IP Library Granted Patent US 12,499,218
Granted Patent B2
US 12,499,218 · App. 17/995,365 · Granted Dec 16, 2025

Malware protection based on final infection size

Inventors: Xiao-Si Wang (London, GB); Jessica Welding (London, GB)
Assignee: British Telecommunications Public Limited Company
G06F21/552G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,499,218
App. No.
17/995,365
Granted
Dec 16, 2025
Kind
B2
Abstract

A computer implemented malware protection method to protect at least a subset of computer systems in a population of network-connected computer systems, including determining a distribution of predicted final infection size, each predicted final infection size being determined by a forecasting simulation of malware propagation from an originating system in the population; determining a plurality of ranges of final infection size from the distribution; determining weighted associations between clusters of computer systems and ranges of final infection size based on measures of numbers of originating computer systems in each cluster associated with each range of final infection size; and deploying protective measures for one or more clusters of computer systems responsive to the weighted associations.

Claims (28)

1 . A computer implemented malware protection method to protect computer systems in a population of network-connected computer systems, the method comprising:

identifying a plurality of clusters of the computer systems in the population of network-connected computer systems, wherein the computer systems within each of the plurality of clusters share at least one common characteristic;

determining a distribution of a metric of predicted final infection size for the population as a total number of computer systems infected by a propagation of a malware in the population, the distribution including predictions for infections originating with computer systems in the population, each predicted final infection size being determined by a forecasting simulation of malware propagation from an originating computer system in the population, the forecasting simulation of malware propagation being performed based on at least one malware propagation model defining at least a transmission rate of the malware between computer systems in the population determined to be in communication with each other, and a removal rate of computer systems being removed from a state of infection by the malware;

determining a plurality of ranges of final infection size from the distribution;

determining weighted associations between the identified plurality of clusters of computer systems and the determined ranges of final infection size based on numbers of incidences, during the forecasting simulation, that a malware infection beginning at originating computer systems in each cluster results in a final infection size within each range of final infection size, wherein determining the weighted associations comprises determining associations based on an association between each originating computer system in the population and a frequency of one or more final infection sizes arising from the forecasting simulation of malware propagation, and a cluster membership of the computer system, and determining the weighted associations for each determined association based on a frequency of occurrence of each final infection size within the determined ranges; and

deploying protective measures for one or more of the plurality of identified clusters of computer systems responsive to the weighted associations.

2 . The method of claim 1 , wherein the at least one common characteristic includes: a logical position or a physical position of the computer systems in the population; a network attribute of the computer systems in the population; a predetermined role or a function of the computer systems in the population; or a common type of device of the computer systems in the population.

3 . The method of claim 1 , wherein the at least one malware propagation model identifies interacting pairs of the computer systems in the population based on interactions corresponding to previous communication occurring between the computer systems in the pair.

4 . The method of claim 3 , wherein the forecasting simulation includes simulating, over a plurality of simulated time periods, a propagation of the malware from an originating computer system in the population, the simulating being based on a number of interactions per time period between each interacting pair of computer systems in the population, the transmission rate and the removal rate.

5 . The method of claim 1 , wherein the distribution includes predictions for infections originating with each computer system in the population.

6 . The method of claim 1 , wherein the plurality of ranges of final infection size is determined by:

determining a probability of each final infection size in the distribution to generate a signal indicating a range of probabilities for each final infection size, the signal being processed to reduce noise therein; and

determining the plurality of ranges of final infection size based on the signal.

7 . The method of claim 6 , wherein the plurality of ranges of final infection size are determined based on the signal by dividing the signal into the plurality of ranges based on an identification of local minima in the signal.

8 . The method of claim 1 , wherein the protective measures include one or more of: an anti-malware facility; a malware filter; a malware detector; a block, a preclusion or a cessation of interaction; or a reconfiguration of one or more computer systems.

