IP Library › Granted Patent US 12,587,559
Granted Patent B2
US 12,587,559 · App. 18/845,144 · Granted Mar 24, 2026

Time-based approaches in malware simulation for responsive measure deployment

Inventors: Alfie Beard (London, GB); Tom Bowman (London, GB)
Assignee: BRITISH TELECOMMUNICATIONS PUBLIC LIMITED COMPANY
H04L63/1433H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,587,559
App. No.
18/845,144
Granted
Mar 24, 2026
Kind
B2
Abstract

A computer-implemented method of simulating the propagation of malware in a network is provided. The method comprises accessing a model of the network, where the model comprising a plurality of computer nodes and where each computer node of the plurality of computer nodes is connected to at least one edge of a plurality of edges. Each edge of the plurality of edges connects a pair of computer nodes of the plurality of computer nodes. The method further comprises initiating an outbreak of the malware in the model at a predetermined source computer node of the plurality of computer nodes, and propagating the malware through the model of the network from the source computer node over a plurality of step-times. The propagation is determined based on a rate of transmission per step-time for each edge, and each step-time of the plurality of step-times corresponds to a temporal point that is universal across the network, such that at each step-time the malware propagation through the network occurs simultaneously for each edge of the plurality of edges according to the rate of transmission per step-time for each edge.

Claims (37)

1 . A computer-implemented method of simulating the propagation of malware in a network, the method comprising:

accessing a model of the network, the model comprising a plurality of computer nodes, each computer node of the plurality of computer nodes being connected to at least one edge of a plurality of edges, wherein each edge of the plurality of edges connects a pair of computer nodes of the plurality of computer nodes;

initiating an outbreak of the malware in the model at a predetermined source computer node of the plurality of computer nodes; and

propagating the malware through the model of the network from the source computer node over a plurality of step-times, the propagation being determined based on a rate of transmission per step-time for each edge;

wherein each step-time of the plurality of step-times corresponds to a temporal point that is universal across the network, such that at each step-time the malware propagation through the network occurs simultaneously for each edge of the plurality of edges according to the rate of transmission per step-time for each edge.

2 . The method according to claim 1 , wherein the rate of transmission per step-time is based on a contact rate per step time, and wherein the contact rate per step time for each edge of the plurality of edges is calculated based on the amount of network traffic passing between corresponding computer nodes over the plurality of step-times.

3 . The method according to claim 2 , wherein the contact rate for each edge of the plurality of edges is adjusted over the plurality of step-times according to changes in the amount of network traffic passing between corresponding computer nodes between each step-time.

4 . The method according to claim 1 , wherein during the propagation of the malware, newly infected computer nodes of the plurality of computer nodes include an incubation period, the incubation period occurring over at least one step-time of the plurality of step-times.

5 . The method according to claim 4 , wherein during the incubation period, the detection rate per step-time for the corresponding infected computer node is zero.

6 . The method according to claim 4 , wherein during the incubation period, the detection rate per step-time for the corresponding infected computer node increases over the incubation period.

7 . The method according to claim 1 , wherein the rate of transmission for each edge additionally includes a weighting factor, the weighting factor being based on the estimated behaviour of users of the network over at least one step-time of the plurality of step-times.

8 . The method according to claim 7 , wherein the weighting factor is adjusted over the plurality of step-times according to changes in the estimated behaviour of users of the network over at least one step-time of the plurality of step-times.

9 . A computer implemented malware protection method to protect at least a subset of a set of computer systems from a malware, the method comprising:

simulating a propagation of the malware through the set of computer systems using a model of the set of computer systems, wherein the simulating comprises

accessing a model of the network, the model comprising a plurality of computer nodes, each computer node of the plurality of computer nodes being connected to at least one edge of a plurality of edges, wherein each edge of the plurality of edges connects a pair of computer modes of the plurality of computer nodes;

initiating an outbreak of the malware in the model at a predetermined source computer node of the plurality of computer nodes; and

propagating the malware through the model of the network from the source computer node over a plurality of step-times, the propagation being determined based on a rate of transmission per step-time for each edge;

wherein each step-time of the plurality of step-times corresponds to a temporal point that is universal across the network, such that at each step-time the malware propagation through the network occurs simultaneously for each edge of the plurality of edges according to the rate of transmission per step-time for each edge; and

identifying one or more malware protection measures to be deployed to one or more of the set of computer systems based on the simulating.

