Malicious program evolution detection method based on biological evolution simulation

By building a malicious program evolution model and using biological evolution simulation technology to evaluate the evasion detection ability and mutability of malicious programs, the efficiency and accuracy of existing malicious program detection technologies are solved in dealing with the evolution of malicious programs, and more efficient and accurate malicious program detection is achieved.

CN120068070APending Publication Date: 2025-05-30HUBEI CENT CHINA TECH DEV OF ELECTRIC POWER
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510103637.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-22
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

When existing malicious program detection technologies cope with challenges such as the diversity of mutants, evasion detection capabilities, and high computing resource consumption in the evolution of malicious programs, the detection efficiency and accuracy are low, increasing network security risks.

Method used

The evolution detection method of malicious programs based on biological evolution simulation is adopted. By constructing a malicious program evolution model, the malicious program is represented as a gene sequence, the fitness function is used to evaluate the ability to evade detection, and the evolutionary behavior of malicious programs is simulated through dynamically regulated cross-and-mutation strategies.

Benefits of technology

It improves the accuracy and efficiency of self-replicating and mutated malicious programs, reduces missed detection rates and computing resource consumption, and enhances the detection ability of unknown or new malicious programs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068070A_ABST
    Figure CN120068070A_ABST
Patent Text Reader

Abstract

The invention provides a rogue program evolution detection method based on biological evolution simulation, which comprises the following steps of: abstracting a rogue program into a gene sequence, simulating a variation process of the rogue program by adopting an evolutionary algorithm, and comprehensively evaluating the escape detection capability of the program by utilizing a fitness function. According to the method, the escape detection capability of an individual is calculated, and the calculation of the overall variation degree is introduced, so that the evolution characteristics of a program are reflected more accurately. By dynamically adjusting crossover and mutation strategies and combining a context-aware mutation tracking mechanism, the method remarkably improves the detection capability of hidden and complex malicious programs, and effectively solves the problems of high false alarm rate and low detection accuracy in a traditional method; according to the method, the rogue program detection comprehensiveness and accuracy are enhanced, and the rogue program concealment, propagation efficiency and resource consumption comprehensive evaluation capability are improved through multi-target fitness optimization, so that the network security protection level is remarkably improved in practical application.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of malicious program detection, and specifically, to a malicious program evolution detection method based on biological evolution simulation. Background Art

[0002] Currently, in existing malicious program detection technologies, common methods include detection means based on signature matching and behavior analysis. These methods are relatively effective in dealing with known malicious programs, but have low detection efficiency for new malicious programs and their variants. This allows many malicious programs to evade traditional detection means through simple mutations or disguises, increasing the risk of network security.

[0003] As the complexity of malicious programs continues to increase, existing detection methods are unable to cope with these complex changes. Traditional methods often rely on fixed features or rules for detection, and these features or rules are prone to failure when faced with evolving malicious programs, resulting in missed detections. In addition, with the explosion of data volume and the number of malicious programs, the detection speed has not increased accordingly. This situation has led to a decrease in detection efficiency, further exacerbating the difficulty of network security protection. Summary of the Invention

[0004] The purpose of the present invention is to provide a malicious program evolution detection method based on biological evolution simulation, which solves the challenges of mutation diversity, detection evasion ability, and high computing resource consumption in the process of malicious program evolution in existing malicious program detection technologies, and improves the detection accuracy and efficiency of self-replicating and mutating malicious programs.

[0005] A malicious program evolution detection method based on biological evolution simulation includes the following steps:

[0006] (1) Construct a malicious program evolution model, which represents a malicious program as a gene sequence G i ={g i,1 , g i,2 ,..., g i,j ...,, g i,n}, where g i,j represents the j-th gene of the malicious program in the gene sequence, representing a code segment or behavioral feature of the program;

[0007] (2) Use a fitness function f(G i ) to evaluate the detection evasion ability of the malicious program. The fitness function is calculated as follows:

[0008]

[0009] where w j is for g i,jThe weight of S(g i,j ), S(g i ) is the evasion detection ability score, λ is the adjustment coefficient, and M(G i ) is the overall variability of the gene sequence G

[0010] Furthermore, the calculation of the evasion detection ability score S(g i,j ) includes the following steps:

[0011] (1) Calculate the static analysis score A(g i,j ) and the dynamic analysis score D(g i,j );

[0012] (2) Calculate the evasion detection ability score based on the static analysis score A(g i,j ) and the dynamic analysis score D(g i,j ):

[0013] S(g i,j ) = α·A(g i,j ) + β·D(g i,j )

[0014] where α and β are the weights of static analysis and dynamic analysis respectively.