9 . A computer system comprising:

a processor and memory storing computer program code for malware protection of computer systems in a population of network-connected computer systems, by:

identifying a plurality of clusters of the computer systems in the population of network-connected computer systems, wherein the computer systems within each of the plurality of clusters share at least one common characteristic;

determining a distribution of a metric of predicted final infection size for the population as a total number of computer systems infected by a propagation of a malware in the population, the distribution including predictions for infections originating with computer systems in the population, each predicted final infection size being determined by a forecasting simulation of malware propagation from an originating computer system in the population, the forecasting simulation of malware propagation being performed based on at least one malware propagation model defining at least a transmission rate of the malware between computer systems in the population determined to be in communication with each other, and a removal rate of computer systems being removed from a state of infection by the malware;

determining a plurality of ranges of final infection size from the distribution;

determining weighted associations between the identified plurality of clusters of computer systems and the determined ranges of final infection size based on numbers of incidences, during the forecasting simulation, that a malware infection beginning at originating computer systems in each cluster results in a final infection size within each range of final infection size, wherein determining the weighted associations comprises determining associations based on an association between each originating computer system in the population and a frequency of one or more final infection sizes arising from the forecasting simulation of malware propagation, and a cluster membership of the computer system, and determining the weighted associations for each determined association based on a frequency of occurrence of each final infection size within the determined ranges; and

deploying protective measures for one or more of the plurality of identified clusters of computer systems responsive to the weighted associations.

10 . A non-transitory computer-readable storage medium storing computer program code to, when loaded into a computer system and executed thereon, cause the computer system to implement malware protection to protect computer systems in a population of network-connected computer systems, by:

identifying a plurality of clusters of the computer systems in the population of network-connected computer systems, wherein the computer systems within each of the plurality of clusters share at least one common characteristic;

determining a distribution of a metric of predicted final infection size for the population as a total number of computer systems infected by a propagation of a malware in the population, the distribution including predictions for infections originating with computer systems in the population, each predicted final infection size being determined by a forecasting simulation of malware propagation from an originating computer system in the population, the forecasting simulation of malware propagation being performed based on at least one malware propagation model defining at least a transmission rate of the malware between computer systems in the population determined to be in communication with each other, and a removal rate of computer systems being removed from a state of infection by the malware;

determining a plurality of ranges of final infection size from the distribution;

determining weighted associations between the identified plurality of clusters of computer systems and the determined ranges of final infection size based on numbers of incidences, during the forecasting simulation, that a malware infection beginning at originating computer systems in each cluster results in a final infection size within each range of final infection size, wherein determining the weighted associations comprises determining associations based on an association between each originating computer system in the population and a frequency of one or more final infection sizes arising from the forecasting simulation of malware propagation, and a cluster membership of the computer system, and determining the weighted associations for each determined association based on a frequency of occurrence of each final infection size within the determined ranges; and

