A software virus prevention and control method based on a double-layer complex network

By constructing a software virus prevention and control method based on a two-layer complex network, improving the infectious disease model and combining it with the information propagation model, simulating the software virus propagation process, and utilizing the isolation mechanism and information propagation rate of antivirus software, the uncertainty problem of virus propagation in networked software systems is solved, and the security and stability of the software system are improved.

CN116415243BActive Publication Date: 2025-09-23BEIHANG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310254212.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-16
Publication Date
2025-09-23
Estimated Expiration
2043-03-16

AI Technical Summary

Technical Problem

Existing technologies are unable to fully address the infectiousness, latency and complexity of software viruses in networked software systems, resulting in high uncertainty in virus propagation. Traditional methods are unable to comprehensively and completely address the complexity of software systems and the laws of virus control.

Method used

A software virus prevention and control method based on double-layer complex network theory is adopted. By improving the infectious disease model and combining it with the information propagation model, a double-layer network model is constructed to simulate the software virus propagation process. The impact of user awareness on virus propagation is considered, and the isolation mechanism and information propagation rate of antivirus software are used to prevent the spread of viruses.

Benefits of technology

It improves the reliability of software systems, effectively prevents and controls the spread of software viruses, enhances the security and stability of software systems, determines the critical control conditions for virus propagation, and reduces the risk of virus spread in networked software systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116415243B_ABST
    Figure CN116415243B_ABST
Patent Text Reader

Abstract

The present invention proposes a software virus prevention and control method based on a double-layer complex network, and the steps are as follows: Step 1: Collect software data that depends on the network to run, determine the nodes and edges in the complex network model abstracted by the networked software system, and construct a complex network model; Step 2: Consider the scenario after the software program is attacked by a virus, and improve the traditional propagation dynamics model in combination with the working principle of antivirus software; Step 3: Simulate the virus propagation process in the networked software system, analyze the software virus propagation situation in the constructed complex network model, and explore the dynamic propagation mechanism of the virus; Step 4: Combined with the interaction driven by user behavior in the networked software system, construct an awareness propagation model based on whether the user is aware of the virus, and construct a double-layer complex network; Step 5: Analyze the impact of human awareness on the spread of software viruses, so as to determine the role of human awareness in preventing and controlling the spread of software viruses in the networked software system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention provides a software virus prevention and control method based on a double-layer complex network, which relates to the implementation of a technology for preventing and controlling software system viruses based on the double-layer complex network theory and belongs to the field of software reliability. Background Art

[0002] As the world's networking continues to accelerate and deepen, networked software, as an abstraction of complex software systems deployed in the Internet environment, is increasingly being used in our daily lives. In the information age, the use of software is an integral part of human production and life. A wide variety of network-dependent applications have enriched and facilitated our lives, but these conveniences also present significant security risks. Networked software systems running on the Internet not only have extremely complex dependencies and interactions between their components, but also have a user and data access scale far exceeding that of traditional PC software. Software's inherent volatility, portability, and fragility make it difficult to ensure its reliability. Furthermore, as software becomes increasingly large and complex, its security vulnerabilities are increasing, making it highly susceptible to viruses and hacker attacks. Many software users have experienced virus attacks to varying degrees. Viruses pose a significant threat to software reliability, particularly causing unforeseen damage to software system operations, such as data loss, theft of confidential information, and software compromise. Once a virus is triggered, it can spread rapidly, impacting software performance. Therefore, preventing and controlling software viruses is crucial. Because there are many types of viruses in software and they spread quickly, it is more difficult for people to detect them. In addition, software viruses are very likely to have variants. These aspects have brought huge challenges to the prevention and control of software viruses.

[0003] On the other hand, software viruses inherently possess numerous characteristics in network environments, such as infectiousness, concealment, infectivity, latency, excitability, manifestation, and destructiveness. The internet is now extremely widespread, and the primary channel for virus transmission is the internet, allowing new viruses to spread rapidly through it. Currently, virus prevention in networked software systems primarily focuses on two aspects: installing genuine antivirus software and updating it promptly, regularly checking for viruses, and promptly patching software vulnerabilities; and, secondly, regular backups to ensure timely data recovery after a virus attack, minimizing losses. This suggests that preventing and controlling software viruses requires considering user awareness and behavior. Whether or not people are aware of software viruses also has a certain impact on their spread. Therefore, this paper explores the role of software users' awareness of the existence of viruses in reducing the likelihood of software virus outbreaks in networked software systems, a topic not previously explored in depth.