[0015] Furthermore, the formula for calculating the overall variability M(G i ) of the gene sequence G i ) is as follows:

[0016]

[0017] where |g i,j - g i-1,j | represents the difference between the current gene fragment and the previous generation gene fragment.

[0018] Furthermore, in the process of constructing the malicious program evolution model, a dynamically adjusted crossover and mutation strategy is adopted to simulate the evolution behavior of the malicious program. The crossover and mutation strategy is specifically as follows:

[0019] (1) Calculate the crossover probability P c based on the fitness value. The calculation formula is as follows:

[0020]

[0021] where f max is the maximum fitness value of the current generation, and N is the number of individuals in the current generation;

[0022] (2) Calculate the mutation rate P m based on the fitness value. The calculation formula is as follows:

[0023]

[0024] Among them, f(G i ) is the fitness value of gene sequence G i .

[0025] Furthermore, during the malicious program evolution simulation, through evolutionary behavior monitoring, a context-aware mutation tracking mechanism is adopted to track the mutation behavior of malicious programs. The mutation tracking mechanism is specifically as follows:

[0026] (1) Extract the context features C i during program execution. The context features C i include environment variables, system status, and user behavior;

[0027] (2) Based on the Markov chain model, model the mutation path under the context, and use the transition probability matrix P(C i → C i+1 ) to describe the path change.

[0028] Furthermore, during the evolution simulation and mutation tracking of malicious programs, an abnormal path recognition mechanism is adopted to identify and analyze the behavior path of malicious programs. The abnormal path recognition mechanism is specifically as follows:

[0029] When the transition probability P(C i → C i+1 ) of the mutation path is lower than the preset threshold, identify this path as an abnormal path and mark it as a potential malicious program.

[0030] Furthermore, a multi-objective fitness optimization mechanism is introduced to comprehensively evaluate malicious programs. The optimization mechanism includes the following steps:

[0031] Comprehensively evaluate the concealment, propagation efficiency, and resource consumption of malicious programs. The fitness function is calculated as follows:

[0032] f multi (G i ) = γ 1 ·H(G i ) + γ 2 ·E(G i ) + γ 3 ·C(G i )

[0033] Among them, H(G i ) is the concealment score, E(G i ) is the propagation efficiency score, C(G i ) is the resource consumption score, γ 1 , γ 2 , γ 3 are weight coefficients;

[0034] The concealment score H(G i ) is calculated based on the following formula:

[0035]

[0036] where P d (B i,k ) represents the detection probability of the k-th detection mechanism for the program behavior B i,k , and m is the total number of detection mechanisms;

[0037] The propagation efficiency score E(G i ) is calculated based on the following formula:

[0038]

[0039] where R t (G i ) is the number of nodes infected by the program at time t, and T t (G i ) is the time consumed for the program to spread;

[0040] The resource consumption score C(G i ) is calculated based on the following formula:

[0041]

[0042] where R p (G i ) represents the consumption of the program on the resource type p, and P is the total number of resource types.

[0043] The present invention has the following advantages:

[0044] 1. Biological evolution simulation: By simulating the evolutionary behavior of malicious programs and introducing the theory of biological evolution, the detection system can dynamically adapt to the diverse mutations of malicious programs, improving the detection accuracy.

[0045] 2. Multi-objective optimization: Using the multi-objective fitness optimization mechanism, comprehensively evaluating the concealment, propagation efficiency and resource consumption of malicious programs, realizing more comprehensive detection of malicious programs and reducing the missed detection rate.

[0046] 3. Efficient resource management: Through the dynamic adjustment strategy based on the fitness function, optimizing the resource allocation in the detection process, reducing the computational resource consumption of the detection system, and improving the detection efficiency at the same time.

