System and method for profile based filtering of outgoing information in a mobile environment
Abstract
A system and method in one embodiment includes modules for detecting an access request by an application to access information in a mobile device, determining that the application is a potential threat according to at least one policy filter, and blocking a send request by the application to send the information from the mobile device without a user's consent. More specific embodiments include user selecting the information through a selection menu on a graphical user interface that includes information categories pre-populated by an operating system of the mobile device, and keywords that can be input by the user. Other embodiments include queuing the send request in a queue with other requests, and presenting an outbox comprising the queue to the user to choose to consent to the requests. The outbox includes graphical elements configured to permit the user to selectively consent to any requests in the queue.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A non-transitory computer-readable storage medium comprising logic that includes code for execution and when executed on a processor configures the processor to perform operations comprising:
detecting an access request by an application to access information in a mobile device; determining whether the information being requested by the access request matches a category of information described by at least one policy filter; flagging the application as a potential threat in response to determining that the information being requested by the access request matches the category of information described by the at least one policy filter, wherein the application is allowed to access the information matching the category of information even though the application is flagged; and in response to flagging the application, blocking send requests by the flagged application to send the information matching the category of information from the mobile device without user's consent.
2 . The non-transitory computer-readable storage medium of claim 1 , further comprising presenting an outbox comprising the send requests and the other requests to the user to choose to consent to individual ones of the send requests and the other requests.
3 . The non-transitory computer-readable storage medium of claim 2 , further comprising placing the send requests in a queue with other requests waiting for the user's consent, wherein the outbox comprises the queue.
4 . The non-transitory computer-readable storage medium of claim 3 , wherein the outbox is presented to the user on a graphical user interface, and comprises graphical elements configured to permit the user to selectively consent to any requests in the queue.
5 . The non-transitory computer-readable storage medium of claim 2 , wherein the outbox is presented to the user on a graphical user interface, and comprises graphical elements configured to permit the user to selectively consent to any requests in the outbox.
6 . The non-transitory computer-readable storage medium of claim 1 , wherein:
a portion of the code comprises privileged code implemented as at least one of: (i) a kernel module; (ii) modified existing system services; (iii) new system services; (iv) modified existing libraries; and (v) new libraries; and another portion of the code comprises unprivileged code.
7 . The non-transitory computer-readable storage medium of claim 1 , wherein the category of information being described by at least one policy filter is selected by a user of the mobile device.
8 . The non-transitory computer-readable storage medium of claim 7 , wherein the user selects the category of information through a selection menu on a graphical user interface, the selection menu comprising:
categories of information that are pre-populated by an operating system of the mobile device; and entries that can be input by the user, wherein the entries comprise at least one selection from: keywords, selected text, patterns and natural language commands.
9 . The non-transitory computer-readable storage medium of claim 8 , wherein the category of information selected by the user is incorporated into the at least one policy filter.
10 . An apparatus comprising:
a memory configured to store data, and a processor operable to execute instructions associated with the data and configured, when executing the instructions, to:
detect an access request by an application to access information in a mobile device;
determine whether the information being requested by the access request matches a category of information described by at least one policy filter;
flag the application as a potential threat in response to determining that the information being requested by the access request matches the category of information described by the at least one policy filter, wherein the application is allowed to access the information matching the category of information even though the application is flagged; and
in response to flagging the application, block send requests by the flagged application to send the information matching the category of information from the mobile device without user's consent.
11 . The apparatus of claim 10 , wherein the processor is further configured to present an outbox comprising the send requests and the other requests to the user to choose to consent to individual ones of the send requests and the other requests.
12 . The apparatus of claim 11 , wherein the processor is further configured to place the send requests in a queue with other requests waiting for the user's consent, wherein the outbox comprises the queue.
13 . The apparatus of claim 12 , wherein the outbox is presented to the user on a graphical user interface and comprises graphical elements configured to permit the user to selectively consent to any requests in the queue.
14 . The apparatus of claim 11 , wherein the outbox is presented to the user on a graphical user interface and comprises graphical elements configured to permit the user to selectively consent to any requests in the outbox.
15 . The apparatus of claim 10 , wherein the category of information being described by at least one policy filter is selected by a user of the mobile device.
16 . The apparatus of claim 15 , wherein the user selects the category of information through a selection menu on a graphical user interface, the selection menu comprising:
categories of information that are pre-populated by an operating system of the mobile device; and entries that can be input by the user, wherein the entries comprise at least one selection from: keywords, selected text, patterns and natural language commands.
17 . The apparatus of claim 16 , wherein the category of information selected by the user is incorporated into the at least one policy filter.
18 . A method comprising a processor performing steps of:
detecting an access request by an application to access information in a mobile device; determining whether the information being requested by the access request matches a category of information described by at least one policy filter; flagging the application as a potential threat in response to determining that the information being requested by the access request matches the category of information described by the at least one policy filter, wherein the application is allowed to access the information matching the category of information even though the application is flagged; and in response to flagging the application, blocking send requests by the flagged application to send the information matching the category of information from the mobile device without user's consent.
19 . The method according to claim 18 , further comprising:
placing the send requests in a queue with other requests waiting for the user's consent; and presenting an outbox comprising the queue having the send requests and the other requests to the user to choose to consent to individual ones of the send requests and the other requests.
20 . The method according to claim 19 , wherein the outbox is presented to the user on a graphical user interface, and comprises graphical elements configured to permit the user to selectively consent to any requests in the queue.Join the waitlist — get patent alerts
Track US2015237011A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.