[0004] In recent years, researchers have analyzed software systems, combined the relevant theories of software engineering and complex systems, and viewed software systems from the perspective of complex networks, forming a mature network view. This is to network the software system, and on this basis simulate the dynamic spread of viruses, so as to achieve centralized management and unified virus protection. In the current research on the mechanism of software virus propagation, the traditional infectious disease model does not describe the virus prevention process. The present invention models the networked software system based on the double-layer complex network theory, and conducts an in-depth analysis of the propagation process of software viruses in actual scenarios, improves the traditional infectious disease model, simulates the process of isolating and disinfecting viruses, and then deeply understands the dynamic propagation mechanism of software viruses, explores the critical control conditions of viruses, and realizes software virus prevention and control. In addition, the invention is based on the multi-level complex network theory, combined with the modeled networked software system, and on this basis considers the role of human awareness in the prevention and control of software viruses, constructs an information propagation model, and finally determines the role of human consciousness in the prevention and control of software viruses in networked software systems. Since physical systems and information systems influence each other, the two-layer network theoretical model based on complex networks can help to deeply explore the impact of human awareness on preventing and controlling the spread of software viruses, understand the dynamic evolution laws and interaction mechanisms of information propagation and virus propagation, and provide new ideas and directions for building a multi-level, three-dimensional network virus protection system. Summary of the Invention

[0005] (1) Purpose of the Invention: Due to the infectiousness and latency of software viruses, their spread is highly uncertain, posing a significant challenge to the prevention and control of software viruses. Traditional methods are unable to fully and comprehensively address the complexity of software systems and the laws governing virus control. This invention overcomes the shortcomings of the prior art by providing a method for preventing and controlling software viruses based on complex network theory to address these issues. The invention utilizes a two-layer complex network theory to combine an improved dynamic propagation model based on the traditional virus propagation model with an information propagation model to form a two-layer network model for preventing and controlling software viruses. The invention improves upon the traditional dynamic propagation model to simulate the actual scenario of software being attacked by viruses. Specifically, when a software program exhibits virus characteristics, some users realize that the software has been attacked by a virus and activate antivirus software. At this point, to avoid direct deletion of the software program and the resulting loss to the user, the antivirus software isolates the program and does not kill it, leaving the user to decide whether to perform virus removal or isolation. Since no antivirus software can detect and kill all viruses, the software will restart normally after a period of time. At this point, the virus in the software may still be infectious or have been removed, leaving it vulnerable to attack. Based on the improved virus propagation model, we explored the critical propagation rate for viruses to spread within a system. Taking into account the impact of user awareness of the existence of software viruses, we constructed a two-layer complex network model to explore whether increasing the information propagation rate can help suppress the spread of software viruses within networked software systems. This approach can improve software maintenance and provides an effective method for preventing and controlling software viruses.

[0006] (2) Technical solution

[0007] The technical solution of the present invention: A software virus prevention and control method based on a double-layer complex network is constructed as follows:

[0008] The present invention provides a software virus prevention and control method based on a double-layer complex network, the steps of which are as follows:

[0009] Step 1: Collect data on software that relies on the network to run, determine the nodes and edges in the complex network model abstracted by the networked software system, and build the complex network model;

[0010] Step 2: Consider the scenario where a software program is attacked by a virus and improve the traditional propagation dynamics model by combining the working principle of antivirus software;

[0011] Step 3: Simulate the virus propagation process in the networked software system, analyze the software virus propagation in the constructed complex network model, and explore the dynamic propagation mechanism of the virus;

[0012] Step 4: Combine user behavior-driven interactions in the networked software system, build an awareness propagation model based on whether users are aware of the virus, and construct a two-layer complex network;

[0013] Step 5: Analyze the impact of human knowledge on the spread of software viruses, so as to determine the role of human knowledge in preventing and controlling the spread of software viruses in networked software systems.

[0014] The specific steps in step 1, "collecting network-dependent software data, determining nodes and edges in a complex network model abstracted from the networked software system, and constructing a complex network model," are as follows: First, the networked software system needs to be abstracted into the nodes and edges in the complex network model, focusing on the topological structure of the interconnected interactions in the system. Our research targets networked software systems running on the Internet. Due to the booming popularity of social networking sites such as QQ, Facebook, and Twitter, this invention collects such network-dependent software data. This software data includes both social software data installed on personal computers that relies on the Internet (social networking data such as Facebook and Twitter) and Internet peer-to-peer (P2P) networks. A peer-to-peer (P2P) network is a decentralized network architecture that allows nodes (computers or servers) to directly share and access resources. Real-world examples include cryptocurrency networks, file sharing networks, and computing resource sharing networks. Various network data can be obtained from large network collection websites, such as the network dataset collected by Newman personally (http: / / www-personal.umich.edu / ~mejn / netdata / ), the large-scale network dataset collected by Stanford University (http: / / snap.stanford.edu / data / ), and the dataset compiled by the KONECT project (http: / / konect.uni-koblenz.de / ). Each row of the collected data represents the data interaction between two IDs, that is, the link relationship. This type of network data can be used to construct a complex network abstracted by the networked software system. The nodes in the network represent IDs, that is, the computers or servers where the software is installed. Two nodes (IDs) with data exchange are abstracted as an edge in the network.