[0047] 4. Variant behavior monitoring: Introducing a context-aware variant tracking mechanism to accurately identify the abnormal variant paths of malicious programs and enhancing the detection ability for unknown or new malicious programs.

[0048] 5. Adaptive detection: The malicious program evolution model based on the genetic algorithm enables the detection system to adapt to the evolution process of malicious programs and effectively cope with the rapid evolution and mutation of malicious programs. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] Figure 1 is the flowchart for calculating the score of the evasion detection ability in an embodiment of the present invention;

[0050] Figure 2 is the flowchart for constructing the malicious program evolution model in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0051] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0052] An embodiment of the present invention provides a malicious program evolution detection method based on biological evolution simulation, including the following steps:

[0053] (1) Construct a malicious program evolution model, where the evolution model represents the malicious program as a gene sequence G i ={g i,1 , g i,2 ,..., g i,j ...,, g i,n}, where g i,j represents the j-th gene of the malicious program in the gene sequence, representing a code segment or behavioral characteristic of the program;

[0054] (2) Use a fitness function f(G i ) to evaluate the evasion detection ability of the malicious program. The fitness function is calculated as follows:

[0055]

[0056] where w j is the weight of g i,j , S(g i,j ) is the score of the evasion detection ability, λ is a regulation coefficient, and M(G i ) is the overall mutation degree of the gene sequence G i .

[0057] Among them, the evasion detection ability score S(g i,j) The calculation includes the following steps (as Figure 1 shown):

[0058] (1) Calculate the static analysis score A(g i,j ) and the dynamic analysis score D(g i,j );

[0059] (2) Calculate the evasion detection ability score according to the static analysis score A(g i,j ) and the dynamic analysis score D(g i,j ):

[0060] S(g i,j ) = α·A(g i,j ) + β·D(g i,j )

[0061] where α and β are the weights of static analysis and dynamic analysis respectively.

[0062] Among them, the overall variability M(G i ) of the gene sequence G i ) is calculated by the following formula:

[0063]

[0064] |g i,j - g i-1,j | represents the difference between the current gene segment and the previous generation gene segment.

[0065] Furthermore, in the process of constructing the malicious program evolution model, a dynamically adjusted crossover and mutation strategy (as Figure 2 shown) is adopted to simulate the evolution behavior of the malicious program. The crossover and mutation strategy is specifically as follows:

[0066] (1) Calculate the crossover probability P c based on the fitness value. The calculation formula is as follows:

[0067]

[0068] where f max is the maximum fitness value of the current generation, and N is the number of individuals in the current generation;

[0069] (2) Calculate the mutation rate P m based on the fitness value. The calculation formula is as follows:

[0070]

[0071] where f(G i ) is the fitness value of the gene sequence G i .

[0072] Furthermore, during the malicious program evolution simulation, through evolutionary behavior monitoring, a context-aware mutation tracking mechanism is adopted to track the mutation behavior of malicious programs. The mutation tracking mechanism is as follows:

[0073] (1) Extract the context features C during program execution i , where the context features C i include environment variables, system status, and user behavior;

[0074] (2) Based on the Markov chain model, model the mutation path under the context, and use the transition probability matrix P(C i →C i+1 ) to describe the path change.

[0075] Among them, during the evolution simulation and mutation tracking of malicious programs, an abnormal path recognition mechanism is adopted to identify and analyze the behavior path of malicious programs. The abnormal path recognition mechanism is as follows:

[0076] When the transition probability P(C i →C i+1 ) of the mutation path is lower than the preset threshold, identify this path as an abnormal path and mark it as a potential malicious program.

[0077] Furthermore, a multi-objective fitness optimization mechanism is introduced to comprehensively evaluate malicious programs. The optimization mechanism includes the following steps:

[0078] Comprehensively evaluate the concealment, propagation efficiency, and resource consumption of malicious programs. The fitness function is calculated as follows:

[0079] f multi (G i ) = γ 1 ·H(G i ) + γ 2 ·E(G i ) + γ 3 ·C(G i )

[0080] Among them, H(G i ) is the concealment score, E(G i ) is the propagation efficiency score, C(G i ) is the resource consumption score, γ 1 , γ 2 , γ 3 are weight coefficients.

