Malware Propagation Simulation for Targeted Network Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional malware protection mechanisms are reactive and often fail to prevent the widespread distribution of malware due to delayed detection and impractical deployment of mitigation measures across susceptible computer systems.

Innovation Solution

A computer-implemented method that simulates malware propagation across a set of computer systems, identifying interacting pairs and deploying targeted protection measures based on interaction rates and transmission probabilities to inhibit malware spread.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional reactive malware protection mechanisms are used, then detection and treatment can be performed, but malware propagation cannot be prevented in time due to delayed detection and impractical deployment

Engineering Contradiction:
Improvemalware protection effectivenessVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by simulating malware propagation across the network before actual infection occurs. The simulation identifies vulnerable systems and optimal deployment targets in advance, enabling proactive protection rather than reactive response. This allows mitigation measures to be prepared and deployed at the most effective moment, preventing widespread propagation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The network is segmented into interacting pairs of computer systems based on communication patterns. This segmentation allows the system to analyze and protect specific vulnerable segments rather than treating the entire network as a single unit. Protection measures can be targeted to specific segments where malware propagation is most likely to occur, improving response effectiveness while reducing overall deployment complexity.

Inventive Principle:
Principle #1Segmentation

2Reliability

If mitigation measures are deployed to entire population of susceptible hosts, then malware propagation can be inhibited, but deployment becomes impractical due to complexity and resource requirements

Engineering Contradiction:
Improvemalware protection coverageVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of uniform deployment across all susceptible hosts, the system applies local quality by identifying specific interacting pairs and individual systems where protection measures should be deployed. The simulation reveals which local segments are most vulnerable to malware propagation, allowing targeted deployment of mitigation measures to specific systems or pairs rather than blanket deployment across the entire network.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs partial action by deploying protection measures to only the most critical vulnerable segments identified through simulation, rather than deploying to all susceptible hosts. The simulation determines the minimum necessary deployment scope needed to effectively inhibit malware propagation, avoiding unnecessary complexity and resource expenditure on systems that are less vulnerable or already protected.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If comprehensive monitoring of all computer systems is performed, then malware propagation can be detected, but system complexity and resource consumption increase significantly

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The monitoring system segments the network into interacting pairs of computer systems based on communication patterns. Rather than monitoring all possible system interactions, the system focuses on identified interacting pairs that are most relevant to malware propagation pathways. This segmentation maintains detection accuracy for critical pathways while significantly reducing the complexity of monitoring the entire network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs partial monitoring by focusing computational resources on simulating and monitoring only the most vulnerable interacting pairs identified through the model. Rather than comprehensively monitoring all possible malware transmission pathways, the system concentrates monitoring efforts on the subset of interactions that pose the greatest risk, maintaining effective detection while reducing overall system complexity and resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12511386B2Malware propagation forecasting
Publication Date: 2025.12.30 BRITISH TELECOM PLC
  • US12511386B2 patent drawing
  • US12511386B2 patent drawing
  • US12511386B2 patent drawing

AI summary

A malware protection method to protect at least a subset of a set of computer systems from a malware includes accessing a model of the set of computer systems, the model identifying interacting pairs of the computer systems in the set based on interactions corresponding to previous communication occurring between the computer systems in the pair; simulating, over a plurality of time periods, a propagation of the malware originating from a predetermined source computer system in the model, the simulation being based on a number of interactions per time period between each interacting pair of computer systems in the set, and a rate of transmission of the malware per interaction; and, responsive to the simulating, identifying one or more computer systems or interacting pairs of computer systems to deploy a malware protection measure thereto so as to inhibit a propagation of the malware through the set of computer systems.