deploying protective measures for one or more of the plurality of identified clusters of computer systems responsive to the weighted associations.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2023
From: WANG, XIAO-SI; WELDING, JESSICA
To: BRITISH TELECOMMUNICATIONS PUBLIC LIMITED COMPANY
Reel/Frame 063476/0012 →
Priority Claims (1)
EP 20168112 · Apr 3, 2020 · regional
Continuity (1)
Related Publication 20230161874A1 · May 25, 2023
References Cited (85)
US 8667581B2 · Steeves et al. · 2014 [cited by applicant]
US 8683585B1 · Chen · 2014 [cited by examiner]
US 9060018B1 · Yu et al. · 2015 [cited by applicant]
US 10084806B2 · Ward · 2018 [cited by examiner]
US 10298598B1 · McClintock et al. · 2019 [cited by applicant]
US 10742475B2 · Lai et al. · 2020 [cited by applicant]
US 10963802B1 · Gardner et al. · 2021 [cited by applicant]
US 11283828B2 · Riccetti · 2022 [cited by examiner]
US 11397258B2 · Zeng et al. · 2022 [cited by applicant]
US 11470103B2 · Dean et al. · 2022 [cited by applicant]
US 11500058B2 · Hu et al. · 2022 [cited by applicant]
US 11727109B2 · Speakman et al. · 2023 [cited by applicant]
US 11829484B2 · Lipkis et al. · 2023 [cited by applicant]
US 11863584B2 · Togari · 2024 [cited by examiner]
US 12046040B2 · Wang et al. · 2024 [cited by applicant]
US 12126636B2 · Dean et al. · 2024 [cited by applicant]
US 12273376B2 · Wang et al. · 2025 [cited by applicant]
US 20020162015A1 · Tang · 2002 [cited by examiner]
US 20110078177A1 · Fakeih · 2011 [cited by examiner]
US 20120151588A1 · Wang · 2012 [cited by examiner]
US 20130007741A1 · Britsch · 2013 [cited by examiner]
US 20130340080A1 · Gostev et al. · 2013 [cited by applicant]
US 20190052659A1 · Weingarten et al. · 2019 [cited by applicant]
US 20210160281A1 · Hallaji et al. · 2021 [cited by applicant]
US 20220116411A1 · Melicher et al. · 2022 [cited by applicant]
US 20230123046A1 · Wang et al. · 2023 [cited by applicant]
US 20230161874A1 · Wang et al. · 2023 [cited by applicant]
US 20230376598A1 · Wang et al. · 2023 [cited by applicant]
US 20230379360A1 · Hallaji et al. · 2023 [cited by applicant]
US 20240310851A1 · Ebrahimi Afrouzi et al. · 2024 [cited by applicant]
CN 109190375A · 2019 [cited by applicant]
EP 1990973A2 · 2008 [cited by applicant]
GB 2574093A · 2019 [cited by applicant]
WO 2006132987A1 · 2006 [cited by applicant]
WO WO2019185404A1 · 2019 [cited by applicant]
WO WO2019185405A1 · 2019 [cited by applicant]
WO 2020065737A1 · 2020 [cited by applicant]
WO 2021001237A1 · 2021 [cited by applicant]
WO WO2021165256A1 · 2021 [cited by applicant]
WO WO2021165257A1 · 2021 [cited by applicant]
WO WO2021198295A1 · 2021 [cited by applicant]
WO 2023169772A1 · 2023 [cited by applicant]
WO 2023169773A1 · 2023 [cited by applicant]
WO 2023169774A1 · 2023 [cited by applicant]
WO 2023169775A1 · 2023 [cited by applicant]
Combined Search and Examination Report received for Great Britain Patent Application No. 2020915.1, mailed on May 11, 2021, 5 pages. [cited by applicant]
Combined Search and Examination Report received for Great Britain Patent Application No. 2203355.9, mailed on Oct. 10, 2022, 12 pages. [cited by applicant]
Combined Search and Examination Report received for Great Britain Patent Application No. 2203361.7, mailed on Oct. 17, 2022, 12 pages. [cited by applicant]
Combined Search and Examination Report received for Great Britain Patent Application No. 2203366.6, mailed on Oct. 21, 2022, 12 pages. [cited by applicant]
Combined Search and Examination Report received for Great Britain Patent Application No. 2203371.6, mailed on Nov. 3, 2022, 12 pages. [cited by applicant]
International Preliminary Report on Patentability received for PCT Patent Application No. PCT/EP2021/083783, mailed on Jul. 13, 2023, 8 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/EP2021/083783, mailed on Mar. 1, 2022, 12 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/EP2023/053486, mailed on Apr. 13, 2023, 13 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/EP2023/053489, mailed on Apr. 13, 2023, 13 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/EP2023/053493, mailed on Apr. 21, 2023, 13 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/EP2023/053494, mailed on Apr. 21, 2023, 13 pages. [cited by applicant]
Atwood , et al., “Fair Treatment Allocations in Social Networks”, arXiv:1911.05489v1, Nov. 1, 2019, 11 pages. [cited by applicant]
