EP4017204A1

Mobile device system and method for preventing network signal interception and hacking

Abstract

The present invention extends to methods, systems, for preventing an unauthorized access via signal interception and hacking (via network or host attacks) to a user's mobile device by installing an application executable on the user's mobile device to facilitate execution of sequence of programmed instructions to perform at least one signal transmission between two or more users within a computer-based environment and to facilitate a detection engine to perform analysis of at least one signal transmission between two or more users within a computer-based environment.

EP4017204A1, drawing sheet 1
Sheet 1 of 10

Term

11 yearsto projected expiry

Projected expiry 6 September 2037, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

15 claims: 2 independent, 13 dependent

  1. 1
    A method [200] for protecting a secured device from access via hacking, the method comprising the step of installing on the secured device an application executable on a non-transitory computer-readable medium of the secured device [201]; said secured device with said application effecting further steps of the method comprising the steps of:a. receiving one or more system calls and one or more network calls of said secured device, by a timestamp module [202];b. timestamping said system calls and said network calls by said timestamp module [204];c. packaging said timestamped system calls and timestamped network calls, by a correlation module, into an input vector [206];d. receiving, by said correlation module, one or more lists of privileges for one or more applications installed on said secured device [208];wherein the method [200] further comprises the steps: e. computing parameters of said system calls and said network calls [210], said parameters selected from a group comprising a difference in time values of said timestamp of a said system call and a said network call, a correspondence of a said system call or of a said network call with a privilege in one or more of said lists pertaining to an application making said system call or said network call, a validity of a certificate attached to said network call, or any combination thereof;f. further packaging said parameters into said input vector [212];g. receiving said input vector by a neural network [214];h. determination, by said neural network, of whether a said system call or a said network call is approved or suspected [216];i. feeding a said approved system or network call to an approved output and a suspected system or network call to a suspected output [218];j. receiving, by a mitigation rules engine, said suspected output [220];k. determining, by said mitigation rules engine, a mitigating action as a function of said suspected output [222].
  2. 9
    A hacking-protected secured device connected to a network, said device comprising therein a non-transitory computer-readable medium containing instructions for operation on said device of a hacking prevention system [50], the system comprising:a. a correlation module [60];b. a time stamp module [68], configured to receive system calls [54] - calls for routines of on OS of said device - and network calls [56] - requests for access or status from a network-and associate timestamps with each of said system calls [54] and network calls [56];said correlation module [60] configured to receive said system calls [54] with said timestamps and said network calls [56] with said timestamps;wherein said correlation module is configured to package said timestamped system calls [54], and said timestamped network calls [56] into an input vector [70];c. an applications privileges database [52], said database [52] comprising one or more lists of privileges for one or more applications installed on said device;wherein said correlation module [60] is configured to receive said one or more lists of privileges;d. a neural network [62], configured to receive said input vector [70];e. an approved output [64] and a suspected output [66] of said neural network [62];f. a mitigation rules engine [58];g. wherein: i. said correlation module is further configured to compute parameters of said system calls [54] and said network calls [56], said parameters selected from a group consisting of: a difference in time values of said timestamp of a said system call and a said network call, a correspondence of a said system call or of a said network call with a privilege in one or more of said lists pertaining to an application making said system call or said network call, a validity of a certificate attached to said network call, or any combination thereof and further package said parameters into said input vector [70];ii. said neural network is configured to receive said input vector [70] and determine whether a said system call [54] or a said network call [56] is approved or suspected as a hacking attempt of said device;iii. a said approved system call or network call is fed to said approved output [64];iv. a suspected system or network call is fed to said suspected output [66];v. said mitigation rules engine [58] is configured to receive said suspected output [66] and determine an action as a function of said suspected output [66].