Aggregate Event Profiles for Detecting Malicious Mobile Applications

    公开(公告)号:US20240070268A1

    公开(公告)日:2024-02-29

    申请号:US17821493

    申请日:2022-08-23

    IPC分类号: G06F21/55

    CPC分类号: G06F21/554 G06F2221/031

    摘要: Described systems and methods protect client devices such as personal computers and IoT devices against malicious software. In some embodiments, a plurality of client devices report the occurrence of various events to a security server, each such event caused by a local instance of a target application (e.g., mobile app) executing on a respective device. The security server then collates the behavior of the respective target application across the plurality of client devices. Some embodiments compute an aggregate event set and/or sequence combining events detected on one device with events detected on other devices, and determine whether the target application is malicious according to the aggregate event set/sequence.