[0015] Among them, the specific approach of "considering the scenario after the software program is attacked by a virus and combining the working principle of the anti-virus software to improve the traditional propagation dynamics model" described in step 2 is as follows: when the program presents virus characteristics, the user will start the anti-virus software with a certain probability. At this time, in order to avoid directly deleting the virus program and causing losses to the user, the anti-virus software will store the software in an isolation area and completely isolate it from other parts. The isolation area can be used to store suspicious files and perform virus scanning in the future. At this time, other processes cannot operate the software in the isolation area. Based on the above scenario, the present invention sets a certain probability p * The user performs antivirus processing on the infected software. The antivirus processing time is the time the software is stored in the quarantine area. * Therefore, the traditional virus transmission model SIS (Susceptible-Infected-Susceptible, susceptible-infected-susceptible) model is improved to SII * IS (Susceptible-Infected-Isolated-Infected / Susceptible) model, the software in the S (Susceptible) state can be infected by its neighbors in the I (Infected) state. The probability of the software being infected, that is, the virus transmission rate β, enters the I infected state. Combined with the working principle of antivirus software, p * Probability software is in I * (Isolated) Isolation state, the I state node that has not entered the isolation area is (1-p * )μ probability to recover to S state, with (1-p * )(1-μ) probability is still in state I. t * After a certain time, the software is removed from the quarantine zone. Since antivirus software cannot detect all viruses, when the software is restarted, the software node becomes infectious (I infected) with probability m, or it becomes susceptible (S susceptible) with probability 1-m after the virus has been detected. Nodes in I state then return to S susceptible with probability μ, and remain in I infected with probability 1-μ.

[0016] Among them, the specific method of "simulating the spread of viruses in the networked software system, analyzing the spread of software viruses in the constructed complex network model, and exploring the dynamic spread mechanism of viruses" in step 3 is as follows: simulate the spread of software viruses in the complex network model abstractly constructed by the networked software system through Python simulation, analyze the simulation results, and thus determine the dynamic spread mechanism of software viruses in the networked software system, and calculate the dynamic spread mechanism of software viruses in the networked software system under different probability p * The proportion of infected software nodes to the total nodes under the condition, and the infection probability β changes with p * and t *By exploring the virus propagation mechanism in networked software systems, we can determine the critical conditions under which software viruses will not spread in the system.

[0017] The specific approach described in step 4, "Combining user behavior-driven interactions in networked software systems, constructing an awareness propagation model based on user awareness of the virus, and building a two-layer complex network," is as follows: The networking and service-oriented nature of software has given rise to social service websites, promoting the integration of virtual networks and the real world, enabling users to communicate and collaborate on personal information in different scenarios. Due to the social nature of networked software systems, they can functionally reflect and promote the development of real social relationships and interactions, organically integrating human activities with software functionality. In this context, a UAU (Unawareness-Awareness-Unawareness) awareness propagation model is constructed based on user awareness of the virus, creating a two-layer complex network model. Individuals in state U (unawareness) are unaware of the virus and do not take preventative measures. However, individuals in state A (awareness) know that the software has been attacked by a virus and take preventative measures to reduce the risk of virus spread. Individuals in state U will be informed of the virus by their neighbors in state A. The probability of them returning to state A is θ, and the probability of individuals in state A returning to state U is δ.

[0018] In a two-layer complex network model, one layer represents the virus propagation layer of a networked software system, while the other layer is a virtual communication network formed by the diffusion of information related to software viruses. The topologies of the two layers are different. The two-layer network is assumed to be unweighted and undirected. The one-to-one mapping between nodes corresponds to the dynamic interrelationship between the two layers. Each node on one layer is individually mapped to the corresponding node on the other layer (i.e., both layers have the same nodes).

