Malware Spread Prediction With Machine Learning Knowledge Graphs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for analyzing the spread of malicious software in networks are computationally expensive and time-consuming, leading to inefficiencies and delays that allow the malware to spread undetected.

Innovation Solution

A hybrid approach combining machine learning and knowledge graphs to predict the spread of malicious software by using historical data to calculate velocity and acceleration, identifying time horizons, and performing targeted security actions on subsets of devices within these horizons.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a pure graphical approach is used to analyze all nodes connected to a current point of attack, then comprehensive coverage of affected devices is achieved, but computational expense and time consumption increase significantly

Engineering Contradiction:
Improvecomprehensive coverageVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system segments the network into multiple time horizons (first time horizon, second time horizon, etc.) based on predicted malware spread velocity and acceleration. Each time horizon contains a subset of computing devices that are expected to be affected within a specific time window. This segmentation allows the system to process and analyze devices in manageable groups rather than analyzing all nodes simultaneously, thereby reducing computational expense and time consumption while maintaining comprehensive coverage across all affected devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary analysis by training a machine learning model on historical malware spread data to predict time horizons and identify subsets of devices that will be affected within specific time windows. This preliminary action enables the system to pre-identify high-risk device subsets before actual malware spread occurs, allowing security actions to be targeted efficiently rather than analyzing all nodes equally, thus reducing time consumption while maintaining comprehensive coverage.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a pure graphical approach is used to analyze all nodes connected to a current point of attack, then complete network analysis is achieved, but processing efficiency decreases

Engineering Contradiction:
Improvecomplete network analysisVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system segments the complete network analysis task into multiple time-based horizons, where each horizon represents a subset of devices expected to be affected within a specific time window. The machine learning model predicts these segments based on historical spread patterns, velocity, and acceleration data. This segmentation enables parallel processing of different device subsets, significantly improving processing efficiency while maintaining complete network analysis coverage across all time horizons.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies partial action by focusing security analysis and mitigation efforts on specific subsets of devices within predicted time horizons rather than uniformly analyzing all nodes. The machine learning model identifies high-probability affected subsets, allowing the system to concentrate processing resources on these partial sets first. This approach maintains complete network analysis coverage while improving processing efficiency by avoiding unnecessary analysis of low-risk devices outside predicted horizons.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If security actions are performed on all devices in the network, then complete protection is achieved, but computational resources are wasted on devices not at risk

Engineering Contradiction:
Improvecomplete protectionVSAvoidcomputational resources
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system segments the network into multiple time horizons based on predicted malware spread patterns, where each horizon contains devices expected to be affected within a specific time window. Security actions are then applied selectively to devices within each predicted horizon rather than uniformly to all devices. This segmentation ensures complete protection for at-risk devices while avoiding wasteful application of security measures to devices outside predicted horizons, thereby optimizing computational resource usage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies local quality by tailoring security actions to specific subsets of devices based on their predicted risk levels and time horizons. The machine learning model identifies devices with different vulnerability characteristics and applies appropriate security measures to each subset. This ensures complete protection for high-risk devices while reducing or skipping security actions for low-risk devices, optimizing computational resource allocation while maintaining overall network protection.

Inventive Principle:
Principle #3Local quality

4Measurement precision

If traditional methods are used to detect malware spread, then detection accuracy is maintained, but response time increases allowing malware to spread undetected

Engineering Contradiction:
Improvedetection accuracyVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary detection by training a machine learning model on historical malware spread data to predict time horizons and identify subsets of devices that will be affected within specific time windows. This preliminary detection occurs before actual malware spread reaches those devices, enabling early warning and faster response. The model uses historical patterns, velocity, and acceleration data to anticipate spread, maintaining detection accuracy while significantly reducing response time compared to traditional reactive methods.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies dynamics by using a machine learning model that continuously adapts to malware spread patterns, updating predictions based on historical data, velocity, and acceleration metrics. The model dynamically adjusts time horizon predictions as new data becomes available, allowing the system to maintain high detection accuracy while responding faster to emerging threats. This dynamic approach enables real-time adaptation to changing malware behavior, improving both accuracy and response time.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12462031B2Hybrid machine learning and knowledge graph approach for estimating and mitigating the spread of malicious software
Publication Date: 2025.11.04 BANK OF AMERICA CORP
  • US12462031B2 patent drawing
  • US12462031B2 patent drawing
  • US12462031B2 patent drawing

AI summary

Aspects of the disclosure relate to predicting the spread of malicious software. The computing platform may identify malicious software at a computing device and may input characteristics of the malicious software into a machine learning model to produce time horizons for the malicious software. The computing platform may identify, using a knowledge graph and based on the time horizons, subsets of computing devices, each corresponding to a particular time horizon. The computing platform may perform, at a time within a first time horizon, a first security action for a first subset of computing devices within the first time horizon and a second security action for a second subset of computing devices located within a second time horizon, where the first time horizon and the second time horizon indicate that the first subset will be affected by the malicious software prior to the second subset.