IP Library › Granted Patent US 12,375,923
Granted Patent B1
US 12,375,923 · App. 18/651,423 · Granted Jul 29, 2025

Dynamic detection for mobile device security

Inventors: Ryan Chazen (South Africa, ZA); Asaf Peleg (Kadima-Zoran, IL)
Assignee: Zimperium, Inc.
H04W12/121
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,375,923
App. No.
18/651,423
Granted
Jul 29, 2025
Kind
B1
Abstract

System and methods are disclosed herein for dynamic detection of malicious activities on a mobile device. The mobile device maintains a file that is executable on the mobile device. The file includes a plurality of primitives, with each primitive comprising a piece of detection logic that, when executed, performs a security function on the mobile device. The mobile device receives instructions from a security service to chain a subset of primitives. The subset of primitives, when chained together, forms a detection process for a malicious activity newly identified by the security service. The system and methods then chain the subset of primitives based on instructions received from the security service and identify the malicious activity by executing the chained subset of primitives.

Claims (58)

1. A method comprising:

maintaining, by a mobile device, a plurality of primitives, wherein each primitive comprises a piece of detection logic;

receiving instructions, by the mobile device, from a server, to chain a subset of the plurality of primitives together, wherein the subset of primitives, when chained together, forms a detection process for a malicious activity, the malicious activity including a risk of an attack to the mobile device and identified based on activity relating to the risk performed by a plurality of mobile devices, the instructions received based on the server identifying a vulnerability of the mobile device to the malicious activity and transmitting an indication of the vulnerability to one or more of the plurality of mobile devices; and

configuring the mobile device to detect the malicious activity by chaining the subset of the plurality of primitives based on the instructions.

2. The method of claim 1 , wherein the malicious activity is associated with a mobile application on the mobile device, and wherein detecting the malicious activity does not require updating the mobile application.

3. The method of claim 1 , further comprising:

receiving a second set of instructions that are defined by a provider of an application associated with the mobile device that is vulnerable to the malicious activity, wherein chaining the subset of the plurality of primitives is further based on the second set of instructions.

4. The method of claim 1 , further comprising:

extracting a set of feature vectors based on data associated with the mobile device;

performing feature transformation to the set of feature vectors;

applying a classifier to the transformed set of feature vectors, wherein the classifier is received from the server or another device; and

determining the malicious activity based on results from running the classifier.

5. The method of claim 4 , wherein the classifier is received in conjunction with the instructions from the server and wherein the classifier is compatible with the instructions.

6. The method of claim 4 , further comprising:

storing the set of feature vectors on the mobile device, wherein the set of feature vectors is associated with a first version of a mobile application;

detecting an update to the mobile application to a second version; and

reusing a subset of the set of feature vectors in the detection process for the second version of the mobile application.

7. The method of claim 1 , further comprising:

determining a runtime associated with each primitive of the subset of primitives;

storing results for one or more primitives of the subset of primitives based on the respective runtime; and

reusing the results for the one or more primitives in future detection process.

8. The method of claim 1 , wherein chaining the subset of primitives is based on an operating system associated with the mobile device.

9. A non-transitory computer-readable storage medium storing executable computer instructions that, when executed by one or more processors, cause the one or more processors to perform operations, the instructions comprising instructions to:

maintain, by a mobile device, a plurality of primitives, wherein each primitive comprises a piece of detection logic;

receive instructions, by the mobile device, from a server, to chain a subset of the plurality of primitives together, wherein the subset of primitives, when chained together, forms a detection process for a malicious activity, the malicious activity including a risk of an attack to the mobile device and identified based on activity relating to the risk performed by a plurality of mobile devices, the instructions received based on the server identifying a vulnerability of the mobile device to the malicious activity and transmitting an indication of the vulnerability to one or more of the plurality of mobile devices; and

configure the mobile device to detect the malicious activity by chaining the subset of the plurality of primitives based on the instructions.

10. The non-transitory computer-readable medium of claim 9 , wherein the malicious activity is associated with a mobile application on the mobile device, and wherein detecting the malicious activity does not require updating the mobile application.

11. The non-transitory computer-readable medium of claim 9 , the instructions further comprising instructions to:

receive a second set of instructions that are defined by a provider of an application associated with the mobile device that is vulnerable to the malicious activity, wherein chaining the subset of the plurality of primitives is further based on the second set of instructions.

12. The non-transitory computer-readable medium of claim 9 , the instructions further comprising instructions to:

extract a set of feature vectors based on data associated with the mobile device;

perform feature transformation to the set of feature vectors;

apply a classifier to the transformed set of feature vectors, wherein the classifier is received from the server or another device; and

determine the malicious activity based on results from running the classifier.

13. The non-transitory computer-readable medium of claim 12 , wherein the classifier is received in conjunction with the instructions from the server and wherein the classifier is compatible with the instructions.