[0019] Next, we model the interaction between the two processes. On the one hand, we assume that the user is aware of the software being attacked by a virus immediately. Therefore, when the node in the virus propagation layer changes to the I state, the corresponding node in the virtual communication layer will automatically change to the A state and spread virus-related information. On the other hand, the A-state node in the virtual communication layer will take measures to prevent virus attacks. Therefore, nodes in different states in the virtual communication layer have different probabilities of being infected by viruses in the physical software layer. For this reason, the infection attenuation factor γ (0≤γ≤1) is considered to adjust the probability of the node being infected. Here, the infection rates of the U-state node and the A-state node are denoted as β U =β and β A =γβ U =γβ. In this model, each individual has four different states: unconscious and susceptible (US), conscious and susceptible (AS), conscious and infected (AI), and conscious and isolated (AI* ). The present invention does not consider the unconscious and infected (UI) states. It is assumed here that individuals in the I state will automatically change to the A state.

[0020] Among them, in step 5, "analyzing the impact of human awareness on the spread of software viruses, and thus determining the role of human awareness in preventing and controlling the spread of software viruses in networked software systems", the specific approach is as follows: Under the dynamic propagation mechanism of software viruses in networked software systems, by using the micro-Markov chain method, based on the four different states that individuals may be in in this model: unconscious and susceptible (US), aware and susceptible (AS), aware and infected (AI), and aware and isolated (AI), the individual is in a state of being infected and infected. * ), generate a probability tree to describe the possible transition states between software virus spread and whether people know that the software is infected by the virus, so as to analyze the impact of whether people know that the software is infected by the virus on the spread of the virus. After that, Monte Carlo numerical simulation is performed to calculate the probability of being in the infected state (AI) and the isolated state (AI * The phase transition process of the ratio of nodes in the double-layer network under different parameters such as β and θ shows that the virus is in UAU-SII * The critical threshold β of propagation in the IS model C By simulating the virus propagation process through Monte Carlo simulation, we can increase people's awareness of the existence of software viruses in networked software systems, that is, increase the information propagation rate θ, and explore whether it is possible to increase the threshold β for large-scale propagation of software viruses. C , which makes it more difficult for viruses to spread in networked software systems, thereby determining whether people are aware of the prevention and control of software virus propagation in networked software systems.

[0021] Through the above steps, a software virus prevention and control method based on a two-layer complex network can be constructed, which can be used by software users to prevent and control software viruses. Against the backdrop of increasingly rapid information development and the increasing harmfulness of software virus transmission, some existing software virus prevention and control methods face the problem of being unable to realistically address the complexity of software systems and the laws of virus control. Based on the theory of two-layer complex networks, the present invention can prevent and control software viruses that spread quickly, widely, and with high uncertainty from a new perspective and method.

[0022] (3) Advantages and effects of the present invention

[0023] The advantage of this invention over existing technologies lies in its ability to prevent and control software viruses by leveraging the theory of two-layer complex networks. This method proposes a novel propagation model based on two-layer complex networks to analyze the dynamic propagation mechanisms of viruses in networked software systems and determine the impact of human awareness on software virus propagation. This method can prevent further spread of software viruses, thereby improving software reliability. Furthermore, the effectiveness of this model in preventing and controlling software virus propagation has been verified, which is of great significance for improving software reliability. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] Figure 1 Schematic diagram of the process of the present invention.

[0025] Figure 2 It is a visual display of the complex network model abstracted from the actual networked software data in the embodiment of the present invention.

[0026] Figures 3A-3B This is a visualization of the degree distribution of a complex network model constructed using actual data in an embodiment of the present invention.

[0027] Figure 4 This is a visual display of the improved infectious disease mathematical model in an embodiment of the present invention.

[0028] Figure 5 This is a visualization of the process in which the proportion of nodes (software) infected by viruses changes with the infection probability β in an embodiment of the present invention.

[0029] Figure 6 This is a visualization of the two-layer network constructed in an embodiment of the present invention that takes user behavior decisions into consideration.

[0030] Figures 7A-7C This is a visual representation of the mathematical model of the interaction between information and virus propagation processes in an embodiment of the present invention.

[0031] Figure 8 The AI ​​status of infected nodes and isolated nodes in the embodiment of the present invention * Visual display of the process of the proportion of states changing with the probability β of the software being infected by a virus. DETAILED DESCRIPTION

[0032] To make the technical problems, technical solutions and advantages to be solved by the present invention clearer, a detailed description will be given below in conjunction with the accompanying drawings and specific embodiments. The present invention provides a software virus prevention and control method based on a two-layer complex network. By considering that virus-infected software in a networked software system needs to be disinfected and isolated to prevent these infected software from spreading the virus more widely, the traditional virus propagation model is improved. At the same time, the mechanism of the influence of whether people are aware of the software being infected by a virus on the spread of software viruses is analyzed, and the critical conditions for suppressing the large-scale spread of software viruses under the two-layer complex network model are explored. It is also determined whether humans are aware of the role of preventing and controlling software virus propagation in networked software systems, thereby improving the security and reliability of the software system.