10 . The method of claim 9 , comprising:

deploying the one or more malware protection measures to the one or more computer systems.

11 . A system for simulating propagation of malware in a network comprising:

one or more processors;

a non-transitory memory; and

one or more programs, wherein the one or more programs are stored in the non-transitory memory and configured to be executed by the one or more processors so that the system for simulating the propagation of malware in the network is at least configured to:

access a model of the network, the model comprising a plurality of computer nodes, each computer node of the plurality of computer nodes being connected to at least one edge of a plurality of edges, wherein each edge of the plurality of edges connects a pair of computer nodes of the plurality of computer nodes;

initiate an outbreak of the malware in the model at a predetermined source computer node of the plurality of computer nodes; and

propagate the malware through the model of the network from the source computer node over a plurality of step-times, the propagation being determined based on a rate of transmission per step-time for each edge;

wherein each step-time of the plurality of step-times corresponds to a temporal point that is universal across the network, such that at each step-time the malware propagation through the network occurs simultaneously for each edge of the plurality of edges according to the rate of transmission per step-time for each edge.

12 . A non-transitory computer readable storage medium storing one or more programs, the one or more programs comprising instructions, which, when executed by an electronic device with one or more processors, cause the electronic device to perform any of the methods of claim 1 .

13 . The system according to claim 11 , wherein the rate of transmission per step-time is based on a contact rate per step time, and wherein the system is further configured to calculate the contact rate per step time for each edge of the plurality of edges based on the amount of network traffic passing between corresponding computer nodes over the plurality of step-times.

14 . The system according to claim 13 , wherein the system is further configured to adjust the contact rate for each edge of the plurality of edges over the plurality of step-times according to changes in the amount of network traffic passing between corresponding computer nodes between each step-time.

15 . The system according to claim 11 , wherein during the propagation of the malware, newly infected computer nodes of the plurality of computer nodes include an incubation period, the incubation period occurring over at least one step-time of the plurality of step-times.

16 . The system according to claim 15 , wherein during the incubation period, the detection rate per step-time for the corresponding infected computer node is zero.

17 . The system according to claim 15 , wherein during the incubation period, the detection rate per step-time for the corresponding infected computer node increases over the incubation period.

18 . The system according to claim 11 , wherein the rate of transmission for each edge additionally includes a weighting factor, the weighting factor being based on the estimated behaviour of users of the network over at least one step-time of the plurality of step-times.

