Malware Signature Mutation Simulation for Faster Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional malware protection mechanisms are reactive and fail to anticipate the evolution of malware signatures, leading to delayed detection and ineffective mitigation strategies.

Innovation Solution

A simulation method that models malware propagation by mutating its signatures based on predefined or randomly generated conditions, allowing for proactive identification and deployment of targeted protection measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If conventional malware protection mechanisms are used, then detection and treatment can be performed, but the detection occurs too late after malware has already spread through the network

Engineering Contradiction:
Improvedetection timeVSAvoidprotection effectiveness
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent applies preliminary action by simulating malware propagation and testing protection measures in a virtual environment before deploying them to the actual network. This allows the system to identify effective protection strategies in advance, reducing the time lost in detecting and responding to real malware outbreaks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a copy of the malware (simulated malware with signatures) and propagates it through a simulated network environment. This copying approach enables safe testing and analysis of malware behavior without risking the actual network, allowing for faster identification of effective protection measures.

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If malware signatures are changed frequently to evade detection, then the malware can avoid detection, but it becomes more difficult to detect and measure the malware

Engineering Contradiction:
Improvemalware evasion capabilityVSAvoidmalware detection difficulty
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies parameter changes by systematically varying malware signatures in the simulation to model different malware variants. This allows the simulation to test how protection measures perform against changing malware characteristics, improving the ability to detect and respond to evasive malware strategies.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The simulation provides feedback on detection effectiveness against various malware signatures, allowing researchers to analyze which detection methods remain effective despite signature changes. This feedback loop helps identify robust detection strategies that can adapt to evolving malware evasion techniques.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If simulation accuracy is improved by modeling malware mutations, then the simulation results are more reliable, but the simulation complexity increases

Engineering Contradiction:
Improvesimulation accuracyVSAvoidsimulation complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the complex simulation into distinct components: network topology modeling, malware propagation modeling, signature mutation modeling, and detection mechanism modeling. This modular approach allows each component to be developed and validated independently, managing complexity while maintaining overall simulation accuracy.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12619740B2Simulation of malware with changing signatures
Publication Date: 2026.05.05 BRITISH TELECOM PLC
  • US12619740B2 patent drawing
  • US12619740B2 patent drawing
  • US12619740B2 patent drawing

AI summary

A computer-implemented method of simulating a propagation of a malware through a set of computer systems, the method comprising: identifying a simulated computer system infected with a simulated malware; determining a first signature of the simulated malware; determining that a mutation condition for the simulated malware has been met; and in response to determining that the mutation period has been met, changing the first signature of the simulated malware to a second signature.