[0033] like Figure 1 As shown, a software virus prevention and control method based on a double-layer complex network of the present invention includes the following steps:

[0034] Step 1: Collect software data that relies on the network to run, extract the nodes abstracted by the networked software system and the relationships between nodes, and build a complex network model.

[0035] Before constructing a complex network model of a networked software system, it is necessary to determine the nodes and edges in the complex network model abstracted by the networked software system, and analyze the collected data containing a large number of PCs with installed software and networked software systems with data exchange, that is, to abstract each client into a node, and the software programs with virtual data interaction constitute the edges of the network, and focus on the topological structure of the mutual interaction between individuals in the system. The object of our study is a networked software system running on the Internet. The above method can be used to establish a software system network based on a complex network topology. In the example of the present invention, Gnutella P2P network protocol data was obtained from the website of the large-scale network data set collected by Stanford University (http: / / snap.stanford.edu / data / ). Gnutella is a protocol for distributed search and digital resource sharing. It is a point-to-point, non-central model. The data interaction between IDs described in this data file is directed, and the format of each line of ID is "(FromNode)ID(ToNode)ID", which means that the information is transmitted from (FromNode)ID to (ToNode)ID. Based on this network data, the abstractly constructed complex network is as follows: Figure 2 As shown in the figure, the node represents the client and is also a server. The server provides a client interface through which users can submit queries and view query results. At the same time, they can also accept query requests, search in local data, and return qualified results. The link edges between nodes represent the data transfer between two IDs.

[0036] The network is a directed network, and the average degree of the network is <k>=6.677, such as Figures 3A-3B As shown, the in-degree k in this complex network in The distribution and out-degree j out The distribution shows that the degree (number of connections) of most nodes is higher than a certain constant value, which is consistent with the characteristics of scale-free networks.

[0037] Step 2: Consider the scenario where a software program is attacked by a virus and improve the traditional propagation dynamics model based on the working principle of antivirus software.

[0038] Based on the complex network model constructed in step 1, consider the scenario after the software program is attacked by a virus. When the software shows virus characteristics, the user will start the anti-virus software with a certain probability. The present invention combines the working principle of anti-virus software and improves the traditional SIS (Susceptible-Infected-Susceptible) model. Figure 4 As shown in the figure, the node in state S is infected by its adjacent virus node with probability β. When the software shows virus characteristics, that is, the node in the complex network model is in state I (Infected), the user has a certain probability p * Start anti-virus software to disinfect the software infected by the virus. To avoid direct deletion of the software and cause losses to the user, the software program files will be temporarily stored in the quarantine area. * (Isolated) state, during the period when the user decides whether to perform antivirus (the duration is t * ), the program in the quarantine area cannot run, and the virus in the quarantine area cannot infect other parts of the system. The I state node that has not entered the quarantine area is (1-p * )μ probability of recovery to S susceptible state, with (1-p * )(1-μ) probability is still in the I infection state. During the isolation time t * After that, the software node is still in the infectious I state with probability m, and changes to the S state after successful disinfection with probability 1-m. The I state node recovers to the S state with probability μ. The propagation model is improved to SII * IS (Susceptible-Infected-Isolated-Infected / Susceptible) model.

[0039] Step 3: Simulate the virus propagation process in the networked software system, analyze the software virus propagation in the constructed complex network model, and explore the dynamic propagation mechanism of the virus.

[0040] Based on the complex network model constructed by networked software system data abstraction, Python simulation is carried out, combined with the improved virus propagation model (SII * IS) simulates and analyzes the spread of a software virus in a network. During program execution, the initial state assumes that 95% of the nodes in the network are in the Susceptible state and 5% of the nodes are in the Infected state. At the next moment, based on the propagation process described in step 2, the virus spread is simulated. During the Python program execution, in order to ensure the single variable principle, other parameters are set as μ = 0.8, p = 0. * = 0.3, m = 0.3, explore the virus propagation mechanism in the networked software system, calculate the virus at different anti-virus time t * The proportion of nodes (software) infected by viruses to the total number of nodes changes with the infection probability β under the condition. According to the Monte Carlo simulation results, the phase transition point when the proportion of infected nodes is greater than 0 is observed to determine the critical condition β under which the software virus will not spread in the system. C ,like Figure 5 As shown, below this threshold, viruses will not spread in the networked software system, and prevention and control of viruses in the software system can be achieved.

