US2011179484A1PendingUtilityA1
Malware detection system and method for mobile platforms
Est. expiryApr 6, 2026(expired)· nominal 20-yr term from priority
G06F 21/563H04W 12/10G06F 21/565G06F 21/562H04L 63/145H04W 12/128G06F 21/566G06F 21/56G06F 16/245G06F 21/564H04L 63/1441G06F 2221/033H04W 12/12
53
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
In one example, a management server is configured to provide malware protection for one or more client mobile platforms in communication with the management server via a mobile network. In the example, the management server includes a processor configured to detect malware in the mobile network, select a client mobile platform having a malware scanning agent, and, manage the malware scanning agent of the client mobile platform using a device independent secure management protocol based at least in part on the malware detected in the mobile network.
Claims
exact text as granted — not AI-modified1 . A method of providing malware protection for one or more client mobile platforms in communication with a management server via a mobile network, the method comprising:
detecting, by the management server, malware in the mobile network; selecting, by the management server, a client mobile platform having a malware scanning agent; and, managing, by the management server, the malware scanning agent of the client mobile platform using a device independent secure management protocol based at least in part on the malware detected in the mobile network.
2 . The method of claim 1 , wherein managing further comprises:
selecting one or more malware definitions to be pushed to the malware scanning agent of the client mobile platform; and, pushing the selected malware definitions to the client mobile platform using the device independent secure management protocol.
3 . The method of claim 2 , wherein at least one of the malware definitions comprises one of a malware signature, a hash of a first portion of a malware signature, a splatter set of a first portion of a malware signature, a rigorous hash of a second portion of a malware signature, a feature set from a non-executable portion of an application, a rule for applying a feature set, a data store of feature sets and rules, a probability model, a checksum, and a search string from a compressed code portion of an executable.
4 . The method of claim 2 , wherein pushing further comprises:
synchronizing the malware definitions on the client mobile platform with a set of malware definitions on an operational support system server using a synchronization operation of the device independent secure management protocol.
5 . The method of claim 1 , wherein managing further comprises: initiating a malware scanning operation on the client mobile platform by the management server.
6 . The method of claim 1 , wherein managing further comprises:
receiving a report by the management server from the client mobile platform relating to a malware-infected executable on the client mobile platform.
7 . The method of claim 6 , wherein managing further comprises:
receiving the malware-infected executable by the management server from the client mobile platform.
8 . The method of claim 6 , further comprising:
initiating a response to the report, wherein initiating the response comprises at least one of reporting the malware-infected executable to an operational support system, and initiating a malware cleaning operation on the client mobile platform by the management server.
9 . The method of claim 1 , wherein the client mobile platform is a mobile telephone.
10 . The method of claim 1 , wherein the device independent secure management protocol is supported in firmware of the client mobile platform.
11 . The method of claim 1 , further comprising:
producing, by the management server, a management tree comprising a plurality of leaf nodes, each of the leaf nodes comprising data for at least one of the one or more mobile platforms; and storing malware protection system settings in respective ones of the plurality of leaf nodes, wherein selecting the client mobile platform comprises selecting the client mobile platform associated with one of the plurality of leaf nodes, and wherein managing the malware scanning agent of the client mobile platform comprises updating the malware scanning agent in accordance with the malware protection system settings of the one of the plurality of leaf nodes with which the client mobile platform is associated.
12 . A management server configured to provide malware protection for one or more client mobile platforms in communication with the management server via a mobile network, the management server comprising a processor configured to detect malware in the mobile network, select a client mobile platform having a malware scanning agent, and, manage the malware scanning agent of the client mobile platform using a device independent secure management protocol based at least in part on the malware detected in the mobile network.
13 . The management server of claim 12 , wherein to manage the malware scanning agent, the processor is configured to select one or more malware definitions to be pushed to the malware scanning agent of the client mobile platform, and push the selected malware definitions to the client mobile platform using the device independent secure management protocol.
14 . The management server of claim 13 , wherein at least one of the malware definitions comprises one of a malware signature, a hash of a first portion of a malware signature, a splatter set of a first portion of a malware signature, a rigorous hash of a second portion of a malware signature, a feature set from a non-executable portion of an application, a rule for applying a feature set, a data store of feature sets and rules, a probability model, a checksum, and a search string from a compressed code portion of an executable.
15 . The management server of claim 13 , wherein the processor is configured to synchronize the malware definitions on the client mobile platform with a set of malware definitions on an operational support system server using a synchronization operation of the device independent secure management protocol.
16 . The management server of claim 12 , wherein to manage the malware scanning agent, the processor is configured to initiate a malware scanning operation on the client mobile platform.
