Malware Propagation Simulation for Critical System Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional malware protection mechanisms for critical computer systems are reactive and may render systems unusable during critical malware propagation periods, lacking proactive measures to prevent disruption and ensuring continuous operation.
Innovation Solution
A computer-implemented method that simulates malware propagation across a set of computer systems, identifying the probability of infection and deploying protective measures before the malware reaches a predetermined threshold, allowing for the provisioning of a replacement system to maintain continuous operation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If reactive malware protection mechanisms are deployed, then malware detection capability is improved, but system operational continuity deteriorates due to disconnection and remediation interruptions
Solution Approach 1:
The patent performs preliminary actions by simulating malware propagation and identifying vulnerable targets before actual infection occurs. The system models potential infection paths, calculates infection probabilities, and proactively identifies high-risk systems, allowing protective measures to be prepared in advance rather than reacting after infection has spread
Solution Approach 2:
The patent introduces a simulation model as an intermediary between the malware threat and the actual computer systems. This virtual model allows the system to analyze infection scenarios, predict propagation patterns, and identify vulnerable targets without actually infecting real systems, thereby maintaining operational continuity while improving detection capability
2Reliability
If rapid deployment of anti-malware measures is performed, then malware spread control is improved, but system usability deteriorates during the critical propagation period
Solution Approach 1:
The patent applies local quality by deploying protective measures selectively to specific high-risk targets identified through simulation, rather than uniformly across all systems. The system calculates infection probabilities for individual systems and prioritizes protection for those with highest risk, maintaining usability for lower-risk systems while ensuring malware spread control for critical targets
Solution Approach 2:
The system performs preliminary identification of vulnerable targets through malware propagation simulation before deploying protective measures. This allows organizations to prepare and stage anti-malware solutions in advance, reducing deployment time and minimizing disruption to system usability when protection is actually applied
3Productivity
If critical computer systems are maintained operational during malware outbreak, then service continuity is improved, but risk of infection exposure increases
Solution Approach 1:
The patent performs preliminary identification of high-risk systems through malware propagation simulation, allowing protective measures to be pre-positioned on critical systems before malware exposure occurs. This enables these systems to remain operational during outbreaks with reduced infection risk, as protection is already in place rather than being applied reactively
Solution Approach 2:
The system uses feedback from malware propagation simulations to continuously identify and update high-risk targets. By modeling infection paths and calculating probabilities, the system provides feedback on which systems require protection, enabling dynamic adjustment of protective measures to maintain service continuity while managing infection exposure risk
Data Source
Figure 1~2
Figure 3
AI summary
A computer implemented malware protection method to protect a target computer system in a set of computer systems from a malware, the method comprising: accessing a model of the set of computer systems, the model identifying interacting pairs of the computer systems in the set based on interactions corresponding to previous communication occurring between the computer systems in the pairs, and the model identifying the target computer system; simulating, over a plurality of time periods, a propagation of the malware originating from a predetermined source computer system in the model, the simulation being based on a number of interactions per time period between each interacting pair of computer systems in the set, and a rate of transmission of the malware per interaction; evaluating, for each of at least a subset of the time periods, a probability of infection of the target computer system in the time period; responsive to the simulating step, identifying an earliest time period during which the probability of infection of the target computer system meets a predetermined threshold probability; and triggering the deployment of malware protection measures in respect of the target computer system at a time period selected with reference to the identified time period so as to protect the target computer system from the malware.