[0081] The concealment score H(G i ) is calculated based on the following formula:

[0082]

[0083] Among them, P d (B i,k ) represents the detection probability of the k-th detection mechanism for the program behavior B i,k , and m is the total number of detection mechanisms.

[0084] The propagation efficiency score E(G i ) is calculated based on the following formula:

[0085]

[0086] Among them, R t (G i ) is the number of nodes infected by the program at time t, and T t (G i ) is the time consumed for the program to spread.

[0087] The resource consumption score C(G i ) is calculated based on the following formula:

[0088]

[0089] Among them, R p (G i ) represents the consumption of the program on the resource type p, and P is the total number of resource types.

[0090] An embodiment of the present invention proposes a malicious program evolution detection method based on biological evolution simulation, and verifies the effectiveness of the method through a series of experiments. The experiments are carried out in a simulated complex network environment, aiming to test the performance of the method of the present invention in real network scenarios, including detection accuracy, efficiency, and resource consumption, etc.

[0091] Experimental environment:

[0092] The experiments are carried out in the following configurations:

[0093] Computing nodes: 20 servers, each server is configured with a 32-core CPU, 128GB of memory, and 2TB of NVMe SSD storage.

[0094] Network topology: Simulate a virtual network environment containing 100 subnets, each subnet contains 20 - 200 virtual machines, and the operating systems include Windows 10, Ubuntu 20.04, CentOS 7, and macOS 11.

[0095] Malicious Program Samples: 10,000 malicious program samples were used in the experiment. These samples have undergone multiple rounds of mutation processing, covering various types of malicious programs such as viruses, worms, Trojans, and ransomware, and new variants are continuously generated during the experiment.

[0096] Detection System: A distributed detection system constructed based on the method of the present invention is deployed in 20 servers to achieve real-time detection of malicious programs through a high-performance computing cluster.

[0097] Experimental data and analysis:

[0098] The experimental data was collected through the detection results of the detection system in the simulation environment. The following are the main experimental results:

[0099] Step 1: Construct an evolutionary model of malicious programs

[0100] In this step, malicious programs are represented by gene sequences. Each gene sequence represents the characteristics of a malicious program sample, and each malicious program sample has multiple variants.

[0101] Table 1 Malicious Program Gene Sequences

[0102]

[0103] Step 2: Use a fitness function to evaluate the ability of malicious programs to evade detection

[0104] In this step, each malicious program is evaluated through a fitness function based on the score of the ability to evade detection.

[0105] Example Calculation:

[0106] For the first sample, assume its static analysis score A(g i,j ) and dynamic analysis score D(g i,j ) are as follows:

[0107] Table 2 Malicious Program Gene Fragments

[0108]

[0109] Comprehensive Score:

[0110] S(G 1 ) = {0.65, 0.65, 0.65, 0.65}

[0111] Assume the weight w j = [0.1, 0.2, 0.3, 0.4], and M(G 1 ) = 0.14. The fitness function is calculated as follows:

[0112] f(G 1) = 0.1·0.65 + 0.2·0.65 + 0.3·0.65 + 0.4·0.65 + 0.5·0.14 = 0.75

[0113] Step 3: Calculate the overall variability of the gene sequence

[0114] The overall variability M(G i ) is calculated as follows:

[0115]

[0116] Assume that the gene sequence of the previous generation is G 0 = {0.4, 0.6, 0.3, 0.7}, then the variability of the first sample is:

[0117]

[0118] Step 4: Dynamically adjust the crossover and mutation strategies

[0119] For 20 servers, the experiment uses the following calculation formula to dynamically adjust the crossover probability P c and the mutation rate P m .

[0120] Crossover probability calculation:

[0121]

[0122] Mutation rate calculation:

[0123]

[0124] Assume that the fitness values of the current 10,000 malicious programs are f(G 1 ), f(G 2 ),..., f(G 10000 ), and the maximum fitness is f max = 0.95. Then the crossover probability and mutation rate of each generation are calculated according to the formula.

