WO2013067006A1 - System and method for application security and performance assessment - Google Patents

System and method for application security and performance assessment Download PDF

Info

Publication number
WO2013067006A1
WO2013067006A1 PCT/US2012/062793 US2012062793W WO2013067006A1 WO 2013067006 A1 WO2013067006 A1 WO 2013067006A1 US 2012062793 W US2012062793 W US 2012062793W WO 2013067006 A1 WO2013067006 A1 WO 2013067006A1
Authority
WO
WIPO (PCT)
Prior art keywords
risk score
application
downloadable
determining
score
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/US2012/062793
Other languages
French (fr)
Inventor
Stuart J. SAUNDERS
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Neevo LLC
Original Assignee
Neevo LLC
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Neevo LLC filed Critical Neevo LLC
Publication of WO2013067006A1 publication Critical patent/WO2013067006A1/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • G—PHYSICS
    • G06—COMPUTING OR CALCULATING; COUNTING
    • G06F—ELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G—PHYSICS
    • G06—COMPUTING OR CALCULATING; COUNTING
    • G06F—ELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/57—Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
    • G06F21/577—Assessing vulnerabilities and evaluating computer system security

Definitions

  • the present disclosure relates generally to computer security systems and methods, and, more particularly, to system and method for application security and performance assessment.
  • Modern computing devices such as computers, mobile computing devices, and mobile phones, are capable of downloading and installing a wide variety of software applications.
  • software sources such as the Android Market
  • the Android Market and others like it, allows users to download various applications to their mobile devices, such as their mobile phone.
  • the Android Market and others like it, allows users to download various applications to their mobile devices, such as their mobile phone.
  • computing devices may be configured to require that any code executed be authorized by a trusted party.
  • certain applications may be deemed unsuitable or unsafe for a particular user. Unfortunately, due to the extremely large number of applications, it can be difficult to manage the availability and installation of these applications.
  • Mobile devices may include smart phones, cell phones, personal digital assistants, netbooks, tablet devices, and the like.
  • IT Information Technology
  • aspects of the disclosed technology relate to an end-to-end system and method for managing security and privacy risks associated with downloadable applications for devices, as well as for monitoring performance of downloadable applications.
  • the disclosed system and method allows for curation of an application distribution channel in which an enterprise administrator can have top-down and/or bottom-up management of a network of devices.
  • the top-down functionality allows for curation of application based on risk and performance, while the bottom-up NEVOP0101 US
  • One aspect of the disclosed technology relates to a method of assessing risk associated with a downloadable application for a mobile device that includes determining a security risk score associated with the downloadable application; and determining a privacy risk score associated with the downloadable application.
  • the method includes determining a composite risk score based on the determined security risk score and the determined privacy risk score.
  • determining a security risk score includes defining a plurality of customizable rules for determining the security risk score.
  • determining a security risk score includes applying the plurality of customizable rules to the downloadable application.
  • determining a privacy risk score includes defining a plurality of customizable rules for determining the privacy risk score.
  • determining a privacy risk score includes applying the plurality of customizable rules to the downloadable application.
  • determining a security risk score includes: mining the downloadable application for code, assets, patterns and/or signatures; and applying a plurality of customized rules to the mined code, assets, patterns and/or signatures.
  • determining a privacy risk score includes: mining the downloadable application for code, assets, patterns and/or signatures; and applying a plurality of customized rules to the mined code, assets, patterns and/or signatures.
  • the method includes comparing the security risk score to a predetermined security risk threshold.
  • the predetermined security risk threshold includes a predetermined security risk score.
  • the predetermined security risk threshold includes a plurality of policies or rules indicative of an unacceptable security risk.
  • the method includes comparing the privacy risk score to a predetermine privacy risk threshold.
  • the predetermined privacy risk threshold includes a predetermined privacy risk score.
  • the predetermined privacy risk threshold includes a plurality of policies or rules indicative of an unacceptable privacy risk.
  • the method includes comparing the composite risk score to a predetermined risk score.
  • determining a security risk score includes:
  • performing an active or runtime analysis includes: generating simulated user activity involving the downloadable application outside a computing environment on the mobile device; and capturing runtime data related to the simulated user activity involving the downloadable application.
  • determining a privacy risk score includes:
  • performing an active or runtime analysis includes: generating simulated user activity involving the downloadable application outside a computing environment on the mobile device; and capturing runtime data related to the simulated user activity involving the downloadable application.
  • the method includes determining a performance score for the downloadable application.
  • determining a performance score includes defining a plurality of customizable rules for determining the performance score.
  • determining a performance score includes applying the plurality of customizable rules to the downloadable application.
  • downloadable application includes: generating simulated user activity involving the downloadable application outside a computing environment; and capturing runtime data related to the simulated user activity involving the downloadable application.
  • the downloadable application is pre-installed on the mobile device.
  • a method of assessing risk associated with a downloadable application includes performing a static analysis of the downloadable application; and performing a runtime analysis of the downloadable application.
  • performing a static analysis includes receiving one or more facts indicative of security risk; and applying one or more rules to the downloadable application.
  • performing a static analysis includes receiving one or more facts indicative of privacy risk; and applying one or more rules to the downloadable application.
  • performing a static analysis includes mining the downloadable application for code, assets, patterns and/or signatures; and applying a plurality of customized rules to the mined code, assets, patterns and/or signatures.
  • performing a runtime analysis includes generating simulated user activity involving the downloadable application outside a computing environment; and capturing runtime data related to the simulated user activity involving the downloadable application.
  • Another aspect of the disclosed technology relates to a method of controlling access to a group of downloadable applications that includes: identifying a security risk threshold and a privacy risk threshold for a downloadable application, the security risk threshold being indicative of a maximum allowable security risk for download of the downloadable application, and the privacy risk threshold being NEVOP0101 US
  • Another aspect of the disclosed technology relates to a method of
  • determining whether a downloadable mobile application should be available for download includes: determining a degree of tolerable risk; identifying a risk score indicative of the determined degree of tolerable risk for the downloadable mobile application, wherein the composite risk score includes a security risk component and a privacy risk component; receiving data indicative of a composite risk score; and making the downloadable application available for download if the received risk score is less than the identified risk score.
  • the method includes: identifying a performance score indicative of a threshold of performance for the downloadable mobile application; receiving data indicative of a performance score; and making the downloadable application available for download if the received performance score is greater than the identified performance score.
  • Another aspect of the disclosed technology includes a method for managing a network of mobile devices that includes determining a degree of tolerable risk associated with a downloadable mobile application; identifying a risk score indicative of the determined degree of tolerable risk associated with downloadable mobile applications, wherein the risk score includes a security risk component and a privacy risk component; receiving data indicative of a risk score; and allowing access to a downloadable mobile application if the received risk score is less than the identified risk score.
  • the method includes identifying a performance score indicative of a threshold of performance for downloadable mobile applications; receiving data indicative of a performance score; and allowing access to a NEVOP0101 US
  • Another aspect of the disclosed technology relates to a method for managing a network of mobile devices that includes capturing data representative of a download of a mobile application by a mobile device within the network; identifying a risk score indicative of a determined degree of tolerable risk for mobile
  • the risk score includes a security risk component and a privacy risk component; receiving data indicative of a risk score associated with the mobile application downloaded by the mobile device within the network; and removing the mobile application from the mobile device within the network if the received risk score is greater than the identified risk score.
  • Another aspect of the disclosed technology relates to a method for managing a network of mobile devices that includes capturing data representative of a download of a mobile application by a mobile device within the network; determining whether the downloaded mobile application contains a malicious component; and if the downloaded mobile application contains a malicious component, transmitting code to the mobile device, the transmitted code being operable to remove and/or heal the malicious component.
  • Another aspect of the disclosed technology relates to a method for managing a network of mobile device that includes capturing data representative of a download of a mobile application by a mobile device within the network;
  • Another aspect of the disclosed technology relates to a method for managing a network of mobile devices that includes receiving a risk score threshold indicative of a degree of tolerable risk associated with a downloadable mobile application; wherein the risk score threshold includes a security risk score component and a NEVOP0101 US
  • determining a security risk score associated with the downloadable mobile application determining a privacy risk score associated with the downloadable mobile application; and allowing access to the downloadable mobile application if the determined risk score is less than the identified risk score threshold.
  • Another aspect of the disclosed technology relates to a method for managing a network of mobile devices that includes capturing data representative of a download of a mobile application by a mobile device within the network; determining whether the downloaded mobile application has a risk score greater than a predetermined risk score indicative of a degree of tolerable risk associated with a downloadable mobile application; and removing the mobile application from the mobile device within the network if the determined risk score is greater than the predetermined risk score.
  • Another aspect of the disclosed technology relates to a method of curating a store of downloadable applications for a mobile device that includes identifying a risk score for a downloadable application, the risk score being indicative of a maximum allowable risk for download of the downloadable application; determining a security risk score associated with the downloadable application; determining a privacy risk score associated with the downloadable application; and if the security risk score and the privacy risk score are below the identified risk score, making the downloadable application available for download.
  • Another aspect of the disclosed technology relates to a method for managing a network of mobile device that includes capturing data representative of a download of a mobile application by a mobile device within the network;
  • monitoring code associated with the mobile application at runtime determining whether the code has changed at runtime; and if the code has changed at runtime, removing the mobile application from the mobile device within the network.
  • Another aspect of the disclosed technology relates to a method of curating a store of downloadable applications that includes receiving a risk score threshold indicative of a degree of tolerable risk associated with downloadable applications; NEVOP0101 US
  • the risk score threshold includes a security risk score threshold and a privacy risk score threshold; and dynamically adjusting access to downloadable applications based on the received risk score threshold.
  • dynamically adjusting access includes determining a risk score for a given downloadable application; comparing the risk score for the given downloadable application to the received risk score threshold; and if the risk score for the given downloadable application is greater than the received risk score threshold, restricting access to the given downloadable application.
  • the method includes receiving a performance score threshold indicative of a degree of tolerable performance associated with
  • dynamically adjusting access includes: determining a performance score for a given downloadable application; comparing the performance score for the given downloadable application to the received performance score threshold; and if the performance score for the given
  • Another aspect of the disclosed technology relates to a method of detecting malicious metamorphic code within a downloadable application for a mobile device that includes downloading the downloadable application onto a cloud
  • Another aspect of the disclosed technology relates to a method of assessing performance associated with a downloadable application that includes performing a static analysis of the downloadable application; and performing a runtime analysis of the downloadable application.
  • Another aspect of the disclosed technology relates to a system for assessing risk associated with a downloadable application for a mobile device that includes a processor configured to: determine a security risk score associated with the downloadable application; and determine a privacy risk score associated with the downloadable application.
  • embodiment may be used in the same way or in a similar way in one or more other embodiments and/or in combination with or instead of the features of the other embodiments.
  • FIG. 1 is a diagrammatic illustration of one exemplary computing
  • FIG. 2 is a diagrammatic illustration of another exemplary computing environment in which aspects of the disclosed technology may be implemented
  • FIG. 3 is a diagrammatic illustration of another exemplary computing environment in which aspects of the disclosed technology may be implemented
  • FIG. 4 is a diagrammatic illustration of another exemplary computing environment in which aspects of the disclosed technology may be implemented.
  • FIG. 5 is a diagrammatic illustration of another exemplary computing environment in which aspects of the disclosed technology may be implemented.
  • FIG. 6 is a flow chart illustrating a method of assessing risk associated with an application in accordance with one aspect of the disclosed technology
  • FIG. 7 is a flow chart illustrating a method of assessing risk associated with an application in accordance with one aspect of the disclosed technology
  • FIG. 8 is a flow chart illustrating a method of assessing risk associated with an application in accordance with one aspect of the disclosed technology
