EP4017204B1

Mobile device system and method for preventing network signal interception and hacking

Abstract

This record has no abstract on file.

EP4017204B1, drawing sheet 1
Sheet 1 of 9

Term

11 yearsleft in the term

Expires 6 September 2037.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

15 claims: 2 independent, 13 dependent

  1. 1
    A method [200] for protecting a secured device from access via hacking, the method comprising the step of installing on the secured device an application executable on a non-transitory computer-readable medium of the secured device [201]; said secured device with said application effecting further steps of the method comprising the steps of:a. receiving one or more system calls and one or more network calls of said secured device, by a timestamp module [202];b. timestamping said system calls and said network calls by said timestamp module [204];c. packaging said timestamped system calls and timestamped network calls, by a correlation module, into an input vector [206];and d. receiving, by said correlation module, one or more lists of privileges for one or more applications installed on said secured device [208];wherein the method [200] further comprises the steps: e. computing parameters of said system calls and said network calls [210], said parameters selected from a group comprising a difference in time values of said timestamp of a said system call and a said network call, a correspondence of a said system call or of a said network call with a privilege in one or more of said lists pertaining to an application making said system call or said network call, a validity of a certificate attached to said network call, or any combination thereof;f. further packaging said parameters into said input vector [212];g. receiving said input vector by a neural network [214];h. determination, by said neural network, of whether a said system call or a said network call is approved or suspected [216];i. feeding a said approved system or network call to an approved output and a suspected system or network call to a suspected output [218];j. receiving, by a mitigation rules engine, said suspected output [220];k. determining, by said mitigation rules engine, a mitigating action as a function of said suspected output [222].
  2. 9
    A hacking-protected secured device connected to a network, said device comprising therein a non-transitory computer-readable medium containing instructions for operation on said device of a hacking prevention system [50], the system comprising:a. a correlation module [60];b. a time stamp module [68], configured to receive system calls [54] - calls for routines of on OS of said device - and network calls [56] - requests for access or status from a network-and associate timestamps with each of said system calls [54] and network calls [56];said correlation module [60] configured to receive said system calls [54] with said timestamps and said network calls [56] with said timestamps;wherein said correlation module is configured to package said timestamped system calls [54], and said timestamped network calls [56] into an input vector [70];c. an applications privileges database [52], said database [52] comprising one or more lists of privileges for one or more applications installed on said device;wherein said correlation module [60] is configured to receive said one or more lists of privileges;d. a neural network [62], configured to receive said input vector [70];e. an approved output [64] and a suspected output [66] of said neural network [62];and f. a mitigation rules engine [58];wherein: i. said correlation module is further configured to compute parameters of said system calls [54] and said network calls [56], said parameters selected from a group consisting of: a difference in time values of said timestamp of a said system call and a said network call, a correspondence of a said system call or of a said network call with a privilege in one or more of said lists pertaining to an application making said system call or said network call, a validity of a certificate attached to said network call, or any combination thereof and further package said parameters into said input vector [70];ii. said neural network is configured to receive said input vector [70] and determine whether a said system call [54] or a said network call [56] is approved or suspected as a hacking attempt of said device;iii. a said approved system call or network call is fed to said approved output [64];iv. a suspected system or network call is fed to said suspected output [66];and v. said mitigation rules engine [58] is configured to receive said suspected output [66] and determine an action as a function of said suspected output [66].