17 . The management server of claim 12 , wherein to detect the malware in the mobile network, the processor is configured to receive a report from the client mobile platform relating to a malware-infected executable on the client mobile platform.
18 . The management server of claim 17 , wherein to manage the malware scanning agent, the processor is configured to receive the malware-infected executable by the management server from the client mobile platform.
19 . The management server of claim 17 , wherein the processor is configured to initiate a response to the report, wherein the response comprises at least one of reporting the malware-infected executable to an operational support system, and initiating a malware cleaning operation on the client mobile platform.
20 . The management server of claim 12 , wherein the device independent secure management protocol is supported in firmware of the client mobile platform.
21 . The management server of claim 12 , wherein the processor is further configured to produce a management tree comprising a plurality of leaf nodes, each of the leaf nodes comprising data for at least one of the one or more mobile platforms, and store malware protection system settings in respective ones of the plurality of leaf nodes, wherein to select the client mobile platform, the processor is configured to select the client mobile platform associated with one of the plurality of leaf nodes, and wherein to manage the malware scanning agent of the client mobile platform, the processor is configured to update the malware scanning agent in accordance with the malware protection system settings of the one of the plurality of leaf nodes with which the client mobile platform is associated.
22 . A computer-readable storage medium comprising instructions that, when executed, cause a processor of a management server for providing malware protection for one or more client mobile platforms in communication with the management server via a mobile network to:
detect malware in the mobile network; select a client mobile platform having a malware scanning agent; and, manage the malware scanning agent of the client mobile platform using a device independent secure management protocol based at least in part on the malware detected in the mobile network.
23 . The computer-readable storage medium of claim 22 , wherein the instructions that cause the processor to manage further comprise instructions that cause the processor to:
select one or more malware definitions to be pushed to the malware scanning agent of the client mobile platform; and, push the selected malware definitions to the client mobile platform using the device independent secure management protocol.
24 . The computer-readable storage medium of claim 23 , wherein at least one of the malware definitions comprises one of a malware signature, a hash of a first portion of a malware signature, a splatter set of a first portion of a malware signature, a rigorous hash of a second portion of a malware signature, a feature set from a non-executable portion of an application, a rule for applying a feature set, a data store of feature sets and rules, a probability model, a checksum, and a search string from a compressed code portion of an executable.
25 . The computer-readable storage medium of claim 23 , wherein the instructions that cause the processor to push further comprise instructions that cause the processor to:
synchronize the malware definitions on the client mobile platform with a set of malware definitions on an operational support system server using a synchronization operation of the device independent secure management protocol.
26 . The computer-readable storage medium of claim 22 , wherein the instructions that cause the processor to manage further comprise instructions that cause the processor to initiate a malware scanning operation on the client mobile platform.
27 . The computer-readable storage medium of claim 22 , wherein the instructions that cause the processor to detect the malware further comprise instructions that cause the processor to:
receive a report from the client mobile platform relating to a malware-infected executable on the client mobile platform.
28 . The computer-readable storage medium of claim 27 , further comprising instructions that cause the processor to:
receive the malware-infected executable from the client mobile platform.
29 . The computer-readable storage medium of claim 27 , further comprising instructions that cause the processor to:
initiate a response to the report, wherein the response comprises at least one of reporting the malware-infected executable to an operational support system, and initiating a malware cleaning operation on the client mobile platform.
30 . The computer-readable storage medium of claim 22 , wherein the device independent secure management protocol is supported in firmware of the client mobile platform.
31 . The computer-readable storage medium of claim 22 , further comprising instructions that cause the processor to:
produce a management tree comprising a plurality of leaf nodes, each of the leaf nodes comprising data for at least one of the one or more mobile platforms; and store malware protection system settings in respective ones of the plurality of leaf nodes, wherein the instructions that cause the processor to select the client mobile platform comprise instructions that cause the processor to select the client mobile platform associated with one of the plurality of leaf nodes, and wherein the instructions that cause the processor to manage the malware scanning agent of the client mobile platform comprise instructions that cause the processor to update the malware scanning agent in accordance with the malware protection system settings of the one of the plurality of leaf nodes with which the client mobile platform is associated.
32 . A system comprising:
a plurality of mobile platforms; and a management server in communication with the plurality of mobile platforms via a mobile network, wherein the management server is configured to detect malware in the mobile network, select a client mobile platform from the plurality of mobile platforms having a malware scanning agent, and manage the malware scanning agent of the client mobile platform using a device independent secure management protocol based at least in part on the malware detected in the mobile network.Join the waitlist — get patent alerts
Track US2011179484A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.