  • FIG. 9 is a diagrammatic illustration of a system and method for determining security risk in accordance with one aspect of the disclosed technology.
  • FIG. 10 is a diagrammatic illustration of a system and method for determining privacy risk in accordance with one aspect of the disclosed technology
  • FIG. 1 1 is a diagrammatic illustration of a system and method for determining performance in accordance with one aspect of the disclosed technology
  • FIG. 12 is a flow chart illustrating a method of controlling access to downloadable applications in accordance with one aspect of the disclosed technology
  • FIG. 13 is a diagrammatic illustration of a system and method for determining security risk in accordance with one aspect of the disclosed technology
  • FIG. 14 is a diagrammatic illustration of a system and method for determining privacy risk in accordance with one aspect of the disclosed technology
  • FIG. 15 is a diagrammatic illustration of a system and method for determin performance in accordance with one aspect of the disclosed technology
  • FIG. 16 is a diagrammatic illustration of an exemplary graphical user interface in accordance with one aspect of the disclosed technology.
  • aspects of the disclosed technology relate to an end-to-end system and method for managing security and privacy risks associated with downloadable applications for devices, as well as for monitoring performance of downloadable applications.
  • One aspect of the disclosed technology relates to a heuristics engine that mines applications (e.g., downloadable mobile applications) for code, assets, patterns and signatures.
  • the overall analysis can include a static portion and an active or runtime portion. Custom rules can be applied to calculate risk scores for privacy and/or security. In addition, performance scores can be calculated. Based on the outcome of an overall static analysis, applications can be routed through various workflows, both internal and external to the system.
  • One aspect of the internal workflow allows application to be escalated to a behavioral analysis tool that captures runtime data. This can include low-level operating system hooks, encryption spoofing, custom virtual machines, custom operating system kernels, dynamic class loading, network traffic and modifications to device settings.
  • aspects of the disclosed technology facilitate curation of an application distribution channel in which an enterprise administrator can have top-down and bottom-up management of a network of devices.
  • the disclosed technology can facilitate management of application NEVOP0101 US
  • two lightweight software applications can be used with the system.
  • one client is configured to provide engineers or administrators with performance monitoring of applications installed on network device.
  • a second exemplary client allows for real-time removal of malware and over-the-air healing functionality to revert malicious payloads. Compromised devices can be tracked to ensure all devices affected by malicious software are quarantined and healed.
  • one aspect of the disclosed technology relates to a system and method for application inventory management. Another aspect of the disclosed technology relates to a system and method for device management. Another aspect of the disclosed technology relates to a runtime profiler system and method. Another aspect of the disclosed technology relates to a research toolset system and method. Another aspect of the disclosed technology relates to an onboard agent and associated method that facilitates real-time malware removal, audit of device settings, over-the-air healing, tracking of compromised devices and/or scanning non-enterprise application installs. Yet another aspect of the disclosed technology relates to a system and method for providing a mobile clearinghouse for application security and
  • FIGS. 1 -5 illustrate several exemplary computing environments for carrying out aspects of the disclosed technology.
  • the system may include an application database, such as a mobile application store through which mobile applications may be downloaded or otherwise transferred to one or more mobile devices.
  • the application database or store may be configured to include an enterprise NEVOP0101 US
  • the enterprise store functionality may be implemented through one or more enterprise management tools.
  • the Cisco AppHQ manager may be employed for providing a convenient store front experience for mobile devices within an enterprise network.
  • the Cisco AppHQ store enterprises that deploy Cisco devices can have the ability to create and manage a secure, customized view of applications in Cisco AppHQ.
  • Cisco AppHQ enables enterprise IT managers to effectively control the purchase, licensing, distribution and management of approved applications to and users. As is discussed more fully below, this functionality is enhanced by way of the various aspects of the disclosed technology.
  • the enterprise store provides for control by, monitoring by and communication with an IT administrator or IT manager.
  • Various mobile devices may communicate with the enterprise store through any suitable network, such as the Internet or any suitable wide area network. It will be appreciated that aspects of the disclosed technology are not limited to implementation using Cisco AppHQ. Rather, any suitable enterprise platform may be employed without departing from the scope of the disclosed technology.
  • FIG. 2 illustrates another exemplary computing environment in which mobile devices associated with an enterprise may communicate directly with an application store outside of the realm of an enterprise store. It will be appreciated that aspects of the disclosed technology provide for management of such a network mobile devices by providing bottom-up functionality for applications downloaded outside of the enterprise environment.
  • FIG. 3 shows another exemplary computing environment in which a plurality of mobile devices may access public networks and websites, such as an application store, through a security system, e.g., a cloud-based security system through which an IT administrator or manager has access to and input on mobile device
  • a security system e.g., a cloud-based security system through which an IT administrator or manager has access to and input on mobile device
  • FIG. 4 another exemplary computing environment in which aspects of the disclosed technology may be carried out is provided.
  • a variety of mobile devices may be in communication within a local area network and/or a wide area network through which applications may be downloaded from, for example, an enterprise store.
  • various mobile device may download application outside of the enterprise environment.
  • Various aspects of the security analysis, risk analysis, and performance analysis may be carried out, for example, in a cloud computing environment.
  • an IT administrator or manager will have access to the enterprise store as well as risk and/or performance data or information generated through the methods described more fully.
  • the IT administrator can set various risk and/or performance thresholds to provide dynamic filtering of available applications within the enterprise store.
  • the IT administrator may monitor already-installed applications using similar risk and/or performance thresholds. This monitoring can be complemented with real-time removal of malware, as well as over-the-air healing functionality.
  • FIG. 5 is a simplified computing environment in which an IT administrator may have access to application inventory management information and services as well as device management, diagnostic and triage information and services, for example, hosted on a cloud. These features can provide an IT manager with top- down and bottom-up network management functionality.
  • determining a security risk score can be implemented in a variety of ways without departing from the scope of the disclosed technology. For example, determining security risk score can include defining a plurality of customizable rules and/or facts for determining the security risk score and applying the plurality of customizable rules and/or facts to the application. Further, determining a security risk score can include mining the downloadable application for code, assets, patterns and/or signatures and applying a plurality or customizable rules or facts to the mind.
  • a security risk score can be determined or otherwise computed based on a security analysis done for the application, application permissions which determine what the application is capable of accessing, reputation of the vendor that created the application, feedback from users, real-time analysis of application behavior in the cloud, or combinations of the above.
  • determining a privacy risk score can include defining a plurality of customizable rules or facts for determining the privacy risk score and applying the plurality of customizable rules or facts to the application. Determining a privacy risk score can include mining the application for code, assets, patterns and/or signatures and applying a plurality of customized rules to the mind code, assets, patterns and/or signatures.
  • privacy risk score may be based on a privacy analysis performed for the application, feedback from users of the
  • the security risk score and/or a privacy risk score will allow for dynamic filtering of application inventory. For example, if a particular application is requested by a mobile device, access to the application may be granted or denied depending on whether the requested application meets a minimum threshold for security and/or privacy as set forth by an IT administrator or manager.
  • a composite risk score can be calculated based on the determined security risk score and/or the
  • applications may be examined and assigned a performance score, which may be a numerical score or may be a pass/no pass score indicative of whether the application meets minimum performance requirements or standards for the given enterprise rules and/or policies.
  • determining a security risk score can include performing a static analysis on the application and/or performing an active or runtime analysis on the application. In accordance with one embodiment, if the application passes the static analysis, then an active or run time analysis may be performed. However, if the application does not pass the static analysis, there is no need to perform an active or run time analysis of the
  • determining a privacy risk score can include performing a static analysis on the application and/or performing an active or runtime analysis on the application.
  • performing an active or runtime analysis can include generating simulated user activity involving the application outside the computing environment on the mobile device and capturing runtime data related to the simulated user activity involving the downloadable application.
  • an application may be downloaded onto a suitable cloud server or cloud processor which simulates a download on a mobile device.
  • the cloud server or cloud processor may engage in normal runtime use of the application, where runtime data related to the simulated user activity is captured and used to determine NEVOP0101 US
  • a method of assessing risk includes performing a static analysis of the application, for example, a downloadable application or a pre-installed application.
  • performing a static analysis can include receiving one or more facts indicative of security risk, as well as receiving one or more facts indicative of privacy risks.
  • the method of performing a static analysis can include applying one or more rules to the downloadable application based on the received facts indicative of security risks as well as applying one or more rules to the application based on the one or more facts indicative of privacy risk.
  • the method can include receiving or otherwise identifying a risk threshold.
  • a risk threshold can be related to a given security risk threshold or score and/or a given privacy risk threshold or score.
  • a risk score can be determined for a given application, including determining a security risk score for the application and/or a privacy risk score for the application. If the determined risk score exceeds the received risk threshold, access to the application can be denied and/or the application can be removed from the available inventory in the given enterprise store.
  • application performance can be viewed in determining access to a given application. For example, if a risk threshold has been identified and risk has been determined for a given application, where the risk score does not exceed the received risk threshold, performance criteria can be determined or otherwise received. If the application satisfies the performance criteria and/or receives a sufficiently high performance score, the application can be made available to download. Alternatively, if the application does not satisfy the performance criteria and/or receives a sufficiently low performance score, access to the application can be blocked and/or the application can be removed from the available inventory, for example, in the enterprise store. NEVOP0101 US
  • the method includes capturing data representative of a download of a mobile application by a mobile device within the network.
  • the method further includes identifying a risk threshold indicative of a determined degree of tolerable risk, wherein a risk threshold includes a security risk component and a privacy risk component.
  • Data indicative of a security risk score is received and data indicative of a privacy risk score is received.
  • the mobile application can be removed from the mobile device within the network if the received security risk score and/or privacy risk score is greater than the identified risk threshold.
  • determining a security risk score, a privacy risk score and/or a performance score can be achieved using a static or passive analysis and an active or runtime analysis, together with third party data.
  • third party data See, e.g., FIGS. 13-15.
  • CVE Common Vulnerabilities and Exposures
  • a vulnerability is a state in a computing system (or set of systems) that either:
  • An information security "exposure” is a system configuration issue or a mistake in software that allows access to information or capabilities that can be used by a hacker as a stepping-stone into a system or network.
  • Exposure describes a state in a computing system (or set of systems) that is not a vulnerability, but either:
  • Examples of exposures include:
  • Tunning services that are common attack points e.g., HTTP, FTP, or SMTP •use of applications or services that can be successfully attacked by brute force methods (e.g., use of trivially broken encryption, or a small key space)
  • a mobile clearinghouse for data can be established using the risk and performance analysis described above, together with accessing and processing information within third-party databases, such as the above-described CVE database.
  • a security risk analysis and a privacy risk analysis may be performed alone or together with a performance analysis. If it is found that the previously downloaded or otherwise pre-installed application violates a given risk threshold (whether it be security risk threshold or privacy risk threshold) or violates specific performance metrics, proactive action can be taken to remedy the situation. Such action can include, but is not limited to, removing the application and/or any malware associated with the application, as well as over-the-air-healing functionality to revert any malicious payloads. In this manner, compromised devices can be tracked to ensure that all devices affected by malicious software are quarantined and healed.
  • FIG. 16 shows a very simplified graphical user interface in which an IT administrator can adjust various risk and performance thresholds.
  • the exemplary graphical user interface includes a plurality of user-selectable sliders representative of a desired threshold for privacy risk, security risk and performance. Through this graphical user interface an IT administrator can adjust threshold values for privacy risk threshold, security risk threshold and/or performance threshold and receive dynamic feedback as to the effects on application availability within an enterprise store.
  • this type of feedback can be provided with respect to already- installed applications on mobile devices within the network.
  • exemplary graphical user interface includes virtual sliders, it will be appreciated that any user-selectable interface can be employed without departing from the scope of the disclosed technology.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Software Systems (AREA)
  • Theoretical Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Computing Systems (AREA)
  • Debugging And Monitoring (AREA)

