WO2010141826A2

System and method for detecting energy consumption anomalies and mobile malware variants

Abstract

A system is presented for detecting malware applications residing on a mobile device powered by a battery. The system includes a power monitoring module, a data analysis module and a data store that stores a plurality of known power signatures signifying a power consumption anomaly. The power monitoring module measures power drawn from the battery and the data analysis module extracts a power history signature from the power measures. The data analysis module then compares the power history signature with the plurality of known power signatures and initiates a protective operation if the power history signature is closely correlated to one or more of the known power signatures.

WO2010141826A2, drawing sheet 1
Sheet 1 of 19

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

31 claims: 3 independent, 28 dependent

  1. 1
    CLAIMS What is claimed is:1. A system for detecting malware applications residing on a mobile device powered by a battery, comprising: a data store that stores a plurality of known power signatures, each of the power signatures signifying a power consumption pattern of an application;a power monitoring module, implemented as computer executable instructions executed by a computer processor, that measures power drawn from the battery;a data analysis module, implemented as computer executable instructions executed by a computer processor, that receives power measures from the power monitor and extracts a power history signature from the power measures, the data analysis module compares the power history signature with a plurality of known power signatures and initiates a protective operation if the power history signature is closely correlated to one or more of the known power signatures.
  2. 20
    A mobile computing device powered by a battery, comprising:a data store for storing a plurality of known power signatures, each of the power signatures signifying a power consumption pattern of an application;a power monitoring module that measures power drawn from the battery and generates a power consumption history indicating amounts of power drawn from the battery at various times;a data analysis module embodied as computer executable instructions in computer memory receives the power consumption history from the power monitoring module and extracts a power signature form the power measure, the data analysis module computes a similarity measure between the power signature and each of the plurality of known power signatures and initiates a protective operation when the similarity measure between the power signature and a known power signature corresponding to a malware application exceeds a threshold.
  3. 29
    A method for monitoring malware on a mobile device comprising:maintaining a data store storing known power signatures, wherein known power signatures indicate expected power usages of known applications at various time periods;determining amounts of power being drawn from a battery at various sampling times and generating a power consumption history indicating the amounts of power being drawn from the battery at the various times;filtering the power consumption history, wherein noise corresponding to statistical outliers on the power consumption history are smoothed on the power consumption history;performing data compression on the filtered power consumption history, wherein a power signature corresponding to the power consumption history is generated;comparing the power signature with known power signatures stored in a power signature data store, wherein known power signatures correspond to power consumption histories of known applications associated with the mobile device;determining a closest known power signature based on the comparing of the power signature with the known power signatures, wherein the closest known power signature has a highest degree of correlation with the power signature;and performing a protective operation when the closest known power signature corresponds to a power consumption history of a malware application.