Malware Propagation Simulation for Critical System Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional malware protection mechanisms for critical computer systems are reactive and may render systems unusable during critical malware propagation periods, lacking proactive measures to prevent disruption and ensuring continuous operation.

Innovation Solution

A computer-implemented method that simulates malware propagation across a set of computer systems, identifying the probability of infection and deploying protective measures before the malware reaches a predetermined threshold, allowing for the provisioning of a replacement system to maintain continuous operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If reactive malware protection mechanisms are deployed, then malware detection capability is improved, but system operational continuity deteriorates due to disconnection and remediation interruptions

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidsystem operational continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent performs preliminary actions by simulating malware propagation and identifying vulnerable targets before actual infection occurs. The system models potential infection paths, calculates infection probabilities, and proactively identifies high-risk systems, allowing protective measures to be prepared in advance rather than reacting after infection has spread

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a simulation model as an intermediary between the malware threat and the actual computer systems. This virtual model allows the system to analyze infection scenarios, predict propagation patterns, and identify vulnerable targets without actually infecting real systems, thereby maintaining operational continuity while improving detection capability

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If rapid deployment of anti-malware measures is performed, then malware spread control is improved, but system usability deteriorates during the critical propagation period

Engineering Contradiction:
Improvemalware spread controlVSAvoidsystem usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by deploying protective measures selectively to specific high-risk targets identified through simulation, rather than uniformly across all systems. The system calculates infection probabilities for individual systems and prioritizes protection for those with highest risk, maintaining usability for lower-risk systems while ensuring malware spread control for critical targets

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs preliminary identification of vulnerable targets through malware propagation simulation before deploying protective measures. This allows organizations to prepare and stage anti-malware solutions in advance, reducing deployment time and minimizing disruption to system usability when protection is actually applied

Inventive Principle:
Principle #10Preliminary action

3Productivity

If critical computer systems are maintained operational during malware outbreak, then service continuity is improved, but risk of infection exposure increases

Engineering Contradiction:
Improveservice continuityVSAvoidinfection exposure risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary identification of high-risk systems through malware propagation simulation, allowing protective measures to be pre-positioned on critical systems before malware exposure occurs. This enables these systems to remain operational during outbreaks with reduced infection risk, as protection is already in place rather than being applied reactively

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses feedback from malware propagation simulations to continuously identify and update high-risk targets. By modeling infection paths and calculating probabilities, the system provides feedback on which systems require protection, enabling dynamic adjustment of protective measures to maintain service continuity while managing infection exposure risk

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP4222923B1Malware infection mitigation of critical computer systems
Publication Date: 2024.06.19 BRITISH TELECOM PLC
  • EP4222923B1 patent drawingFigure 1~2
  • EP4222923B1 patent drawingFigure 3
  • EP4222923B1 patent drawing

AI summary

A computer implemented malware protection method to protect a target computer system in a set of computer systems from a malware, the method comprising: accessing a model of the set of computer systems, the model identifying interacting pairs of the computer systems in the set based on interactions corresponding to previous communication occurring between the computer systems in the pairs, and the model identifying the target computer system; simulating, over a plurality of time periods, a propagation of the malware originating from a predetermined source computer system in the model, the simulation being based on a number of interactions per time period between each interacting pair of computer systems in the set, and a rate of transmission of the malware per interaction; evaluating, for each of at least a subset of the time periods, a probability of infection of the target computer system in the time period; responsive to the simulating step, identifying an earliest time period during which the probability of infection of the target computer system meets a predetermined threshold probability; and triggering the deployment of malware protection measures in respect of the target computer system at a time period selected with reference to the identified time period so as to protect the target computer system from the malware.