[0125] Step 5: Context-aware mutation tracking mechanism

[0126] In the experiment, the context features C i during program execution include the operating system of the virtual machine, network status, etc. Use the Markov chain model to model the mutation path and calculate the transition probability matrix P(C i → C i+1 ).

[0127] Table 3 Transition probability matrix

[0128]

[0129] When the transition probability is lower than a preset threshold (e.g., 0.7), it is identified as an abnormal path.

[0130] Step 6: Abnormal path identification

[0131] Suppose in the transition probability matrix P(C i →C i+1 ), P(C 1 →C 2 ) = 0.6 which is lower than the threshold 0.7. Therefore, the path C 1 →C 2 is marked as abnormal.

[0132] Step 7: Multi-objective fitness optimization

[0133] The comprehensive evaluation of malicious programs considers concealment, propagation efficiency, and resource consumption. The fitness function is calculated as:

[0134] f multi (G i ) = γ 1 ·H(G i ) + γ 2 ·E(G i ) + γ 3 ·C(G i )

[0135] Table 4 Malicious program evaluation

[0136]

[0137] Step 8: Malicious program detection and response

[0138] The final detection results of the experiment are effectively optimized through methods such as multi-objective fitness calculation, mutation degree evaluation, and context-aware path monitoring, enabling the system to quickly and accurately identify and defend against malicious programs in the actual application environment.

[0139] Table 4 Evaluation table of the final detection effect

[0140]

[0141] According to the experimental results, the present invention has the following innovations:

[0142] 1. Biological evolution simulation mechanism: Traditional malicious program detection methods mainly rely on signature and behavior analysis, and usually have difficulty dealing with malicious programs that mutate rapidly and self-replicate. These methods lack dynamic adaptability, resulting in reduced detection accuracy, especially in the case of continuously evolving malicious programs. The present invention introduces a biological evolution simulation mechanism, which simulates the self-replication and mutation behavior of malicious programs by emulating their evolutionary paths. This mechanism enables the detection system to dynamically track the mutation trends of malicious programs and accurately identify their mutation behaviors, thereby significantly improving the detection accuracy and adaptability.

[0143] 2. Multi-objective fitness optimization: Some malicious program detection methods usually only focus on optimizing certain aspects of performance, such as detection accuracy or resource consumption, lacking comprehensive consideration. The strategy of a single optimization objective may sacrifice other performances when improving a certain indicator, resulting in poor performance of the detection system in complex scenarios. The present invention adopts a multi-objective fitness optimization strategy, comprehensively considering multiple key indicators such as concealment, propagation efficiency, and resource consumption. This innovative strategy enables the detection system to balance various requirements in complex mutation scenarios, improve the overall detection effect, and overcome the limitations of traditional methods.

[0144] 3. Mutation depth analysis: Traditional detection methods lack the analysis of the mutation depth of malicious programs and usually can only detect surface mutations, unable to deeply understand the mutation path and genetic stability. This makes it easy for the detection system to miss detections and generate false positives when dealing with malicious programs with deep mutations and multi-generation mutations. The present invention introduces the analysis of mutation depth and genetic stability, and by deeply tracking the mutation path of malicious programs, evaluates their evolutionary degree. This innovation enables the detection system to accurately identify highly variable malicious programs and maintain high detection accuracy during multiple generations of evolution, effectively reducing the miss detection rate.

[0145] 4. Efficient resource management strategy: Existing malicious program detection methods usually face the problem of excessive consumption of computing resources when processing a large number of samples. Especially in a complex network environment, unbalanced resource allocation may lead to low detection efficiency. The present invention adopts a system load balancing and resource dynamic scheduling mechanism, and by adjusting the allocation of computing resources in real time, optimizes the resource usage during the detection process. This strategy not only improves the detection efficiency but also significantly reduces the occupation of computing resources, achieving the dual goals of resource conservation and performance optimization.

[0146] 5. Complex scenario detection ability: When dealing with complex network environments and multi-variation scenarios, traditional detection systems usually show unstable performance, are prone to detection delays or performance degradation, which limits their use in complex application environments. The detection system of the present invention can maintain high detection performance and stability in complex scenarios such as multi-node synchronization and random hybrid mutation. This innovation demonstrates the excellent anti-interference ability of the detection system in complex environments, ensuring its wide application in changing network environments.