Abstract

The present application is directed to a system and method for application security and performance assessment. Aspects of the disclosed technology relate to an end-to-end system and method for managing securit5 y and privacy risks associated with downloadable applications for devices, as well as for monitoring performance of downloadable applications. The disclosed system and method allows for curation of an application distribution channel in which an enterprise administrator can have top-down and/or bottom-up management of a network of 10 devices. The top-down functionality allows for curation of application based on risk and performance, while the bottom-up functionality allows for real-time removal of harmful items and/or over-the-air healing functionality.

Description

NEVOP0101 US
SYSTEM AND METHOD FOR APPLICATION SECURITY AND PERFORMANCE ASSESSMENT
Related Application Data
This application claims priority of U.S. Provisional Application No. 61/553,719, filed on October 31 , 201 1 , which is incorporated herein by reference in its entirety.
Field of Invention
The present disclosure relates generally to computer security systems and methods, and, more particularly, to system and method for application security and performance assessment.
Background
Modern computing devices, such as computers, mobile computing devices, and mobile phones, are capable of downloading and installing a wide variety of software applications. For example, software sources, such as the Android Market, allow users to browse and download applications onto their computing devices. For example, the Android Market, and others like it, allows users to download various applications to their mobile devices, such as their mobile phone. Currently, there are an extremely large number of applications available through sources like the Android Market or the Apple Store.
Different users and computing devices, however, may have different requirements regarding how these applications execute. For example, computing devices may be configured to require that any code executed be authorized by a trusted party. As another example, certain applications may be deemed unsuitable or unsafe for a particular user. Unfortunately, due to the extremely large number of applications, it can be difficult to manage the availability and installation of these applications.
Mobile device adoption is poised to overtake conventional computers
(laptops, desktops, etc.). Mobile devices may include smart phones, cell phones, personal digital assistants, netbooks, tablet devices, and the like. With the proliferation of mobile devices and their associated operating systems and applications, mobile security poses significant threat to enterprises, service providers, and the like. That is, enterprises are struggling with the consumerization of Information Technology (IT). With the proliferation of mobile devices within the NEVOP0101 US
enterprise, IT administrators can no longer ignore these devices as outside their scope of responsibility. Further, computing power on these devices is now as powerful as laptops. Users may access corporate data and the Internet through wireless networks such as Wi-Fi hotspots or cellular 3G/4G that are not controlled by IT. With many corporate applications being hosted in the cloud, the risk is even higher. Ensuring the security of corporate data is no longer a matter of deploying adequate measures within the organization. It is important that security and policy travel with users wherever they are, on whatever type of device they use. Unlike the personal computer (PC) world that is dominated by a few main operating systems, the number of platforms and device form-factors for mobile devices is much higher, as is their churn rate. IT needs a solution that is easy to deploy, supports multiple mobile platforms and provides consistent user policy enforcement across PCs and mobile devices.
There are challenges that affect IT organizations as the proliferation and adoption of mobile devices increases with enterprises. One challenge is that the line between enterprise and personal usage is getting blurred on mobile devices. These devices run the gamut of applications, from Facebook, YouTube, Pandora, to enterprise apps like email and sales force automation. Since the enterprise typically does not own the device, enforcing policies for acceptable usage or installing application controls like a traditional IT administrator would on a corporate PC is often not viable. There is an increased risk of exposing corporate data on mobile devices since they roam and connect to multiple Wi-Fi and cellular 3G/4G networks. Traditionally, web security protections have been enforced either by way of a gateway web proxy at an enterprise's egress to the Internet or via signature-based anti-virus protections installed on the user PC. With mobile devices, there is no obvious point of enforcement like an enterprise proxy. To complicate matters further, enterprise data is rapidly migrating to the cloud. As a result, an employee's mobile web transactions may never hit the enterprise network while accessing critical cloud-hosted data.
Another challenge is that security apps for mobile devices are expensive to NEVOP0101 US
develop and often ineffective. Unlike the PC world, which is dominated by Microsoft, there are several different mobile operating systems-Apple iOS, Android, Windows Mobile, Blackberry, Symbian, etc. Each platform has its own software development environment and a security vendor developing mobile security applications will have to replicate the effort across various platforms. Further, some platforms such as Apple iOS do not allow traditional anti-virus applications on their platform. Loading third party applications, not approved by the platform vendor may lead to violation of contract and may require "jailbreaking" the device-definitely not an enterprise option. Even if security applications are allowed, they are a headache to deploy, require constant updates, and are easy to circumvent-the user can simply uninstall them if they dislike it. Worst of all, they impact device performance and degrade user experience by stretching the already limited processor and memory resources on the mobile device.
With the advent of mobile devices, there has been an explosion of custom built applications that users can download from various mobile markets such as the Apple App Store and the Android Market. The Apple App Store has over 250,000 apps and has crossed the 10 billion download mark. The Android Market is in a similar position. As such, mobile platforms are even more desirable targets for web based exploits given that the devices are always accessible and online and thus more likely to be impacted by a short lived attack.
Summary of Invention
Aspects of the disclosed technology relate to an end-to-end system and method for managing security and privacy risks associated with downloadable applications for devices, as well as for monitoring performance of downloadable applications. The disclosed system and method allows for curation of an application distribution channel in which an enterprise administrator can have top-down and/or bottom-up management of a network of devices. The top-down functionality allows for curation of application based on risk and performance, while the bottom-up NEVOP0101 US
functionality allows for real-time removal of harmful items and/or over-the-air healing functionality.
One aspect of the disclosed technology relates to a method of assessing risk associated with a downloadable application for a mobile device that includes determining a security risk score associated with the downloadable application; and determining a privacy risk score associated with the downloadable application.
According to one feature, the method includes determining a composite risk score based on the determined security risk score and the determined privacy risk score.
According to one feature, determining a security risk score includes defining a plurality of customizable rules for determining the security risk score.
According to one feature, determining a security risk score includes applying the plurality of customizable rules to the downloadable application.
According to one feature, determining a privacy risk score includes defining a plurality of customizable rules for determining the privacy risk score.
According to one feature, determining a privacy risk score includes applying the plurality of customizable rules to the downloadable application.
According to one feature, determining a security risk score includes: mining the downloadable application for code, assets, patterns and/or signatures; and applying a plurality of customized rules to the mined code, assets, patterns and/or signatures.
According to one feature, determining a privacy risk score includes: mining the downloadable application for code, assets, patterns and/or signatures; and applying a plurality of customized rules to the mined code, assets, patterns and/or signatures.
According to one feature, the method includes comparing the security risk score to a predetermined security risk threshold.
According to one feature, the predetermined security risk threshold includes a predetermined security risk score. NEVOP0101 US
According to one feature, the predetermined security risk threshold includes a plurality of policies or rules indicative of an unacceptable security risk.
According to one feature, the method includes comparing the privacy risk score to a predetermine privacy risk threshold.
According to one feature, the predetermined privacy risk threshold includes a predetermined privacy risk score.
According to one feature, the predetermined privacy risk threshold, includes a plurality of policies or rules indicative of an unacceptable privacy risk.
According to one feature, the method includes comparing the composite risk score to a predetermined risk score.
According to one feature, determining a security risk score includes:
performing a static analysis on the downloadable application; and performing an active or runtime analysis on the downloadable application.
According to one feature, performing an active or runtime analysis includes: generating simulated user activity involving the downloadable application outside a computing environment on the mobile device; and capturing runtime data related to the simulated user activity involving the downloadable application.
According to one feature, determining a privacy risk score includes:
performing a static analysis on the downloadable application; and performing an active or runtime analysis on the downloadable application.
According to one feature, performing an active or runtime analysis includes: generating simulated user activity involving the downloadable application outside a computing environment on the mobile device; and capturing runtime data related to the simulated user activity involving the downloadable application.
According to one feature, the method includes determining a performance score for the downloadable application.
According to one feature, determining a performance score includes defining a plurality of customizable rules for determining the performance score.
According to one feature, determining a performance score includes applying the plurality of customizable rules to the downloadable application. NEVOP0101 US
According to one feature, determining a performance score for the
downloadable application includes: generating simulated user activity involving the downloadable application outside a computing environment; and capturing runtime data related to the simulated user activity involving the downloadable application.
According to one feature, the downloadable application is pre-installed on the mobile device.
According to another aspect of the disclosed technology, a method of assessing risk associated with a downloadable application includes performing a static analysis of the downloadable application; and performing a runtime analysis of the downloadable application.
According to one feature, performing a static analysis includes receiving one or more facts indicative of security risk; and applying one or more rules to the downloadable application.
According to one feature, performing a static analysis includes receiving one or more facts indicative of privacy risk; and applying one or more rules to the downloadable application.
According to one feature, performing a static analysis includes mining the downloadable application for code, assets, patterns and/or signatures; and applying a plurality of customized rules to the mined code, assets, patterns and/or signatures.
According to one feature, performing a runtime analysis includes generating simulated user activity involving the downloadable application outside a computing environment; and capturing runtime data related to the simulated user activity involving the downloadable application.
Another aspect of the disclosed technology relates to a method of controlling access to a group of downloadable applications that includes: identifying a security risk threshold and a privacy risk threshold for a downloadable application, the security risk threshold being indicative of a maximum allowable security risk for download of the downloadable application, and the privacy risk threshold being NEVOP0101 US
indicative of a maximum allowable privacy risk for download of the downloadable application; determining a security risk score associated with the downloadable application; determining a privacy risk score associated with the downloadable application; and allowing access to the downloadable application if (i) the security risk score is below the identified security risk threshold and (ii) the privacy risk score is below the identified privacy risk threshold.
Another aspect of the disclosed technology relates to a method of
determining whether a downloadable mobile application should be available for download that includes: determining a degree of tolerable risk; identifying a risk score indicative of the determined degree of tolerable risk for the downloadable mobile application, wherein the composite risk score includes a security risk component and a privacy risk component; receiving data indicative of a composite risk score; and making the downloadable application available for download if the received risk score is less than the identified risk score.
According to one feature, the method includes: identifying a performance score indicative of a threshold of performance for the downloadable mobile application; receiving data indicative of a performance score; and making the downloadable application available for download if the received performance score is greater than the identified performance score.
Another aspect of the disclosed technology includes a method for managing a network of mobile devices that includes determining a degree of tolerable risk associated with a downloadable mobile application; identifying a risk score indicative of the determined degree of tolerable risk associated with downloadable mobile applications, wherein the risk score includes a security risk component and a privacy risk component; receiving data indicative of a risk score; and allowing access to a downloadable mobile application if the received risk score is less than the identified risk score.
According to one feature, the method includes identifying a performance score indicative of a threshold of performance for downloadable mobile applications; receiving data indicative of a performance score; and allowing access to a NEVOP0101 US
downloadable mobile application if the received performance score is greater than the identified performance score.
Another aspect of the disclosed technology relates to a method for managing a network of mobile devices that includes capturing data representative of a download of a mobile application by a mobile device within the network; identifying a risk score indicative of a determined degree of tolerable risk for mobile
applications, wherein the risk score includes a security risk component and a privacy risk component; receiving data indicative of a risk score associated with the mobile application downloaded by the mobile device within the network; and removing the mobile application from the mobile device within the network if the received risk score is greater than the identified risk score.
Another aspect of the disclosed technology relates to a method for managing a network of mobile devices that includes capturing data representative of a download of a mobile application by a mobile device within the network; determining whether the downloaded mobile application contains a malicious component; and if the downloaded mobile application contains a malicious component, transmitting code to the mobile device, the transmitted code being operable to remove and/or heal the malicious component.
