Network Infection Risk Prediction via Distance-Based Probability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional systems for predicting malware spread between connected devices often fail to account for all factors, particularly when infected and at-risk devices are on different networks with different administrators, leading to increased infection risks.
Innovation Solution
A computer-implemented method that determines the distance between connected devices, detects malware infections, calculates infection probabilities based on this distance, and performs security actions to reduce infection risk when probabilities meet a predetermined threshold.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional malware prediction systems are used, then device complexity is reduced, but measurement precision of infection risk is insufficient
Solution Approach 1:
The system segments the network into multiple layers including L2 network segments, L3 network segments, and cloud environments. Each segment is assigned a specific risk weight factor, allowing precise measurement of infection risk at different network levels while maintaining manageable system complexity through hierarchical organization.
Solution Approach 2:
The patent introduces multiple dimensions for risk assessment beyond simple connectivity, including network segment layers (L2, L3, cloud), device types (IoT, mobile, desktop), and communication protocols. This multi-dimensional approach significantly improves measurement precision by considering various factors simultaneously without overwhelming system complexity.
2Measurement precision
If comprehensive network monitoring is implemented across different networks, then measurement precision improves, but loss of information increases due to different administrators
Solution Approach 1:
The system introduces intermediary components including gateway devices that connect different network segments, intermediary servers that aggregate data from multiple administrators, and centralized risk calculation servers. These intermediaries facilitate information sharing across administrative boundaries while maintaining data availability and improving infection detection accuracy.
Solution Approach 2:
The patent implements universal data formats and communication protocols that work across different network administrators' systems. The risk calculation framework is designed to be administrator-agnostic, accepting infection data from any source and processing it through standardized procedures, thus preventing information loss while maintaining measurement precision.
3Reliability
If distance-based infection probability calculation is implemented, then reliability of security predictions improves, but device complexity increases
Solution Approach 1:
The system changes parameters by assigning specific risk weight factors to different network segment layers (L2, L3, cloud) and device types. Instead of complex mathematical distance calculations, the patent uses weighted parameter aggregation where each network segment and device type contributes a predetermined weight to the overall infection probability, improving reliability while keeping the calculation system relatively simple.
4Reliability
If proactive security actions are deployed across multiple networks, then reliability of protection improves, but loss of energy increases
Solution Approach 1:
The system applies partial action by deploying security measures proportionally based on calculated infection probabilities. Instead of uniform proactive protection across all devices, the patent implements security actions only on devices exceeding specific risk thresholds, optimizing protection effectiveness while minimizing unnecessary energy consumption on low-risk devices.
Data Source
AI summary
The disclosed computer-implemented method for reducing infection risk of computing systems may include (i) determining a distance between a computing system that is connected to a local network and an additional computing system that is not connected to the local network but is connected to the computing system via a series of connected devices, (ii) detecting that the additional computing system is infected with malware, (iii) calculating an infection probability for the computing system that is based at least in part on the distance between the computing system and the additional computing system that is infected, and (iv) performing a security action on the computing system that reduces a risk of infection of the computing system in response to the infection probability for the computing system meeting a predetermined threshold for infection probability. Various other methods, systems, and computer-readable media are also disclosed.