[0041] Step 4: Combine the user behavior-driven interactions in the networked software system, build an awareness propagation model based on whether the user is aware of the virus, and construct a two-layer complex network.

[0042] Due to the social nature of networked software systems, they can reflect and promote the development of real social relationships and the formation of communication activities, so that human behavior and software functions are organically integrated. In view of this scenario, the present invention constructs a consciousness propagation model UAU (Unawareness-Awareness-Unawareness, unconsciousness-awareness-unconsciousness) based on whether the user is aware of the virus, and constructs a two-layer complex network model, such as Figure 6 As shown in Figure 1, the lower layer represents the physical layer of a networked software system, where software viruses dynamically propagate. The upper layer, representing the information layer, describes the virtual communication network formed by the spread of information related to the software virus. The topologies of the two layers are different. Both layers are assumed to be unweighted and undirected. The one-to-one mapping between nodes corresponds to the dynamic interrelationship between the two layers: each node on one layer is individually mapped to the corresponding node on the other layer.

[0043] Modeling the interaction between the two processes. On the one hand, the present invention assumes that the user will immediately realize that the software has been attacked by a virus. Therefore, when the node of the virus propagation layer changes to the I state, the corresponding node of the virtual communication layer will automatically change to the A state and spread the virus related information. Based on this assumption, the present invention does not have the unconscious and infected (UI) states. The transition between the A state and the U state is as follows: Figure 7A As shown, the US state changes to AS with a probability of θ, and the A state changes to U with a probability of δ.

[0044] When the nodes in the virtual communication layer are in state A, measures will be taken to prevent virus attacks. Therefore, the probability of nodes in different states in the virtual communication layer being infected by viruses in the physical software layer is different. The present invention considers the infection attenuation factor γ (0≤γ≤1) to adjust the probability of nodes being infected. Here, the infection rates of nodes in state U and state A are denoted as β U =β and β A =γβ U =γβ. The propagation model of the entire system after considering the influence of the communication layer is as follows: Figure 7B As shown in the model, each individual has four different states: unconscious and susceptible (US), conscious and susceptible (AS), conscious and infected (AI), and conscious and isolated (AI * ). The present invention does not consider the unconscious and infected (UI) states, based on our assumption that individuals in the I state will automatically become the A state. Figure 7B Individuals in the US state are β U The probability of becoming UI is that individuals in state I will automatically change to state A, while individuals in state AS will change to state A with a probability of β A The probability of becoming AI, the individual in AI state is p * The probability of being detected by antivirus software alone * After the antivirus process is completed, it becomes AI * , with (1-p * )(1-μ) becomes AI with a probability of (1-p * )μ’s probability becomes AS, and then AI * An individual becomes AI with a probability of m and becomes AS with a probability of 1-m. Among them, an individual that becomes AI becomes AS with a probability of μ and becomes AI with a probability of 1-μ.

[0045] The present invention defines A={a ij } and B={b ij } are respectively used as the adjacency matrices of the virtual communication layer and the virus propagation layer, where there is a link between node i and node j, then the element a in the matrix ij =1,b ij =1, otherwise a ij =0,b ij = 0. At time t, each node i is in one of the four states with a certain probability, which are expressed as and In the virtual communication layer, we use r i (t) represents the probability that individual i in state U is not notified by any neighbor. In the virus propagation layer, we use and represents the probability that node i, which is unaware and aware of the S state, is not infected by any neighboring virus node j. According to the above definition, r i (t), and It can be expressed as:

[0046]

[0047]

[0048]

[0049] in In addition, the following normalization conditions are met at each time step:

[0050]

[0051] Based on the above probabilities, the probability transmission tree of the nodes in the four possible states on the two-layer network is as follows: Figure 7C As shown in Figure (a), the individual in AS changes to US with a probability of δ and continues to maintain the AS state with a probability of 1-δ, where US is q U The probability of continuing to maintain the US state is 1-q U The probability of becoming AI state, while the individual in AS state is q A The probability of maintaining the AS state is 1-q A Figure (b) shows that individuals in the AI ​​state continue to maintain the AI ​​state with a probability of δ, and change to the UI state with a probability of 1-δ. The individuals in the AI ​​state continue to maintain the AI ​​state with a probability of (1-p * )μ becomes AS with the probability p * The probability of becoming AI * , with (1-p * )(1-μ) probability of becoming AI. Since we assume that individuals in state I will automatically become state A, individuals in state UI will become AI with a probability of 1. Figure (c) shows that individuals in state US will become AI with a probability of r i The probability of becoming US is 1-r i The probability of continuing to maintain the AS state, where US is q U The probability of continuing to maintain the US state is 1-q U The probability of becoming AI state, while the individual in AS state is q A The probability of maintaining the AS state is 1-q A The probability of becoming AI state. Figure (d) shows the AI * An individual in state changes to US with probability m and changes to AS with probability 1-m.