Another aspect of the disclosed technology relates to a method for managing a network of mobile device that includes capturing data representative of a download of a mobile application by a mobile device within the network;
determining whether the downloaded mobile application exhibits acceptable performance; and if the downloaded mobile application does not exhibit acceptable performance, transmitting code to the mobile device, the transmitted code being operable to remove the downloaded mobile application or heal the downloaded mobile application.
Another aspect of the disclosed technology relates to a method for managing a network of mobile devices that includes receiving a risk score threshold indicative of a degree of tolerable risk associated with a downloadable mobile application; wherein the risk score threshold includes a security risk score component and a NEVOP0101 US
privacy risk score component; determining a security risk score associated with the downloadable mobile application; determining a privacy risk score associated with the downloadable mobile application; and allowing access to the downloadable mobile application if the determined risk score is less than the identified risk score threshold.
Another aspect of the disclosed technology relates to a method for managing a network of mobile devices that includes capturing data representative of a download of a mobile application by a mobile device within the network; determining whether the downloaded mobile application has a risk score greater than a predetermined risk score indicative of a degree of tolerable risk associated with a downloadable mobile application; and removing the mobile application from the mobile device within the network if the determined risk score is greater than the predetermined risk score.
Another aspect of the disclosed technology relates to a method of curating a store of downloadable applications for a mobile device that includes identifying a risk score for a downloadable application, the risk score being indicative of a maximum allowable risk for download of the downloadable application; determining a security risk score associated with the downloadable application; determining a privacy risk score associated with the downloadable application; and if the security risk score and the privacy risk score are below the identified risk score, making the downloadable application available for download.
Another aspect of the disclosed technology relates to a method for managing a network of mobile device that includes capturing data representative of a download of a mobile application by a mobile device within the network;
monitoring code associated with the mobile application at runtime; determining whether the code has changed at runtime; and if the code has changed at runtime, removing the mobile application from the mobile device within the network.
Another aspect of the disclosed technology relates to a method of curating a store of downloadable applications that includes receiving a risk score threshold indicative of a degree of tolerable risk associated with downloadable applications; NEVOP0101 US
wherein the risk score threshold includes a security risk score threshold and a privacy risk score threshold; and dynamically adjusting access to downloadable applications based on the received risk score threshold.
According to one feature, dynamically adjusting access includes determining a risk score for a given downloadable application; comparing the risk score for the given downloadable application to the received risk score threshold; and if the risk score for the given downloadable application is greater than the received risk score threshold, restricting access to the given downloadable application.
According to one feature, the method includes receiving a performance score threshold indicative of a degree of tolerable performance associated with
downloadable applications; and dynamically adjusting access to downloadable applications based on the received performance score threshold.
According to one feature, dynamically adjusting access includes: determining a performance score for a given downloadable application; comparing the performance score for the given downloadable application to the received performance score threshold; and if the performance score for the given
downloadable application is less than the received performance score threshold, restricting access to the given downloadable application.
Another aspect of the disclosed technology relates to a method of detecting malicious metamorphic code within a downloadable application for a mobile device that includes downloading the downloadable application onto a cloud
computer/processor configured to emulate a mobile device; running the
downloadable application on the cloud computer/processor; monitoring patterns in code of the downloadable application during running of the downloadable application; and determining whether patterns in the code of the downloadable application change.
Another aspect of the disclosed technology relates to a method of assessing performance associated with a downloadable application that includes performing a static analysis of the downloadable application; and performing a runtime analysis of the downloadable application. NEVOP0101 US
Another aspect of the disclosed technology relates to a system for assessing risk associated with a downloadable application for a mobile device that includes a processor configured to: determine a security risk score associated with the downloadable application; and determine a privacy risk score associated with the downloadable application.
These and further features of the present invention will be apparent with reference to the following description and attached drawings. In the description and drawings, particular embodiments of the invention have been disclosed in detail as being indicative of some of the ways in which the principles of the invention may be employed, but it is understood that the invention is not limited correspondingly in scope. Rather, the invention includes all changes, modifications and equivalents coming within the spirit and terms of the claims appended thereto.
Features that are described and/or illustrated with respect to one
embodiment may be used in the same way or in a similar way in one or more other embodiments and/or in combination with or instead of the features of the other embodiments.
It should be emphasized that the term "comprises/comprising" when used in this specification is taken to specify the presence of stated features, integers, steps or components but does not preclude the presence or addition of one or more other features, integers, steps, components or groups thereof.
Brief Description of the Drawings
Many aspects of the invention can be better understood with reference to the following drawings. The components in the drawings are not necessarily to scale, emphasis instead being placed upon clearly illustrating the principles of the present invention. Likewise, elements and features depicted in one drawing may be combined with elements and features depicted in additional drawings. Moreover, in the drawings, like reference numerals designate corresponding parts throughout the several views. NEVOP0101 US
FIG. 1 is a diagrammatic illustration of one exemplary computing
environment in which aspects of the disclosed technology may be implemented;
FIG. 2 is a diagrammatic illustration of another exemplary computing environment in which aspects of the disclosed technology may be implemented;
FIG. 3 is a diagrammatic illustration of another exemplary computing environment in which aspects of the disclosed technology may be implemented;
FIG. 4 is a diagrammatic illustration of another exemplary computing environment in which aspects of the disclosed technology may be implemented;
FIG. 5 is a diagrammatic illustration of another exemplary computing environment in which aspects of the disclosed technology may be implemented;
FIG. 6 is a flow chart illustrating a method of assessing risk associated with an application in accordance with one aspect of the disclosed technology;
FIG. 7 is a flow chart illustrating a method of assessing risk associated with an application in accordance with one aspect of the disclosed technology;
FIG. 8 is a flow chart illustrating a method of assessing risk associated with an application in accordance with one aspect of the disclosed technology;
FIG. 9 is a diagrammatic illustration of a system and method for determining security risk in accordance with one aspect of the disclosed technology;
FIG. 10 is a diagrammatic illustration of a system and method for determining privacy risk in accordance with one aspect of the disclosed technology;
FIG. 1 1 is a diagrammatic illustration of a system and method for determining performance in accordance with one aspect of the disclosed technology;
FIG. 12 is a flow chart illustrating a method of controlling access to downloadable applications in accordance with one aspect of the disclosed technology;
FIG. 13 is a diagrammatic illustration of a system and method for determining security risk in accordance with one aspect of the disclosed technology;
FIG. 14 is a diagrammatic illustration of a system and method for determining privacy risk in accordance with one aspect of the disclosed technology; NEVOP0101 US
FIG. 15 is a diagrammatic illustration of a system and method for determin performance in accordance with one aspect of the disclosed technology;
FIG. 16 is a diagrammatic illustration of an exemplary graphical user interface in accordance with one aspect of the disclosed technology; and
Detailed Description
To illustrate aspects of the disclosed technology in a clear and concise manner, the drawings may not necessarily be to scale and certain features may be shown in somewhat schematic form.
Aspects of the disclosed technology relate to an end-to-end system and method for managing security and privacy risks associated with downloadable applications for devices, as well as for monitoring performance of downloadable applications. One aspect of the disclosed technology relates to a heuristics engine that mines applications (e.g., downloadable mobile applications) for code, assets, patterns and signatures. The overall analysis can include a static portion and an active or runtime portion. Custom rules can be applied to calculate risk scores for privacy and/or security. In addition, performance scores can be calculated. Based on the outcome of an overall static analysis, applications can be routed through various workflows, both internal and external to the system.
One aspect of the internal workflow allows application to be escalated to a behavioral analysis tool that captures runtime data. This can include low-level operating system hooks, encryption spoofing, custom virtual machines, custom operating system kernels, dynamic class loading, network traffic and modifications to device settings.
As will be described more fully below, aspects of the disclosed technology facilitate curation of an application distribution channel in which an enterprise administrator can have top-down and bottom-up management of a network of devices. The disclosed technology can facilitate management of application NEVOP0101 US
inventory for an enterprise network of devices, as well as diagnostic and triage functionality for the enterprise network of devices.
In accordance with one aspect, two lightweight software applications (e.g., thin-clients) can be used with the system. In accordance with one exemplary embodiment, one client is configured to provide engineers or administrators with performance monitoring of applications installed on network device. A second exemplary client allows for real-time removal of malware and over-the-air healing functionality to revert malicious payloads. Compromised devices can be tracked to ensure all devices affected by malicious software are quarantined and healed.
As will be discussed more fully below, in general terms, one aspect of the disclosed technology relates to a system and method for application inventory management. Another aspect of the disclosed technology relates to a system and method for device management. Another aspect of the disclosed technology relates to a runtime profiler system and method. Another aspect of the disclosed technology relates to a research toolset system and method. Another aspect of the disclosed technology relates to an onboard agent and associated method that facilitates real-time malware removal, audit of device settings, over-the-air healing, tracking of compromised devices and/or scanning non-enterprise application installs. Yet another aspect of the disclosed technology relates to a system and method for providing a mobile clearinghouse for application security and
performance data.
It will be appreciated that aspects of the disclosed technology can be carried out in a number of exemplary computing environments. For example, FIGS. 1 -5 illustrate several exemplary computing environments for carrying out aspects of the disclosed technology. One example of an environment suitable for practicing various embodiments of the disclosed technology is provided in FIG. 1 . As shown, the system may include an application database, such as a mobile application store through which mobile applications may be downloaded or otherwise transferred to one or more mobile devices.
The application database or store may be configured to include an enterprise NEVOP0101 US
store. The enterprise store functionality may be implemented through one or more enterprise management tools. For example, the Cisco AppHQ manager may be employed for providing a convenient store front experience for mobile devices within an enterprise network. For example, in the case of the Cisco AppHQ store, enterprises that deploy Cisco devices can have the ability to create and manage a secure, customized view of applications in Cisco AppHQ. In addition, Cisco AppHQ enables enterprise IT managers to effectively control the purchase, licensing, distribution and management of approved applications to and users. As is discussed more fully below, this functionality is enhanced by way of the various aspects of the disclosed technology. As shown, the enterprise store provides for control by, monitoring by and communication with an IT administrator or IT manager. Various mobile devices may communicate with the enterprise store through any suitable network, such as the Internet or any suitable wide area network. It will be appreciated that aspects of the disclosed technology are not limited to implementation using Cisco AppHQ. Rather, any suitable enterprise platform may be employed without departing from the scope of the disclosed technology.
FIG. 2 illustrates another exemplary computing environment in which mobile devices associated with an enterprise may communicate directly with an application store outside of the realm of an enterprise store. It will be appreciated that aspects of the disclosed technology provide for management of such a network mobile devices by providing bottom-up functionality for applications downloaded outside of the enterprise environment.
FIG. 3 shows another exemplary computing environment in which a plurality of mobile devices may access public networks and websites, such as an application store, through a security system, e.g., a cloud-based security system through which an IT administrator or manager has access to and input on mobile device
operations, such as downloading applications and running applications.
Turning now to FIG. 4, another exemplary computing environment in which aspects of the disclosed technology may be carried out is provided. In the NEVOP0101 US
illustrated exemplary computing environment, a variety of mobile devices may be in communication within a local area network and/or a wide area network through which applications may be downloaded from, for example, an enterprise store.
Alternatively, various mobile device may download application outside of the enterprise environment. Various aspects of the security analysis, risk analysis, and performance analysis may be carried out, for example, in a cloud computing environment. As shown, an IT administrator or manager will have access to the enterprise store as well as risk and/or performance data or information generated through the methods described more fully. For example, the IT administrator can set various risk and/or performance thresholds to provide dynamic filtering of available applications within the enterprise store. Alternatively, the IT administrator may monitor already-installed applications using similar risk and/or performance thresholds. This monitoring can be complemented with real-time removal of malware, as well as over-the-air healing functionality.