[0147] As described above, the above are only specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

Claims

1. A method for detecting malicious program evolution based on biological evolution simulation, characterized in that: The following steps are involved: (1) Constructing a malware evolution model, wherein the malware is represented as a gene sequence G i = {g i,1 , g i,2 , ..., g i,j ..., g i,n }, where g i,j Indicates the jth gene of the malicious program in the gene sequence, representing the code fragment or behavioral characteristics of the program; (2) Using the fitness function f(G i ) evaluates the ability of malicious programs to evade detection. The fitness function is calculated as follows: Among them, w j g i,j The weight of S(g i,j ) is the score of evasion detection capability, λ is the adjustment coefficient, M(G i ) is the gene sequence G i 's overall variability.

2. The detection method according to claim 1, characterized in that: The evasion detection ability score S(g i,j ) calculation includes the following steps: (1) Calculate the static analysis score A(g i,j ) and dynamic analysis score D(g i,j ); (2) According to the static analysis score A(g i,j ) and dynamic analysis score D(g i,j ) Calculate the evasion score: S(g i,j )=α·A(g i,j )+β·D(g i,j ) Among them, α and β are the weights of static analysis and dynamic analysis respectively.

3. The detection method according to claim 1, characterized in that: The gene sequence G i The overall variability M(G i ) is calculated as follows: Among them, |g i,j -g i-1,j |Indicates the difference between the current gene fragment and the previous generation gene fragment.

4. The detection method according to claim 1, characterized in that: In the process of constructing the malware evolution model, a dynamically adjusted crossover and mutation strategy is used to simulate the evolutionary behavior of the malware. The crossover and mutation strategy is specifically as follows: (1) Calculate the crossover probability P based on the fitness value c , the calculation formula is as follows: where f max is the maximum fitness value of the current generation, and N is the number of individuals in the current generation; (2) Calculate the mutation rate P based on the fitness value m , the calculation formula is as follows: Among them, f(G i ) is the gene sequence G i的 Fitness value.

5. The detection method according to claim 1, characterized in that: In the process of malware evolution simulation, the evolution behavior is monitored and a context-aware mutation tracking mechanism is used to track the mutation behavior of the malware. The mutation tracking mechanism is as follows: (1) Extracting context features C during program execution i , the context feature C i Including environment variables, system status, and user behavior; (2) Based on the Markov chain model, the mutation path under the context is modeled and the transition probability matrix P(C i →C i+1 ) describes the path changes.

6. The detection method according to claim 5, characterized in that: In the process of evolution simulation and mutation tracking of malicious programs, an abnormal path identification mechanism is used to identify and analyze the behavior path of malicious programs. The abnormal path identification mechanism is as follows: When the transition probability P(C i →C i+1 ) is lower than a preset threshold, the path is identified as an abnormal path and marked as a potential malicious program.

7. The detection method according to claim 1, characterized in that: A multi-objective fitness optimization mechanism is introduced to comprehensively evaluate malicious programs. The optimization mechanism includes the following steps: Comprehensively evaluate the concealment, propagation efficiency and resource consumption of malicious programs. The fitness function is calculated as follows: f muulti (G i )=γ1·H(G i )+γ2·E(G i )+γ3·C(G i ) Among them, H(G i ) is the concealment score, E(G i ) is the transmission efficiency score, C(G i ) is the resource consumption score, γ1, γ2, γ3 are weight coefficients.

8. The detection method according to claim 7, characterized in that: The concealment score H(G i ) is calculated based on the following formula: Among them, P d (B i,k ) represents the kth detection mechanism for program behavior B i,k The detection probability of m is the total number of detection mechanisms; The transmission efficiency score E(G i ) is calculated based on the following formula: Among them, R t (G i ) is the number of nodes infected by the program at time t, T t (G i ) is the time consumed by program propagation; The resource consumption score C(G i ) is calculated based on the following formula: Among them, R p (G i ) represents the consumption of the program on resource type p, where P is the total number of resource types.