[0052] Step 5: Analyze the impact of human knowledge on the spread of software viruses, so as to determine the role of human knowledge in preventing and controlling the spread of software viruses in networked software systems.

[0053] In a two-layer network constructed by abstracting the networked software system and the information layer, software viruses are dynamically propagated in the virus propagation layer based on the above propagation model. At the same time, combined with people's understanding of whether the software infected by the virus in the networked software system is aware (aware / aware state (A) state) or unaware / unconscious state (U) state), this paper explores the impact of the two states on the spread of software viruses and determines whether they can effectively inhibit the spread of software viruses in the networked software system. It is mainly based on Figure 7C The described probability transmission tree is simulated by Monte Carlo simulation.

[0054] In this example, when the Python program is running, the state (AI, AI * ) node ratio changes with the virus transmission rate β, and it is found that the virus is in UAU-SII * The critical threshold β of propagation in the IS model C ,During the simulation, we focus on exploring the impact of human knowledge, that is, the impact of the information propagation rate θ of the US state changing to AS on the proportion of infected nodes, so other parameters are fixed as μ=0.8,δ=0.5,p * =0.3, m=0.3, γ=0.5(β U =β,β A =γβ U =0.5β), t*=100, the simulation results are as follows Figure 8 As shown in the figure, the effects of different information propagation rates θ (θ = 0.5, 0.8) are obvious. Increasing the information propagation rate of people knowing about software viruses in networked software systems can increase the threshold β for large-scale propagation of software viruses. C , that is, when it is easier to realize the existence of the virus (the probability of changing from US to AS is greater, θ = 0.8), the infected node (AI state) and the isolated node (AI * The smaller the proportion of the virus in the networked software system, the higher the critical virus propagation rate β C The larger the value, the more difficult it is for the virus to spread in the system. This result shows that whether people are aware of the information or not has a certain preventive and control effect on the spread of software viruses in networked software systems. The higher the level of people's awareness, the greater the information dissemination rate, which can increase the threshold value β for the outbreak of software virus spread. C , which can improve the reliability of the software system to a certain extent.

[0055] Through the above steps, a software virus prevention and control method based on a two-layer complex network can be constructed. In this technology, the present invention uses two-layer complex network theory to prevent and control software viruses. This method abstracts network modeling of networked software system data, considers scenarios after software is attacked by viruses, and combines the working principles of antivirus software to add an isolation state to the traditional software virus propagation model. This simulates isolating the virus-infected software from other parts of the networked software system and performs corresponding antivirus processing to prevent the virus from spreading more widely, thereby better maintaining the software and improving its reliability. Furthermore, a consciousness propagation model is constructed to determine the impact of people's awareness of virus-infected software in networked software systems on the spread of software viruses. The critical threshold for software virus outbreaks in the two-layer complex network model is evaluated, and the impact of human awareness on software virus propagation is factored into the model, providing a new research direction and method for preventing software viruses and preventing their further spread. The portions not described in detail in this invention belong to the known art in the field.

[0056] The above description is only part of the specific implementation methods of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by any person familiar with the art within the technical scope disclosed in the present invention should be covered by the protection scope of the present invention.< / k>

