving the requested security scores. The method may further include restricting use of selected ones of the one or more mobile applications when a security score corresponding to the one or more mobile applications is below the threshold security score value.

Claims (105)

1. A method comprising:

requesting, by a mobile device, one or more security scores of one or more mobile applications,

the one or more security scores defining a level of security risk corresponding to the one or more mobile applications, and

a security score, of the one or more security scores, being based on:

a first security review performed on a mobile application of the one or more mobile applications,

the first security review resulting in a modified initial security score including a value within a first range, and

a second security review performed on the mobile application,

the second security review being different than the first security review, and

the second security review resulting in a further modified initial security score including a value within a second range,

 the second range including an upper limit that is greater than an upper limit of the first range;

receiving, by the mobile device, a policy relating to mobile applications that are permitted to be used by the mobile device,

the policy including a threshold security score value;

receiving, by the mobile device, the requested one or more security scores; and

restricting, by the mobile device, use of a selected mobile application, of the one or more mobile applications, when a security score, of the one or more received security scores, corresponding to the selected mobile application is below the threshold security score value.

2. The method of claim 1 , where the restricting the use of the selected mobile application includes:

preventing the selected mobile application from being installed on the mobile device;

preventing the selected mobile application from being executed by the mobile device;

providing a user of the mobile device with a notification when the selected mobile application is executed by the mobile device; or

uninstalling the selected mobile application from the mobile device.

3. The method of claim 1 , further comprising:

providing a graphical indication of a plurality of mobile applications that are installed on the mobile device and corresponding security scores of the installed plurality of mobile applications.

4. The method of claim 1 , where the requested one or more security scores correspond to security scores of mobile applications installed at the mobile device.

5. The method of claim 1 , where the requested one or more security scores include security scores determined, at least in part, through a manual analysis of the mobile applications.

6. The method of claim 1 , further comprising:

providing, for presentation, the requested one or more security scores.

7. The method of claim 1 , where

when requesting the one or more security scores, the method includes:

requesting a first security score, of the one or more security scores, for a first mobile application of the one or more mobile applications; and

requesting a second security score, of the one or more security scores, for a second mobile application of the one or more mobile applications,

when receiving the requested one or more security scores, the method includes:

receiving the first security score, and

receiving the second security score, and

the method further includes:

providing, for presentation, the received first security score and the received second security score.

8. A device comprising:

a processor to:

request one or more security scores for one or more mobile applications,

the one or more security scores defining a level of security risk corresponding to the one or more mobile applications, and

a security score, of the one or more security scores, being based on:

a first security review performed on a mobile application of the one or more mobile applications,

 the first security review resulting in a modified initial security score including a value within a first range, and

a second security review performed on the mobile application,

 the second security review being different than the first security review, and

 the second security review resulting in a further modified initial security score including a value within a second range,

 the second range including an upper limit that is greater than an upper limit of the first range;

receive a policy relating to mobile applications that are permitted to be used by the device,

the policy including a threshold security score value;

receive the requested one or more security scores; and

restrict use of a selected mobile application, of the one or more mobile applications, when a security score, of the one or more received security scores, corresponding to the selected mobile application is below the threshold security score value.

9. The device of claim 8 , where, when restricting the use of the selected mobile application, the processor is to:

prevent the selected mobile application from being installed on the device;

prevent the selected mobile application from being executed by the device;

provide a user of the device with a notification when the selected mobile application is executed by the device; or

uninstall the selected mobile application from the device.

10. The device of claim 8 , where the processor is further to:

provide a graphical indication of all a plurality of mobile applications that are installed on the device and corresponding security scores of the installed plurality of mobile applications.

11. The device of claim 8 , where the requested one or more security scores correspond to security scores of mobile applications installed at the device.

12. The device of claim 8 , where the requested one or more security scores include security scores determined, at least in part, through a manual analysis of the mobile applications.

13. The device of claim 8 , where the processor is further to:

provide, for presentation, the requested one or more security scores.

14. The device of claim 8 , where

the processor, when requesting the one or more security scores, is to:

request a first security score, of the one or more security scores, for a first mobile application of the one or more mobile applications; and

request a second security score, of the one or more security scores, for a second mobile application of the one or more mobile applications,

the processor, when receiving the requested one or more security scores, is to:

receive the first security score, and

receive the second security score, and

the processor is further to:

provide, for presentation, the received first security score and the received second security score.

15. A non-transitory computer readable medium storing instructions, the instructions comprising:

one or more instructions which, when executed by a processor of a device, cause the processor to:

request one or more security scores for one or more applications,

the one or more security scores defining a level of security risk corresponding to the one or more applications, and

a security score, of the one or more security scores, being based on:

a first security review performed on an application of the one or more applications,

 the first security review resulting in a modified initial security score including a value within a first range, and

a second security review performed on the application,

 the second security review being different than the first security review, and

 the second security review resulting in a further modified initial security score including a value within a second range,

 the second range including an upper limit that is greater than an upper limit of the first range;

receive a policy relating to applications that are permitted to be used by the device,

the policy including a threshold security score value;

receive the requested one or more security scores; and

restrict use of a selected application, of the one or more applications, when a security score, of the one or more received security scores, corresponding to the selected application is below the threshold security score value.

16. The non-transitory computer readable medium of claim 15 , where the one or more instructions to restrict the use of the selected application include:

one or more instructions to prevent the selected application from being installed on the device;

one or more instructions to prevent the selected application from being executed by the device;

one or more instructions to provide a user of the device with a notification when the selected application is executed by the device; or

one or more instructions to uninstalling the selected application from the device.

17. The non-transitory computer readable medium of claim 15 , where the instructions further comprise:

one or more instructions to provide a graphical indication of a plurality of applications that are installed on the device and corresponding security scores of the installed plurality of applications.

18. The non-transitory computer readable medium of claim 15 , where

the requested one or more security scores correspond to security scores of applications installed at the device, and

the requested one or more security scores include security scores determined, at least in part, through a manual analysis of the applications.

19. The non-transitory computer readable medium of claim 15 , where the instructions further comprise:

one or more instructions to provide, for presentation, the requested one or more security scores.

20. The non-transitory computer readable medium of claim 15 , where

the one or more instructions to request the one or more security scores include:

one or more instructions to request a first security score, of the one or more security scores, for a first application of the one or more applications; and

one or more instructions to request a second security score, of the one or more security scores, for a second application of the one or more applications,

the one or more instructions to receive the requested one or more security scores include:

one or more instructions to receive the first security score, and

one or more instructions to receive the second security score, and

the instructions further include:

one or more instructions to provide, for presentation, the received first security score and the received second security score.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 8, 2014
From: ARCHER, STEVEN T.; TIPPETT, PETER S.; CRAWFORD, GREGORY P.; HUBBARD, PAUL; GANLEY, GINA M.; JOELS, JO ANN
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 033692/0958 →
Continuity (2)
Division 13477489 · May 22, 2012
Related Publication 20140380413A1 · Dec 25, 2014