FIG. 5 is a simplified computing environment in which an IT administrator may have access to application inventory management information and services as well as device management, diagnostic and triage information and services, for example, hosted on a cloud. These features can provide an IT manager with top- down and bottom-up network management functionality.
While for purposes of simplicity of explanation, various flow charts or diagrams include a series of steps or functional blocks that represent one or more aspects of the relevant operation of the system and method, it is to be understood and appreciated that aspects of the disclosed technology are not limited to the order of steps or functional blocks, as some steps or functional blocks may, in accordance with aspects of the disclosed technology, occur in different orders and/or
concurrently with other steps or functional blocks from that shown and described herein. Moreover, not all illustrated steps or functional blocks of aspects of relevant operation may be required to implement a methodology in accordance with an aspect of the disclosed technology. Furthermore, additional steps or functional blocks of aspects of relevant operation may be added without departing from the NEVOP0101 US
scope of the disclosed technology.
Turning now to FIG. 6, a method of assessing risk associated with an application, for example, a downloadable application accessible through an application store or a pre-installed application is provided. The method begins at a first step where a security risk score is determined for a given application. It will be appreciated that determining a security risk score can be implemented in a variety of ways without departing from the scope of the disclosed technology. For example, determining security risk score can include defining a plurality of customizable rules and/or facts for determining the security risk score and applying the plurality of customizable rules and/or facts to the application. Further, determining a security risk score can include mining the downloadable application for code, assets, patterns and/or signatures and applying a plurality or customizable rules or facts to the mind.
In accordance with another exemplary embodiment, a security risk score can be determined or otherwise computed based on a security analysis done for the application, application permissions which determine what the application is capable of accessing, reputation of the vendor that created the application, feedback from users, real-time analysis of application behavior in the cloud, or combinations of the above.
Next, a privacy risk score is determined for the application. In accordance with one embodiment, determining a privacy risk score can include defining a plurality of customizable rules or facts for determining the privacy risk score and applying the plurality of customizable rules or facts to the application. Determining a privacy risk score can include mining the application for code, assets, patterns and/or signatures and applying a plurality of customized rules to the mind code, assets, patterns and/or signatures.
In another exemplary embodiment, privacy risk score may be based on a privacy analysis performed for the application, feedback from users of the
application around security, real-time analysis of application behavior in the cloud or combinations of the above. As will be discussed more fully below, the determination NEVOP0101 US
of the security risk score and/or a privacy risk score will allow for dynamic filtering of application inventory. For example, if a particular application is requested by a mobile device, access to the application may be granted or denied depending on whether the requested application meets a minimum threshold for security and/or privacy as set forth by an IT administrator or manager.
In accordance with another exemplary embodiment, a composite risk score can be calculated based on the determined security risk score and/or the
determined privacy risk score.
In accordance with another embodiment (FIG. 7), applications may be examined and assigned a performance score, which may be a numerical score or may be a pass/no pass score indicative of whether the application meets minimum performance requirements or standards for the given enterprise rules and/or policies.
In accordance with one embodiment (FIG. 8 and FIG. 9), determining a security risk score can include performing a static analysis on the application and/or performing an active or runtime analysis on the application. In accordance with one embodiment, if the application passes the static analysis, then an active or run time analysis may be performed. However, if the application does not pass the static analysis, there is no need to perform an active or run time analysis of the
application. Likewise, determining a privacy risk score can include performing a static analysis on the application and/or performing an active or runtime analysis on the application.
In accordance with one embodiment, performing an active or runtime analysis can include generating simulated user activity involving the application outside the computing environment on the mobile device and capturing runtime data related to the simulated user activity involving the downloadable application. For example, an application may be downloaded onto a suitable cloud server or cloud processor which simulates a download on a mobile device. The cloud server or cloud processor may engage in normal runtime use of the application, where runtime data related to the simulated user activity is captured and used to determine NEVOP0101 US
whether the application presents any security risk or privacy risk.
In accordance with another exemplary embodiment, a method of assessing risk includes performing a static analysis of the application, for example, a downloadable application or a pre-installed application. In accordance with one embodiment, performing a static analysis can include receiving one or more facts indicative of security risk, as well as receiving one or more facts indicative of privacy risks. The method of performing a static analysis can include applying one or more rules to the downloadable application based on the received facts indicative of security risks as well as applying one or more rules to the application based on the one or more facts indicative of privacy risk.
Another aspect of the disclosed technology relates to a method of controlling access to a group of downloadable applications (FIG. 12). The method can include receiving or otherwise identifying a risk threshold. As is discussed above, a risk threshold can be related to a given security risk threshold or score and/or a given privacy risk threshold or score. A risk score can be determined for a given application, including determining a security risk score for the application and/or a privacy risk score for the application. If the determined risk score exceeds the received risk threshold, access to the application can be denied and/or the application can be removed from the available inventory in the given enterprise store.
In accordance with another embodiment, application performance can be viewed in determining access to a given application. For example, if a risk threshold has been identified and risk has been determined for a given application, where the risk score does not exceed the received risk threshold, performance criteria can be determined or otherwise received. If the application satisfies the performance criteria and/or receives a sufficiently high performance score, the application can be made available to download. Alternatively, if the application does not satisfy the performance criteria and/or receives a sufficiently low performance score, access to the application can be blocked and/or the application can be removed from the available inventory, for example, in the enterprise store. NEVOP0101 US
Another aspect of the disclosed technology relates to a method of managing a network of mobile devices. The method includes capturing data representative of a download of a mobile application by a mobile device within the network. The method further includes identifying a risk threshold indicative of a determined degree of tolerable risk, wherein a risk threshold includes a security risk component and a privacy risk component. Data indicative of a security risk score is received and data indicative of a privacy risk score is received. The mobile application can be removed from the mobile device within the network if the received security risk score and/or privacy risk score is greater than the identified risk threshold.
In accordance with another embodiment, determining a security risk score, a privacy risk score and/or a performance score can be achieved using a static or passive analysis and an active or runtime analysis, together with third party data. (See, e.g., FIGS. 13-15). It will be appreciated that numerous third-party databases can be used without departing from the scope of the present invention. For example, aspects of the disclosed technology may be used in conjunction with a third-party analysis or data, (e.g., known vulnerabilities and exposures or other known security risk data, privacy risk data and/or performance data). For example, to Common Vulnerabilities and Exposures (CVE) database can be accessed and used in connection with aspects of the disclosed technology.
Below are the CVE Initiative's definitions of the terms "Vulnerability" and
"Exposure":
Vulnerability
An information security "vulnerability" is a mistake in software that can be directly used by a hacker to gain access to a system or network.
CVE considers a mistake a vulnerability if it allows an attacker to use it to violate a reasonable security policy for that system (this excludes entirely "open" security policies in which all users are trusted, or where there is no consideration of risk to NEVOP0101 US
the system).
For CVE, a vulnerability is a state in a computing system (or set of systems) that either:
•allows an attacker to execute commands as another user
•allows an attacker to access data that is contrary to the specified access restrictions for that data
•allows an attacker to pose as another entity
»allows an attacker to conduct a denial of service
Examples of vulnerabilities include: »phf (remote command execution as user "nobody")
•rpc.ttdbserverd (remote command execution as root)
•world-writeable password file (modification of system-critical data)
•default password (remote command execution or other access)
•denial of service problems that allow an attacker to cause a Blue Screen of Death »smurf (denial of service by flooding a network)
Review vulnerabilities on the Common Vulnerabilities and Exposures (CVE) List.
Exposure
An information security "exposure" is a system configuration issue or a mistake in software that allows access to information or capabilities that can be used by a hacker as a stepping-stone into a system or network.
CVE considers a configuration issue or a mistake an exposure if it does not directly allow compromise but could be an important component of a successful attack, and NEVOP0101 US
is a violation of a reasonable security policy.
An "exposure" describes a state in a computing system (or set of systems) that is not a vulnerability, but either:
•allows an attacker to conduct information gathering activities
•allows an attacker to hide activities
•includes a capability that behaves as expected, but can be easily compromised •is a primary point of entry that an attacker may attempt to use to gain access to the system or data
•is considered a problem according to some reasonable security policy
Examples of exposures include:
•running services such as finger (useful for information gathering, though it works as advertised)
•inappropriate settings for Windows NT auditing policies (where "inappropriate" is enterprise-specific)
Tunning services that are common attack points (e.g., HTTP, FTP, or SMTP) •use of applications or services that can be successfully attacked by brute force methods (e.g., use of trivially broken encryption, or a small key space)
In accordance with one exemplary embodiment, a mobile clearinghouse for data can be established using the risk and performance analysis described above, together with accessing and processing information within third-party databases, such as the above-described CVE database.
While aspects of the disclosed technology have been described in
connection with controlling access to downloadable applications, it will be
appreciated that aspects of the disclosed technology may also be applied to a NEVOP0101 US
method of controlling access to a distribution channel or knowledge based in which one or more applications may have already been downloaded by a mobile device within the network. In accordance with this embodiment, a security risk analysis and a privacy risk analysis may be performed alone or together with a performance analysis. If it is found that the previously downloaded or otherwise pre-installed application violates a given risk threshold (whether it be security risk threshold or privacy risk threshold) or violates specific performance metrics, proactive action can be taken to remedy the situation. Such action can include, but is not limited to, removing the application and/or any malware associated with the application, as well as over-the-air-healing functionality to revert any malicious payloads. In this manner, compromised devices can be tracked to ensure that all devices affected by malicious software are quarantined and healed.
As is discussed above, the various embodiments of the disclosed system and method provide an IT administrator with information and/or functionality to manage security and privacy risks and performance for mobile devices within an enterprise. One aspect of the disclosed technology includes a user interface configured to receive input from an IT administrator. FIG. 16 shows a very simplified graphical user interface in which an IT administrator can adjust various risk and performance thresholds. For example, the exemplary graphical user interface includes a plurality of user-selectable sliders representative of a desired threshold for privacy risk, security risk and performance. Through this graphical user interface an IT administrator can adjust threshold values for privacy risk threshold, security risk threshold and/or performance threshold and receive dynamic feedback as to the effects on application availability within an enterprise store.
Alternatively, this type of feedback can be provided with respect to already- installed applications on mobile devices within the network.
While the exemplary graphical user interface includes virtual sliders, it will be appreciated that any user-selectable interface can be employed without departing from the scope of the disclosed technology.
Also, while aspects of the privacy risk score, security risk score and/or NEVOP0101 US
performance risk score are described or alluded to in numerical terms, it will be appreciated that qualitative thresholds can also be employed without departing from the scope of the disclosed technology.
It will be appreciated that above-described application security system and method finds broad application in connection with managing security and privacy risks and performance for mobile devices within a network.
Although the invention has been shown and described with respect to a certain embodiment or embodiments, it is obvious that equivalent alterations and modifications will occur to others skilled in the art upon the reading and
understanding of this specification and the annexed drawings. In particular regard to the various functions performed by the above described elements (components, assemblies, devices, compositions, etc.), the terms (including a reference to a "means") used to describe such elements are intended to correspond, unless otherwise indicated, to any element which performs the specified function of the described element (i.e., that is functionally equivalent), even though not structurally equivalent to the disclosed structure which performs the function in the herein illustrated exemplary embodiment or embodiments of the invention. In addition, while a particular feature of the invention may have been described above with respect to only one or more of several illustrated embodiments, such feature may be combined with one or more other features of the other embodiments, as may be desired and advantageous for any given or particular application.