19 . The system according to claim 18 , wherein the system is further configured to adjust weighting factor over the plurality of step-times according to changes in the estimated behaviour of users of the network over at least one step-time of the plurality of step-times.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 9, 2024
From: BEARD, ALFIE; BOWMAN, TOM
To: BRITISH TELECOMMUNICATIONS PUBLIC LIMITED COMPANY
Reel/Frame 068527/0782 →
Priority Claims (1)
GB 2203366 · Mar 10, 2022 · national
Continuity (1)
Related Publication 20250267163A1 · Aug 21, 2025
References Cited (97)
US 7739740B1 · Nachenberg · 2010 [cited by examiner]
US 8065731B1 · Nucci · 2011 [cited by examiner]
US 8683585B1 · Chen · 2014 [cited by applicant]
US 8978141B2 · Eliseev · 2015 [cited by examiner]
US 9060018B1 · Yu et al. · 2015 [cited by applicant]
US 9332029B1 · Tikhonov · 2016 [cited by examiner]
US 9473520B2 · Dixon · 2016 [cited by examiner]
US 9607148B1 · Magar · 2017 [cited by examiner]
US 11546767B1 · Shaw · 2023 [cited by applicant]
US 12273376B2 · Wang · 2025 [cited by applicant]
US 20070150957A1 · Hartrell · 2007 [cited by examiner]
US 20080201129A1 · Natvig · 2008 [cited by examiner]
US 20090320133A1 · Viljoen · 2009 [cited by examiner]
US 20110041179A1 · Ståhlberg · 2011 [cited by examiner]
US 20110078177A1 · Fakeih · 2011 [cited by applicant]
US 20120151588A1 · Wang · 2012 [cited by applicant]
US 20130007883A1 · Zaitsev · 2013 [cited by applicant]
US 20130340080A1 · Gostev et al. · 2013 [cited by applicant]
US 20180288087A1 · Hittel · 2018 [cited by examiner]
US 20190052659A1 · Weingarten et al. · 2019 [cited by applicant]
US 20210014240A1 · Wang · 2021 [cited by examiner]
US 20220038467A1 · Kimura · 2022 [cited by examiner]
US 20230123046A1 · Wang · 2023 [cited by applicant]
CN 109190375 · 2019 [cited by applicant]
EP 1990973 · 2008 [cited by applicant]
EP 4222923 · 2024 [cited by applicant]
GB 2574093 · 2019 [cited by applicant]
WO 2006132987 · 2006 [cited by applicant]
WO 2019185404 · 2019 [cited by applicant]
WO 2019185405 · 2019 [cited by applicant]
WO 2021001235 · 2021 [cited by applicant]
WO 2021001237 · 2021 [cited by applicant]
WO 2021165256 · 2021 [cited by applicant]
WO 2021165257 · 2021 [cited by applicant]
WO 2021198295 · 2021 [cited by applicant]
WO 2022069401 · 2022 [cited by applicant]
Office Action dated Dec. 2, 2024 issued for U.S. Appl. No. 17/904,467 (13 pages). [cited by applicant]
Notice of Allowance dated Dec. 31, 2024 issued for U.S. Appl. No. 17/904,453 (9 pages). [cited by applicant]
Office Action dated Apr. 3, 2025 issued for U.S. Appl. No. 17/904,453 (17 pages). [cited by applicant]
Notice of Allowance dated May 1, 2025 issued for U.S. Appl. No. 17/995,365 (14 pages). [cited by applicant]
Notice of Allowance dated May 14, 2025 issued for U.S. Appl. No. 17/904,467 (22 pages). [cited by applicant]
International Preliminary Report on Patentability dated Sep. 19, 2024, issued for International Application No. PCT/EP2023/053486 (9 pages). [cited by applicant]
International Preliminary Report on Patentability dated Sep. 19, 2024, issued for International Application No. PCT/EP2023/053494 (10 pages). [cited by applicant]
International Preliminary Report on Patentability dated Sep. 19, 2024, issued for International Application No. PCT/EP2023/053489 (9 pages). [cited by applicant]
International Preliminary Report on Patentability dated Sep. 19, 2024, issued for International Application No. PCT/EP2023/053493 (9 pages). [cited by applicant]
Office Action dated Sep. 29, 2024, issued for U.S. Appl. No. 17/995,365 (33 pages). [cited by applicant]
Wanping Liu, Shouming Zhong, “Web malware spread modelling and optimal control strategies”, published on Feb. 10, 2017 (19 pages). [cited by applicant]
