US2014380414A1PendingUtilityA1

Method and system for application-based policy monitoring and enforcement on a mobile device

Assignee: SAIDI HASSENPriority: Mar 2, 2012Filed: Sep 9, 2014Published: Dec 25, 2014
Est. expiryMar 2, 2032(~5.6 yrs left)· nominal 20-yr term from priority
G06F 21/6218H04L 63/10H04L 63/1408H04L 63/20H04L 63/145G06F 21/577G06F 2221/2141G06F 21/6245G06F 21/53H04W 88/02H04L 63/1416H04W 12/37G06F 2221/2101H04W 12/128
51
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method and system for application-based monitoring and enforcement of security, privacy, performance and/or other policies on a mobile device includes incorporating monitoring and policy enforcement code into a previously un-monitored software application package that is installable on a mobile device, and executing the monitoring and policy enforcement code during normal use of the software application by a user of the mobile device.

Claims

exact text as granted — not AI-modified
1 .- 15 . (canceled) 
     
     
         16 . A system for enforcing a privacy or security policy associated with a software application on a mobile computing device, the system to cause the mobile computing device to:
 intercept system calls issued by the software application;   for each intercepted system call:
 determine an argument of the intercepted system call; and 
 execute policy logic to analyze the system call and the argument of the intercepted system call; and 
   permit execution of an intercepted system call to continue if the policy logic determines that the combination of the intercepted system call and the argument of the intercepted system call is permitted by the privacy or security policy associated with the software application.   
     
     
         17 . The system of  claim 16 , wherein the system is to cause execution of the intercepted system call to at least temporary discontinue if the policy logic determines that (i) the intercepted system call is permitted by the privacy or security policy associated with the software application and (ii) the argument of the intercepted system call is not permitted by the privacy or security policy associated with the software application. 
     
     
         18 . The system of  claim 16 , wherein the system is to cause execution of the intercepted system call to at least temporary discontinue if the policy logic determines that the intercepted system call is not permitted by the privacy or security policy associated with the software application. 
     
     
         19 . The system of  claim 16 , wherein the system is to (i) intercept system calls having an argument that identifies a network address and (ii) permit execution of the intercepted system calls if the policy logic determines that the network address is permitted by the privacy or security policy associated with the software application. 
     
     
         20 . The system of  claim 19 , wherein the system is to pass the network address to a blacklisting service to determine if the network address is permitted by the privacy or security policy associated with the software application. 
     
     
         21 . The system of  claim 19 , wherein the system is to pass the network address to a domain registry service to determine if the network address is permitted by the privacy or security policy associated with the software application. 
     
     
         22 . The system of  claim 16 , wherein the system is to (i) intercept system calls having an argument that identifies a network address and (ii) at least temporarily discontinue execution of intercepted system calls if the policy logic determines that the network address is not permitted by the privacy or security policy associated with the software application. 
     
     
         23 . The system of  claim 16 , wherein the system is to (i) intercept system calls having an argument that identifies a target application for an inter-process communication and (ii) permit execution of the intercepted system calls if the policy logic determines that inter-process communication with the target application is permitted by the privacy or security policy associated with the software application. 
     
     
         24 . The system of  claim 16 , wherein the system is to (i) intercept system calls having an argument that identifies a target application for an inter-process communication and (ii) at least temporarily discontinue execution of the intercepted system calls if the policy logic determines that inter-process communication with the target application is not permitted by the privacy or security policy associated with the software application. 
     
     
         25 . The system of  claim 16 , wherein the system is to (i) intercept system calls having an argument that identifies a target application for an inter-process communication, (ii) determine if the inter-process communication with the target application is permitted by the privacy or security policy associated with the software application; and (iii) prior to completing the inter-process communication with the target application, by an output device of the mobile computing device, output a notification. 
     
     
         26 . The system of  claim 25 , wherein the system is to, by an input device of the mobile computing device, receive a response to the notification, store the response to the notification, and apply the response to the analysis of a subsequent system call or to the analysis of an argument of the subsequent system call. 
     
     
         27 . The system of  claim 26 , wherein the system is to permit execution of subsequent system calls based on the response. 
     
     
         28 . The system of  claim 26 , wherein the system is to at least temporarily discontinue execution of subsequent system calls based on the response. 
     
     
         29 . A system for associating a privacy or security policy with a software application for a mobile computing device, the system to:
 configure monitoring and enforcement code to implement the privacy or security policy by specifying, with the monitoring and enforcement code: (i) a combination of a type of system call and an argument of the system call that is permitted by the privacy or security policy; and (ii) a combination of a type of system call and an argument of the system call that is not permitted by the privacy or security policy; and   create an application package comprising the software application and the monitoring and enforcement code.   
     
     
         30 . The system of  claim 29 , wherein the system is to configure the monitoring and enforcement code to identify combinations of system calls and arguments that cause a privilege escalation on the mobile computing device. 
     
     
         31 . The system of  claim 29 , wherein the system is to configure the monitoring and enforcement code to prevent the software application from activating a camera or voice recorder of the mobile computing device in response to a combination of a system call and an argument of the system call. 
     
     
         32 . The system of  claim 29 , wherein the system is to configure the monitoring and enforcement code to prevent the software application from accessing a network address in response to a combination of a type of system call and an argument of the system call that is not permitted by the privacy or security policy. 
     
     
         33 . The system of  claim 29 , wherein the system is to configure the monitoring and enforcement code to analyze a network address specified as an argument to a system call by accessing a network address registry or blacklisting service. 
     
     
         34 . The system of  claim 33 , wherein the system is to configure the monitoring and enforcement code to at least temporarily discontinue execution of a system call in response to analysis of a network address specified as an argument to the system call by the network address registry or blacklisting service. 
     
     
         35 . The system of  claim 29 , wherein the system is to configure the monitoring and enforcement code to identify combinations of system calls and arguments that are associated with inter-process communications that are not permitted by the privacy or security policy.

Join the waitlist — get patent alerts

Track US2014380414A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.