Claims

Claims What is claimed is:
1 . A method of assessing risk associated with a downloadable application for a mobile device, the method comprising:
determining a security risk score associated with the downloadable
application; and
determining a privacy risk score associated with the downloadable
application.
2. The method of claim 1 , further comprising:
determining a composite risk score based on the determined security risk score and the determined privacy risk score.
3. The method of claim 1 or claim 2, wherein determining a security risk score includes defining a plurality of customizable rules for determining the security risk score.
4. The method of any of claims 1 -3, wherein determining a security risk score includes applying the plurality of customizable rules to the downloadable application.
5. The method any of claims 1 -4, wherein determining a privacy risk score includes defining a plurality of customizable rules for determining the privacy risk score.
6. The method of claim 5, wherein determining a privacy risk score includes applying the plurality of customizable rules to the downloadable application.
7. The method of any of claims 1 -6, wherein determining a security risk score includes: mining the downloadable application for code, assets, patterns and/or signatures; and
applying a plurality of customized rules to the mined code, assets, patterns and/or signatures.
8. The method of any of claims 1 -7, wherein determining a privacy risk score includes:
mining the downloadable application for code, assets, patterns and/or signatures; and
applying a plurality of customized rules to the mined code, assets, patterns and/or signatures.
9. The method of any of claims 1 -8, further comprising:
comparing the security risk score to a predetermined security risk threshold.
10. The method of claim 9, wherein the predetermined security risk threshold includes a predetermined security risk score.
1 1 . The method of claim 9, wherein the predetermined security risk threshold, includes a plurality of policies or rules indicative of an unacceptable security risk.
12. The method of any of claims 1 -1 1 , further comprising:
comparing the privacy risk score to a predetermine privacy risk threshold.
13. The method of claim 12, wherein the predetermined privacy risk threshold includes a predetermined privacy risk score.
14. The method of claim 12, wherein the predetermined privacy risk threshold, includes a plurality of policies or rules indicative of an unacceptable privacy risk.
15. The method of any of claims 2-14, further comprising: comparing the composite risk score to a predetermined risk score.
16. The method of any of claims 1 -15, wherein determining a security risk score includes:
performing a static analysis on the downloadable application; and
performing an active or runtime analysis on the downloadable application.
17. The method of claim 16, wherein performing an active or runtime analysis includes:
generating simulated user activity involving the downloadable application outside a computing environment on the mobile device; and
capturing runtime data related to the simulated user activity involving the downloadable application.
18. The method of any of claims 1 -17, wherein determining a privacy risk score includes:
performing a static analysis on the downloadable application; and
performing an active or runtime analysis on the downloadable application.
19. The method of claim 18, wherein performing an active or runtime analysis includes:
generating simulated user activity involving the downloadable application outside a computing environment on the mobile device; and
capturing runtime data related to the simulated user activity involving the downloadable application.
20. The method of any of claims 1 -19, further comprising:
determining a performance score for the downloadable application.
21 . The method of any of claims 1 -20, wherein determining a performance score includes defining a plurality of customizable rules for determining the performance score.
22. The method of claim 21 , wherein determining a performance score includes applying the plurality of customizable rules to the downloadable application.
23. The method of claim 20, wherein determining a performance score for the downloadable application includes:
generating simulated user activity involving the downloadable application outside a computing environment; and
capturing runtime data related to the simulated user activity involving the downloadable application.
24. The method of any of claims 1 -23, wherein the downloadable application is pre-installed on the mobile device.
25. A method of assessing risk associated with a downloadable
application, the method comprising
performing a static analysis of the downloadable application; and
performing a runtime analysis of the downloadable application.
26. The method of claim 25, wherein performing a static analysis includes: receiving one or more facts indicative of security risk; and
applying one or more rules to the downloadable application.
27. The method of claim 25 or claim 26, wherein performing a static analysis includes:
receiving one or more facts indicative of privacy risk; and
applying one or more rules to the downloadable application.
28. The method of any of claims 25-27, wherein performing a static analysis includes:
mining the downloadable application for code, assets, patterns and/or signatures; and
applying a plurality of customized rules to the mined code, assets, patterns and/or signatures.
29. The method of any of claims 25-28, wherein performing a runtime analysis includes:
generating simulated user activity involving the downloadable application outside a computing environment; and
capturing runtime data related to the simulated user activity involving the downloadable application.
30. A method of controlling access to a group of downloadable
applications, the method including:
identifying a security risk threshold and a privacy risk threshold for a downloadable application, the security risk threshold being indicative of a maximum allowable security risk for download of the downloadable application, and the privacy risk threshold being indicative of a maximum allowable privacy risk for download of the downloadable application;
determining a security risk score associated with the downloadable
application;
determining a privacy risk score associated with the downloadable
application; and
allowing access to the downloadable application if (i) the security risk score is below the identified security risk threshold and (ii) the privacy risk score is below the identified privacy risk threshold.
31 . The method of claim 30, wherein determining a security risk score includes defining a plurality of customizable rules for determining the security risk score.
32. The method of claim 31 , wherein determining a security risk score includes applying the plurality of customizable rules to the downloadable application.
33. The method of any of claims 30-32, wherein determining a privacy risk score includes defining a plurality of customizable rules for determining the privacy risk score.
34. The method of claim 33, wherein determining a privacy risk score includes applying the plurality of customizable rules to the downloadable application.
35. The method of any of claims 30-34, wherein determining a security risk score includes:
mining the downloadable application for code, assets, patterns and/or signatures; and
applying a plurality of customized rules to the mined code, assets, patterns and/or signatures.
36. The method of any of claims 30-35, wherein determining a privacy risk score includes:
mining the downloadable application for code, assets, patterns and/or signatures; and
applying a plurality of customized rules to the mined code, assets, patterns and/or signatures.
37. The method of any of claims 30-36, further comprising:
comparing the security risk score to the predetermined security risk threshold.
38. The method of claim 37, wherein the predetermined security risk threshold includes a predetermined security risk score.
39. The method of claim 37, wherein the predetermined security risk threshold, includes a plurality of policies or rules indicative of an unacceptable security risk.
40. The method of any of claims 30-39, further comprising:
comparing the privacy risk score to a predetermine privacy risk threshold.
41 . The method of claim 40, wherein the predetermined privacy risk threshold includes a predetermined privacy risk score.
42. The method of claim 40, wherein the predetermined privacy risk threshold, includes a plurality of policies or rules indicative of an unacceptable privacy risk.
43. The method of any of claims 30-42, wherein determining a security risk score includes:
performing a static analysis on the downloadable application; and
performing a runtime analysis on the downloadable application.
44. The method of claim 43, wherein performing a runtime analysis includes:
generating simulated user activity involving the downloadable application outside a computing environment; and
capturing runtime data related to the simulated user activity involving the downloadable application.
45. The method of any of claims 30-44, wherein determining a privacy risk score includes:
performing a static analysis on the downloadable application; and
performing a runtime analysis on the downloadable application.
46. The method of claim 45, wherein performing a runtime analysis includes:
generating simulated user activity involving the downloadable application outside a computing environment; and
capturing runtime data related to the simulated user activity involving the downloadable application.
47. The method of any of claims 30-46, the method further comprising: identifying a performance threshold for the downloadable application;
determining a performance score associated with the downloadable application; and
allowing access to the downloadable application if the performance score is above the identified performance threshold.
48. The method of claim 47, wherein determining a performance score includes:
generating simulated user activity involving the downloadable application outside a computing environment; and
capturing runtime data related to the simulated user activity involving the downloadable application.
49. A method of determining whether a downloadable mobile application should be available for download, the method comprising:
determining a degree of tolerable risk;
identifying a risk score indicative of the determined degree of tolerable risk for the downloadable mobile application, wherein the composite risk score includes a security risk component and a privacy risk component;
receiving data indicative of a composite risk score; and
making the downloadable application available for download if the received risk score is less than the identified risk score.
50. The method of claim 49, further comprising:
identifying a performance score indicative of a threshold of performance for the downloadable mobile application;
receiving data indicative of a performance score; and
making the downloadable application available for download if the received performance score is greater than the identified performance score.
51 . A method for managing a network of mobile devices, the method comprising:
determining a degree of tolerable risk associated with a downloadable mobile application;
identifying a risk score indicative of the determined degree of tolerable risk associated with downloadable mobile applications, wherein the risk score includes a security risk component and a privacy risk component;