Wright Rob, “What is polymorphic virus?—Definition from WhatIs.com”, 2021, pp. 1-5 URL: httQs:/Iweb.archive.org/webI20211127061825/httQs:/ Iwww.techtarget.co (5 pages). [cited by applicant]
Jia Zhi-Juan et al, 2017 29th Chinese Control and Decision Conference (CCDC), 2017, “Research on computer virus source modeling with immune characteristics”, pp. 4616-4619 p. 1, line 10, p. 2, col. 2, lines 16-17, p. 3,… [cited by applicant]
Faghani Mohammad et al, 5th International Conference on New Technologies, Mobility and Security (NTMS), 2012, “A Study of Trojan Propagation in Online Social Networks”, pp. 1-5 p. 3, col. 2, lines 11-16, 2012 (5 pages). [cited by applicant]
Beyah R A et al: “The case for collaborative distributed wireless intrusion detection systems”, Granular Computing, 2006 IEEE International Conference on Atlanta, GA, USA May 10-12, 2006, Piscataway, NJ, USA, IEEE, May … [cited by applicant]
Chenxi Wang et al: “On computer viral infection and the effect of immunization”, Computer Security Applications, 2000, ACSAC '00. 16th Annual Conference E New Orleans, LA, USA Dec. 11-15, 2000, Los Alamitos, CA, USA, IE… [cited by applicant]
Combined Search & Exam Report for GB2203361.7 dated Oct. 7, 2022 (12 pages). [cited by applicant]
Combined Search & Exam Report for GB2203366.6 dated Oct. 21, 2022 (12 pages). [cited by applicant]
Combined Search and Exam Report for 2203371.6 dated Nov. 3, 2022 (12 pages). [cited by applicant]
Combined Search and Exam Report for 2004994.6 Dated Jul. 13, 2020. [cited by applicant]
Combined Search and Exam Report for GB2002121.8 Dated Aug. 4, 2020. [cited by applicant]
Piet Van Mieghem, Computer Communications, vol. 35, Apr. 18, 2012, “The viral conductance of a network”, pp. 1494-1506 see Abstract Section 2 (8 pages). [cited by applicant]
Eder-Neuhauser Peter et al: “Malware propagation in smart grid networks: metrics, simulation and comparison of three malware types”, Journal of Computer Virology and Hacking Techniques, Springer Paris, Paris, vol. 15, N… [cited by applicant]
Exam Report for GB2002122.6 dated Nov. 30, 2021. [cited by applicant]
Faghani Mohammad R. et al: “A Study of Trojan Propagation in Online Social Networks” , 2012 5th International Conference on New Technologies, Mobility and Security (NTMS) , May 1, 2012 (May 1, 2012), pp. 1-5, XP05596635… [cited by applicant]
Combined Search & Exam ReEort for GB2020915.1 dated May 11, 2021 5 Pages). [cited by applicant]
Combined Search & Exam Report for GB2203355.9 dated Oct. 10, 2022. [cited by applicant]
Hernandez Guillen J D et al: “A mathematical model for malware spread on WSNs with population dynamics”, Physica A, North-Holland, Amsterdam, NL, vol. 545, Nov. 22, 2019 (Nov. 22, 2019), XP086098687 (11 pages). [cited by applicant]
Hosseini Soodeh Ed—Vega-Rodriguez Miguel A et al: “Defense against malware propagation in complex heterogeneous networks”, Cluster Computing, Baltzer Science Publishers, Bussum, NL, vol. 24, No. 2, Sep. 12, 2020 (Sep. 1… [cited by applicant]
Khan Muhamad Salman et al., IEEE International Symposium on Technologies for Homeland Security (HST), 2017, “Cognitive modeling of polymorphic malware using fractal based semantic characterization”, pp. 1-7 p. 2, col. 1… [cited by applicant]
International Preliminary Report on Patentability for PCT/EP2021/058360 issued Aug. 11, 2022 (14 Pages). [cited by applicant]
International Preliminary Report on Patentability for PCT/EP2021/053763 dated Sep. 1, 2022 (9 pages). [cited by applicant]
International Preliminary Report on Patentability for PCT/EP2021/053764 dated Sep. 1, 2022 (9 pages). [cited by applicant]