Beyah , et al., “The Case for Collaborative Distributed Wireless Intrusion Detection Systems”, Granular Computing, IEEE International Conference on Atlanta, 2006, pp. 782-787. [cited by applicant]
Eder-Neuhauser , et al., “Malware Propagation in Smart Grid Networks: Metrics, Simulation and Comparison of Three Malware Types”, Journal of Computer Virology and Hacking Techniques, vol. 15, 2019, pp. 109-125. [cited by applicant]
Faghani , et al., “A Study of Trojan Propagation in Online Social Networks”, 5th International Conference on New Technologies, Mobility and Security, 2012, 5 pages. [cited by applicant]
Guillen , et al., “A Mathematical Model for Malware Spread on WSNs with Population Dynamics”, Physica A, vol. 545, 2020, 11 pages. [cited by applicant]
Hosseini, Soodeh , “Defense Against Malware Propagation in Complex Heterogeneous Networks”, Cluster Computing, vol. 24, No. 2, 2021, pp. 1199-1215. [cited by applicant]
Khan , et al., “Cognitive Modeling of Polymorphic Malware using Fractal Based Semantic Characterization”, IEEE International Symposium on Technologies for Homeland Security (HST), 2017, 7 pages. [cited by applicant]
Liu , et al., “An Approach to Finding the Cost-effective Immunization Targets for Information Assurance”, Decision Support Systems, vol. 67, Nov. 2014, pp. 40-52. [cited by applicant]
Matsubara, et al., “Nonlinear Dynamics of Information Diffusion in Social Networks”, ACM Transactions on the Web, vol. 11, No. 2, Article 11, Apr. 2017, pp. 1-40. [cited by applicant]
Muchnik , et al., “Initial Growth Rates of Epidemics Fail to Predict their Reach: A Lesson from Large Scale Malware Spread Analysis”, Aug. 2, 2020, 15 pages. [cited by applicant]
Wright, Rob , “What is Polymorphic Virus?—Definition from Whatls.com”, Available Online at <https://web.archive.org/web/20211127061825/https://www.techtarget.com/searchsecurity/definition/polymorphic-malware>, 2021, 5 p… [cited by applicant]
Xu , et al., “Analysis of Malware-Induced Cyber Attacks in Cyber-Physical Power Systems”, IEEE Transactions on Circuits and Systems II, 2020, 5 pages. [cited by applicant]
Combined Search and Examination Report under Sections 17 and 18(3) for Great Britain Application No. 2002121.8, mailed Aug. 4, 2020, 6 pages. [cited by applicant]
Combined Search and Examination Report under Sections 17 and 18(3) for Great Britain Application No. 2004994.6, mailed Jul. 13, 2020, 5 pages. [cited by applicant]
Examination Report under 18(3) for Great Britain Application No. 2002122.6, mailed Nov. 30, 2021, 3 pages. [cited by applicant]
Extended European Search Report for Application No. 20157627.9, mailed on Jun. 12, 2020, 9 pages. [cited by applicant]
Extended European Search Report for Application No. 20168112.9, mailed on Sep. 4, 2020, 9 pages. [cited by applicant]
International Preliminary Report on Patentability for Application No. PCT/EP2021/053764, mailed on Sep. 1, 2022, 9 pages. [cited by applicant]
International Preliminary Report on Patentability for Application No. PCT/EP2021/058360, mailed on Aug. 11, 2022, 14 pages. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/EP2021/053763 mailed on Mar. 9, 2021, 13 pages. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/EP2021/053764 mailed on Mar. 9, 2021, 13 pages. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/EP2021/058360 mailed on Jun. 2, 2021, 12 pages. [cited by applicant]
Jia Z., et al., “Research on Computer Virus Source Modeling with Immune Characteristics,” 2017 29th Chinese Control And Decision Conference (CCDC), May 28, 2017, pp. 4616-4619. [cited by applicant]
Liu W., “Web Malware Spread Modelling And Optimal Control Strategies,” Scientific Reports, Feb. 10, 2017, vol. 7(42308), 19 pages. [cited by applicant]
Mieghem P.V., “The Viral Conductance of a Network”, Computer Communications, vol. 35, Apr. 18, 2012, pp. 1494-1506. [cited by applicant]
Search Report under Section 17(5) for Great Britain Application No. 2002122.6, mailed on Aug. 4, 2020, 4 pages. [cited by applicant]
Wang C., et al., “On Computer Viral Infection and the Effect of Immunization,” Proceedings 16th Annual Computer Security Applications Conference (ACSAC'00), Dec. 11-15, 2000, pp. 246-256. [cited by applicant]
Written Opinion of the International Preliminary Examining Authority for Application No. PCT/EP2021/058360, mailed on Apr. 22, 2022, 7 pages. [cited by applicant]
Office Action received for European Patent Application No. 21824337.6, mailed on Jul. 1, 2024, 5 pages. [cited by applicant]