receiving data indicative of a risk score; and
allowing access to a downloadable mobile application if the received risk score is less than the identified risk score.
52. The method of claim 51 , further comprising:
identifying a performance score indicative of a threshold of performance for downloadable mobile applications;
receiving data indicative of a performance score; and
allowing access to a downloadable mobile application if the received performance score is greater than the identified performance score.
53. A method for managing a network of mobile devices, the method comprising:
capturing data representative of a download of a mobile application by a mobile device within the network;
identifying a composite risk score indicative of a determined degree of tolerable risk, wherein the composite risk score includes a security risk component and a privacy risk component;
receiving data indicative of a composite risk score associated with the mobile application downloaded by the mobile device within the network; and
removing the mobile application from the mobile device within the network if the received composite risk score is greater than the identified composite risk score.
54. The method of claim 53, further comprising:
identifying a performance score indicative of a threshold of performance for mobile applications;
receiving data indicative of a performance score associated with the mobile application downloaded by the mobile device within the network; and
removing the mobile application from the mobile device within the network if the received performance score is greater than the identified performance score.
55. A method for managing a network of mobile devices, the method comprising:
capturing data representative of a download of a mobile application by a mobile device within the network;
determining whether the downloaded mobile application contains a malicious component; and
if the downloaded mobile application contains a malicious component, transmitting code to the mobile device, the transmitted code being operable to remove and/or heal the malicious component.
56. A method for managing a network of mobile devices, the method comprising:
receiving a composite risk score threshold indicative of a degree of tolerable risk associated with a downloadable mobile application; wherein the composite risk score includes a security risk score and a privacy risk score;
determining a security risk score associated with the downloadable mobile application;
determining a privacy risk score associated with the downloadable mobile application;
determining a composite risk score based on the determined security risk score and the determined privacy risk score; and
allowing access to the downloadable mobile application if the determined composite risk score is less than the identified composite risk score.
57. A method for managing a network of mobile devices, the method comprising:
capturing data representative of a download of a mobile application by a mobile device within the network;
determining whether the downloaded mobile application has a composite risk score greater than a predetermined risk score indicative of a degree of tolerable risk associated with a downloadable mobile application; and
removing the mobile application from the mobile device within the network if the determined composite risk score is greater than the predetermined composite risk score.
58. The method of claim 57, wherein determining whether the downloaded mobile application has a composite risk score greater than a predetermined risk score includes determining a composite risk score for the downloaded mobile application.
59. The method of claim 57 or claim 58, wherein determining a composite risk score includes:
determining a privacy risk score; and
determining a security risk score.
60. The method of any of claims 57-59, wherein determining a security risk score includes defining a plurality of customizable rules for determining the security risk score.
61 . The method of any of claims 57-60, wherein determining a security risk score includes applying the plurality of customizable rules to the downloadable application.
62. The method of any of claims 57-61 , wherein determining a privacy risk score includes defining a plurality of customizable rules for determining the privacy risk score.
63. The method of any of claims 57-62, wherein determining a privacy risk score includes applying the plurality of customizable rules to the downloadable application.
64. The method of any of claims 57-63, wherein determining a security risk score includes:
mining the downloadable application for code, assets, patterns and/or signatures; and
applying a plurality of customized rules to the mined code, assets, patterns and/or signatures.
65. The method of any of claims 57-64, wherein determining a privacy risk score includes:
mining the downloadable application for code, assets, patterns and/or signatures; and
applying a plurality of customized rules to the mined code, assets, patterns and/or signatures.
66. The method of any of claims 57-65, further comprising:
comparing the security risk score to a predetermined security risk score.
67. The method of any of claims 57-66, further comprising: comparing the privacy risk score to a predetermine privacy risk score.
68. The method of any of claims 57-67, further comprising:
comparing the composite risk score to a predetermined risk score.
69. The method of any of claims 57-68, wherein determining a security risk score includes:
performing a static analysis on the downloadable application; and
performing a dynamic analysis on the downloadable application.
70. The method of any of claims 57-69, wherein performing a dynamic analysis includes:
generating simulated user activity involving the downloadable application outside a computing environment on the mobile device; and
capturing runtime data related to the simulated user activity involving the downloadable application.
71 . The method of any of claims 57-70, wherein determining a privacy risk score includes:
performing a static analysis on the downloadable application; and
performing a dynamic analysis on the downloadable application.
72. The method of any of claims 57-71 , wherein performing a dynamic analysis includes:
generating simulated user activity involving the downloadable application outside a computing environment on the mobile device; and
capturing runtime data related to the simulated user activity involving the downloadable application.
73. The method of any of claims 57-72, further comprising: determining whether the downloaded mobile application has a performance score greater than a predetermined performance score indicative of a degree of tolerable performance associated with a downloadable mobile application; and
removing the mobile application from the mobile device within the network if the determined performance score is less than the predetermined performance score.
74. A method of curating a store of downloadable applications for a mobile device, the method comprising:
identifying a composite risk score for a downloadable application, the composite risk score being indicative of a maximum allowable risk for download of the downloadable application;
determining a security risk score associated with the downloadable application;
determining a privacy risk score associated with the downloadable
application;
determining a composite risk score based on the determined security risk score and the determined privacy risk score; and
if the composite risk score is below the identified composite risk score, making the downloadable application available for download.
75. A method for managing a network of mobile devices, the method comprising:
capturing data representative of a download of a mobile application by a mobile device within the network;
monitoring code associated with the mobile application at runtime;
determining whether the code has changed at runtime; and
if the code has changed at runtime, removing the mobile application from the mobile device within the network.
76. A method of curating a store of downloadable applications, the method comprising:
receiving a composite risk score threshold indicative of a degree of tolerable risk associated with downloadable applications; wherein the composite risk score includes a security risk score and a privacy risk score; and
dynamically adjusting access to downloadable based on the received composite risk score.
77. The method of claim 76, wherein dynamically adjusting access includes:
determining a composite risk score for a given downloadable application; comparing the composite risk score for the given downloadable application to the received composite risk score threshold; and
if the composite risk score for the given downloadable application is greater than the received composite risk score threshold, restricting access to the given downloadable application.
78. The method of claim 76 or claim 77, further comprising:
receiving a performance score threshold indicative of a degree of tolerable performance associated with downloadable applications; and
dynamically adjusting access to downloadable applications based on the received performance score threshold.
79. The method of any of claims 76-78, wherein dynamically adjusting access
includes:
determining a performance score for a given downloadable application; comparing the performance score for the given downloadable application to the received performance score threshold; and
if the performance score for the given downloadable application is less than the received performance score threshold, restricting access to the given
downloadable application.
80. A method of detecting malicious metamorphic code within a
downloadable application for a mobile device, the method comprising:
downloading the downloadable application onto a cloud computer/processor configured to emulate a mobile device;
running the downloadable application on the cloud computer/processor;
monitoring patterns in code of the downloadable application during running of the downloadable application; and
determining whether patterns in the code of the downloadable application change.
81 . A method of assessing performance associated with a downloadable application, the method comprising
performing a static analysis of the downloadable application; and
performing a dynamic analysis of the downloadable application.
82. The method of claim 81 , wherein performing a static analysis includes: receiving one or more facts indicative of performance; and
applying one or more rules to the downloadable application.
83. The method of claim 81 or claim 82, wherein performing a runtime analysis includes:
generating simulated user activity involving the downloadable application outside a computing environment; and
capturing runtime data related to the simulated user activity involving the downloadable application.
84. A system for assessing risk associated with a downloadable
application for a mobile device, the system comprising:
a processor configured to:
determine a security risk score associated with the downloadable application; and
determine a privacy risk score associated with the downloadable application.
PCT/US2012/062793 2011-10-31 2012-10-31 System and method for application security and performance assessment Ceased WO2013067006A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
US201161553719P 2011-10-31 2011-10-31
US61/553,719 2011-10-31