14. The non-transitory computer-readable medium of claim 12 , the instructions further comprising instructions to:

store the set of feature vectors on the mobile device, wherein the set of feature vectors is associated with a first version of a mobile application;

detect an update to the mobile application to a second version; and

reuse a subset of the set of feature vectors in the detection process for the second version of the mobile application.

15. The non-transitory computer-readable medium of claim 9 , the instructions further comprising instructions to:

determine a runtime associated with each primitive of the subset of primitives;

store results for one or more primitives of the subset of primitives based on the respective runtime; and

reuse the results for the one or more primitives in future detection process.

16. The non-transitory computer-readable medium of claim 9 , wherein chaining the subset of primitives is based on an operating system associated with the mobile device.

17. A system comprising:

memory with instructions encoded thereon; and

one or more processors that, when executing the instructions, are caused to perform operations comprising:

maintaining, by a mobile device, a plurality of primitives, wherein each primitive comprises a piece of detection logic;

receiving instructions, by the mobile device, from a server, to chain a subset of the plurality of primitives together, wherein the subset of primitives, when chained together, forms a detection process for a malicious activity, the malicious activity including a risk of an attack to the mobile device and identified based on activity relating to the risk performed by a plurality of mobile devices, the instructions received based on the server identifying a vulnerability of the mobile device to the malicious activity and transmitting an indication of the vulnerability to one or more of the plurality of mobile devices; and

configuring the mobile device to detect the malicious activity by chaining the subset of the plurality of primitives based on the instructions.

18. The system of claim 17 , wherein the malicious activity is associated with a mobile application on the mobile device, and wherein detecting the malicious activity does not require updating the mobile application.

19. The system of claim 17 , the operations further comprising:

receiving a second set of instructions that are defined by a provider of an application associated with the mobile device that is vulnerable to the malicious activity, wherein chaining the subset of the plurality of primitives is further based on the second set of instructions.

20. The system of claim 17 , the operations further comprising:

extracting a set of feature vectors based on data associated with the mobile device;

performing feature transformation to the set of feature vectors;

applying a classifier to the transformed set of feature vectors, wherein the classifier is received from the server or another device; and

determining the malicious activity based on results from running the classifier.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 15, 2024
From: CHAZEN, RYAN; PELEG, ASAF
To: ZIMPERIUM, INC.
Reel/Frame 067416/0505 →
Continuity (1)
Continuation 17316561 · May 10, 2021
References Cited (32)
US 6105136A · Cromer et al. · 2000 [cited by applicant]
US 7409717B1 · Szor · 2008 [cited by applicant]
US 7890089B1 · Fujisaki · 2011 [cited by applicant]
US 9158915B1 · Yumer et al. · 2015 [cited by applicant]
US 9223997B2 · Adams · 2015 [cited by applicant]
US 9226145B1 · Loman · 2015 [cited by examiner]
US RE46768E · Hering et al. · 2018 [cited by applicant]
US 10176329B2 · Chen et al. · 2019 [cited by applicant]
US 10277621B2 · Vervier et al. · 2019 [cited by applicant]
US 11205233B1 · Callahan · 2021 [cited by applicant]
US 11275570B1 · Collins · 2022 [cited by examiner]
US 11507671B1 · Moritz et al. · 2022 [cited by applicant]
US 11528292B1 · Thanos · 2022 [cited by applicant]
US 11775636B1 · Neel · 2023 [cited by examiner]
US 11803792B2 · Makhija · 2023 [cited by examiner]
US 12047402B2 · Kakizaki · 2024 [cited by examiner]
US 12147145B2 · Goun · 2024 [cited by examiner]
US 20040236843A1 · Wing et al. · 2004 [cited by applicant]
US 20040268145A1 · Watkins et al. · 2004 [cited by applicant]
US 20050278777A1 · Loza · 2005 [cited by applicant]
US 20130061325A1 · Singh et al. · 2013 [cited by applicant]
US 20130117769A1 · Sharma · 2013 [cited by examiner]
US 20130152202A1 · Pak et al. · 2013 [cited by applicant]
US 20160226905A1 · Baikalov et al. · 2016 [cited by applicant]
US 20180192292A1 · Coney · 2018 [cited by applicant]
US 20180253558A1 · Li · 2018 [cited by examiner]
US 20200329071A1 · Dani et al. · 2020 [cited by applicant]
US 20230282340A1 · Johnson · 2023 [cited by examiner]
US 20240086530A1 · Klonowski · 2024 [cited by examiner]
US 20240154977A1 · Moore · 2024 [cited by examiner]
United States Office Action, U.S. Appl. No. 17/316,561, filed Dec. 5, 2022, 12 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 17/316,561, filed Jul. 31, 2023, 13 pages. [cited by applicant]