International Report on Patentability for PCT/EP2021/083783 dated Jul. 13, 2023 (8 pages). [cited by applicant]
International Search Report & Written Opinion for PCT/EP2023/053489 dated Apr. 13, 2023 (16 pages). [cited by applicant]
International Search Report & Written Opinion for PCT/EP2023/053486 dated Apr. 13, 2023 (16 pages). [cited by applicant]
International Search Report & Written Opinion for PCT/EP2023/053493 dated Apr. 21, 2023 (16 pages). [cited by applicant]
International Search Report & Written Opinion for PCT/EP2023/053494 dated Apr. 21, 2023 (17 pages). [cited by applicant]
International Search Report & Written Opinion for for PCT/EP2021/053763 dated Mar. 9, 2021 (13 pages). [cited by applicant]
International Search Report & Written OEinion for PCT/EP2021/053764 dated Mar. 9, 2021 (13 pages). [cited by applicant]
International Search Report & Written Opinion for PCT/EP2021/083783 dated Mar. 1, 2022 (15 pages). [cited by applicant]
James Atwood et al: “Fair treatment allocations in social networks”, arxiv.org, Cornell University Library, 201 Olin Libray Cornell University Ithaca, NY 14853, Nov. 1, 2019 (Nov. 1, 2019), XP081531701 (11 pages). [cited by applicant]
Lev Muchnik et al: “Initial growth rates of epidemics fail to predict their reach: A lesson from large scale malware spread analysis”, arxiv.org, Cornell University Library, 201 Olin Library Cornell University Ithaca, N… [cited by applicant]
Liu Guannan et al: “An Approach to finding the cost-effective immunization target for information assurance”, Decision Support Systems, Elsevier, Amsterdam, NL, vol. 67, Aug. 19, 2014 (Aug. 19, 2014), pp. 40-52, XP02902… [cited by applicant]
Matsubara Yasuko et al., “Nonlinear Dynamics of Information Diffusion in Social Networks”, ACM Transactions on the Web (TWEB), ACM New York, 03 NY, USA, 2 Penn Plaza, Suite 701 New York NY 10121-0701 USA, 04 vol. 11, No… [cited by applicant]
Search Report for GB2002122.6 Dated Aug. 4, 2020 (4 pages). [cited by applicant]
Search Report for GB2002122.6 dated Nov. 30, 2021 (3 pages). [cited by applicant]
Examination Report for EP21824337.6 dated Jul. 1, 2024 (5 pages). [cited by applicant]
Extended European Search Report for EP 20157627.9 dated Jun. 12, 2020 (9 pages). [cited by applicant]
Extended European Search Report for EP 20157626.1 dated Jun. 12, 2020 (10 pages). [cited by applicant]
Extended European Search Report for 20168112.9 dated Sep. 4, 2020 (9 pages). [cited by applicant]
International Search Report and Written Opinion for PCT/EP2021/058360 dated Jun. 2, 2021 (12 pages). [cited by applicant]
US Non-Final Office Action for U.S. Appl. No. 17/904,453 dated Jun. 21, 2024 (12 pages). [cited by applicant]
Written Opinion for PCT/EP2021/058360 dated Apr. 22, 2022 (7 pages). [cited by applicant]
Xu Sheng et al: “Analysis of Malware-Induced Cyber Attacks in Cyber-Physical Power Systems”, IEEE Transactions on Circuits and Systems II: Express Briefs, IEEE, USA, vol. 67, No. 12, Dec. 2020, pp. 3482-3486, XPO1182270… [cited by applicant]
U.S. Appl. No. 18/845,189, filed Sep. 9, 2024, Simulation of Malware With Changing Signatures. [cited by applicant]
U.S. Appl. No. 18/844,729, filed Sep. 6, 2024, Contact Rates in Malware Simulation for Responsive Measure Deployment. [cited by applicant]
U.S. Appl. No. 18/844,731, filed Sep. 6, 2024, Determining a Reproduction Number for a Malware. [cited by applicant]
Office Action dated Nov. 24, 2025 issued for U.S. Appl. No. 18/845,189 (13 pages). [cited by applicant]
Office Action dated Nov. 24, 2025, issued for U.S. Appl. No. 18/844,731 (12 pages). [cited by applicant]
Office Action for U.S. Appl. No. 18/844,729, dated Dec. 16, 2025 (9 pages). [cited by applicant]