Publications (1)

Publication Number Publication Date
WO2013067006A1 true WO2013067006A1 (en) 2013-05-10

Family

ID=47557451

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/US2012/062793 Ceased WO2013067006A1 (en) 2011-10-31 2012-10-31 System and method for application security and performance assessment

Country Status (1)

Country Link
WO (1) WO2013067006A1 (en)

Cited By (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107403092A (en) * 2017-07-27 2017-11-28 中国人民大学 A kind of cell phone application privacy risk quantitative estimation method
CN107810504A (en) * 2015-06-15 2018-03-16 赛门铁克公司 The system and method that malicious downloading risk is determined based on user behavior
WO2022071985A1 (en) * 2020-09-29 2022-04-07 Cisco Technology, Inc. Dynamic optimization of client application access via a secure access service edge (sase) network optimization controller (noc)
CN114938466A (en) * 2022-04-28 2022-08-23 国家广播电视总局广播电视科学研究院 Internet television application monitoring system and method
US11531765B2 (en) 2020-07-16 2022-12-20 Allstate Insurance Company Dynamic system profiling based on data extraction
CN120857100A (en) * 2025-09-23 2025-10-28 江苏运满满信息科技有限公司 A method and system for searching private numbers with high connection rate

Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20110145920A1 (en) * 2008-10-21 2011-06-16 Lookout, Inc System and method for adverse mobile application identification

Patent Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20110145920A1 (en) * 2008-10-21 2011-06-16 Lookout, Inc System and method for adverse mobile application identification

Cited By (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107810504A (en) * 2015-06-15 2018-03-16 赛门铁克公司 The system and method that malicious downloading risk is determined based on user behavior
CN107403092A (en) * 2017-07-27 2017-11-28 中国人民大学 A kind of cell phone application privacy risk quantitative estimation method
US11531765B2 (en) 2020-07-16 2022-12-20 Allstate Insurance Company Dynamic system profiling based on data extraction
US12067128B2 (en) 2020-07-16 2024-08-20 Allstate Insurance Company Dynamic system profiling based on data extraction
WO2022071985A1 (en) * 2020-09-29 2022-04-07 Cisco Technology, Inc. Dynamic optimization of client application access via a secure access service edge (sase) network optimization controller (noc)
EP4222920A1 (en) * 2020-09-29 2023-08-09 Cisco Technology, Inc. Dynamic optimization of client application access via a secure access service edge (sase) network optimization controller (noc)
CN116601919A (en) * 2020-09-29 2023-08-15 思科技术公司 Dynamic optimization of client application access via the Secure Access Service Edge (SASE) Network Optimization Controller (NOC)
CN114938466A (en) * 2022-04-28 2022-08-23 国家广播电视总局广播电视科学研究院 Internet television application monitoring system and method
CN114938466B (en) * 2022-04-28 2023-11-07 国家广播电视总局广播电视科学研究院 Internet television application monitoring system and method
CN120857100A (en) * 2025-09-23 2025-10-28 江苏运满满信息科技有限公司 A method and system for searching private numbers with high connection rate

Similar Documents

Publication Publication Date Title
US12099596B2 (en) Mobile device policy enforcement
US10776485B2 (en) Virtual machine security
CN103548320B (en) The dangerous safety applied on device performs
US9467465B2 (en) Systems and methods of risk based rules for application control
US20250284807A1 (en) Integrated application analysis and endpoint protection
AU2019246773B2 (en) Systems and methods of risk based rules for application control
US8549656B2 (en) Securing and managing apps on a device
US10963583B1 (en) Automatic detection and protection against file system privilege escalation and manipulation vulnerabilities
US8984628B2 (en) System and method for adverse mobile application identification
US20130097203A1 (en) System and method for providing threshold levels on privileged resource usage in a mobile network environment
US12099610B2 (en) Dynamic application deployment in trusted code environments
WO2013059138A1 (en) System and method for whitelisting applications in a mobile network environment
Vargas et al. Security controls for Android
US9672353B2 (en) Securing and managing apps on a device using policy gates
Gupta et al. A risk-driven model to minimize the effects of human factors on smart devices
Zhang et al. Design and implementation of efficient integrity protection for open mobile platforms
Powers et al. Whitelist malware defense for embedded control system devices
Kanerva Integrating a mobile device management solution in Android
Amro Personal Mobile Malware Guard PMMG: a mobile malware detection technique based on user's preferences
Sarga et al. Mobile Cyberwarfare Threats and Mitigations: An Overview
Nguyen Android Application Security
Saracino et al. Risk analysis of Android applications: A user-centric solution Gianluca Dini, Fabio Martinelli, Ilaria Matteucci, Marinella Petrocchi

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 12814018

Country of ref document: EP

Kind code of ref document: A1

DPE1 Request for preliminary examination filed after expiration of 19th month from priority date (pct application filed from 20040101)
NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 12814018

Country of ref document: EP

Kind code of ref document: A1