Malware Propagation Simulation via Network Contact Rates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional malware protection mechanisms are reactive and often fail to detect malware in a timely manner, leading to delayed mitigation measures.
Innovation Solution
A computer-implemented method for simulating malware propagation through a network, where the simulation uses contact rates specific to each connection between computers, based on real network traffic data, to model the spread of malware and inform more effective protection measures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of time
If conventional reactive malware protection mechanisms are used, then implementation simplicity is maintained, but detection timeliness and effectiveness deteriorate
Solution Approach 1:
The patent applies preliminary action by simulating malware propagation before actual infections occur. The system models potential infection pathways and identifies vulnerable nodes in advance, enabling proactive deployment of protection measures rather than reacting after detection. This allows organizations to prepare mitigation strategies ahead of time, significantly reducing the time loss associated with reactive approaches.
2Reliability
If generic malware protection measures are deployed, then deployment speed is maintained, but protection effectiveness deteriorates
Solution Approach 1:
The patent implements local quality by assigning unique contact rates to each edge in the network graph, reflecting the specific communication characteristics between node pairs. Instead of using a uniform infection rate across the entire network, the system models local variations in traffic patterns, protocol usage, and interaction frequency. This localized approach significantly improves protection effectiveness by targeting specific vulnerable connections rather than applying generic measures uniformly.
Solution Approach 2:
The patent applies parameter changes by using different contact rates for different edges based on their specific traffic characteristics. The system varies the infection probability parameter locally according to each connection's actual usage patterns, data volume, and communication frequency. This dynamic parameter adjustment allows the simulation to reflect real-world variability in malware transmission risks across different network segments.
3Measurement precision
If detailed network traffic data is collected for contact rates, then simulation realism is improved, but data processing complexity increases
Solution Approach 1:
The patent applies the extraction principle by isolating only the essential elements needed for contact rate calculation from the full network traffic data. Instead of processing all network packets and metadata, the system extracts key parameters such as data volume, packet count, and communication frequency for each edge. This selective extraction maintains high measurement precision for contact rates while significantly reducing the complexity of data processing by focusing only on the most relevant traffic characteristics.
Data Source
AI summary
A computer-implemented method of simulating the propagation of malware in a network is provided. The method comprises accessing a model of the network, where the model comprises a plurality of computer nodes and where each computer node of the plurality of computer nodes is connected to at least one edge of a plurality of edges. Each edge of the plurality of edges connects a pair of computer nodes of the plurality of computer nodes. The method further comprises initiating an outbreak of the malware in the model at a predetermined source computer node of the plurality of computer nodes, and propagating the malware through the model of the network from the source computer node. The propagation is determined based on a rate of transmission, where the rate of transmission is based upon a contact rate for each edge of the plurality of edges, and the contact rate for each edge of the plurality of edges is based upon the network traffic passing between the computer nodes connected by that edge over a predetermined time period.