Claims

1. A software virus prevention and control method based on a two-layer complex network, characterized by: Here are the steps: Step 1: Collect data on software that relies on the network to run, identify the nodes and edges in the complex network model abstracted by the networked software system, and build a complex network model; the nodes in the network represent the computer or server ID where the software is installed, and the two node IDs that exchange data are abstracted as an edge in the network; Step 2: Set the probability that a user will perform antivirus processing on the infected software to p * The antivirus duration is the time the software is stored in the quarantine area, which is t * , the traditional virus propagation model SIS model is improved to SII * IS model: Software in the susceptible state S can be infected by its neighbors in the I state. The probability of the software being infected is β, which is the virus transmission rate. Combined with the working principle of antivirus software, p * Probability software is in I * Isolation state, the I state node that has not entered the isolation area is (1-p * )μ probability to recover to S state, with (1-p * )(1-μ) probability is still in state I; t * After a certain time, the software is removed from the quarantine area. Since antivirus software cannot detect and kill all viruses, when the software is restarted, the software node becomes infectious with probability m, that is, the I infected state, or the virus has been detected and killed, that is, it becomes the S susceptible state with probability 1-m. After that, the I state node recovers to the S susceptible state with probability μ, and remains in the I infected state with probability 1-μ. Step 3: Simulate the virus propagation process in the networked software system, analyze the software virus propagation in the constructed complex network model, and explore the dynamic propagation mechanism of the virus; Step 4: Combine user behavior-driven interactions in the networked software system, build an awareness propagation model based on whether users are aware of the virus, and construct a two-layer complex network; Step 5: Analyze the impact of user knowledge on the spread of software viruses, thereby determining the role of user knowledge in preventing and controlling the spread of software viruses in networked software systems; In step 4, the following is done: In a two-layer complex network model, one layer represents the virus propagation layer of the networked software system, and the other layer is a virtual communication network formed for the diffusion of information related to the software virus. The topologies of the two layers are different; the two layers are defined as unweighted and undirected, and the one-to-one mapping between nodes corresponds to the dynamic relationship between the two layers. Each node on one layer is individually mapped to the corresponding node on the other layer, that is, the two layers have the same nodes. In step 5, the approach is as follows: Under the dynamic propagation mechanism of software viruses in networked software systems, by using the micro-Markov chain method, based on the four different states that individuals may be in in this model: unconscious and susceptible US, conscious and susceptible AS, conscious and infected AI, and conscious and isolated AI * , generate a probability tree to describe the possible transition states between software virus propagation and whether the user knows that the software is infected by the virus. Then, Monte Carlo numerical simulation is performed to calculate the state between AI and AI. * The phase transition process of the ratio of nodes in the double-layer network under different β,θ parameters, it is found that the virus is in UAU-SII * The critical threshold β of propagation in the IS model C By simulating the virus propagation process through Monte Carlo simulation, we can increase the information propagation rate θ of users about the existence of software viruses in networked software systems and explore whether it can increase the threshold β for large-scale spread of software viruses. C .

2. The software virus prevention and control method based on a double-layer complex network according to claim 1 is characterized in that: In step 3, the following is done: Use Python to simulate the propagation process of software viruses in a complex network model constructed by abstracting the networked software system, analyze the simulation results, and thus determine the dynamic propagation mechanism of software viruses in the networked software system, and calculate the probability of the virus spreading under different probability p. * The proportion of infected software nodes to the total nodes under the condition, and the infection probability β changes with p * and t * By exploring the virus propagation mechanism in networked software systems, we can determine the critical conditions under which software viruses will not spread in the system.

3. The software virus prevention and control method based on a double-layer complex network according to claim 1 is characterized in that: In step 4, the approach is as follows: based on whether the user is aware of the virus or not, a consciousness propagation model UAU model is constructed, and a two-layer complex network model is constructed, where the U state is the unaware state, the individual does not know the virus-related information and will not react to prevent the virus, while the A state is the informed state, the individual knows that the software has been attacked by the virus and will take preventive measures to reduce the risk of virus spread; the U state individual will be informed of the virus-related information by the neighbor in the A state, and the probability of becoming the A state is θ, and the probability of the A state individual returning to the U state is δ.

4. The software virus prevention and control method based on a double-layer complex network according to claim 1 is characterized in that: The infection attenuation factor γ is set to adjust the probability of the node being infected, 0≤γ≤1; here, the infection rates of the U-state node and the A-state node are denoted as β U =β and β A =γβ U =γβ; Each individual has four different states: unconscious and susceptible US, conscious and susceptible AS, conscious and infected AI, and conscious and isolated AI * ; Unconscious and infected UI states are not considered here. It is assumed that individuals in state I will automatically change to state A.

5. The software virus prevention and control method based on a double-layer complex network according to claim 4 is characterized in that: Definition A={a ij } and B={b ij } are respectively used as the adjacency matrices of the virtual communication layer and the virus propagation layer, where there is a link between node i and node j, then the element a in the matrix ij =1,b ij =1, otherwise a ij =0,b ij = 0; at time t, each node i is in one of the four states with a certain probability, which are expressed as and In the virtual communication layer, use r i (t) represents the probability that individual i in state U is not notified by any neighbor; in the virus propagation layer, we use and represents the probability that node i, which is unaware and aware of the S state, is not infected by any neighboring virus node j; according to the above definition, r i (t), and Expressed as: in In addition, the following normalization conditions are met at each time step:

Citation Information

Patent Citations

  • Double-layer network propagation model constructing method based on individual sensitivity and mass media influence

    CN109903853A

  • Epidemic propagation control method for implementing isolation by considering individual infection states and individual attributes

    CN112599248A