Simulation of malware with changing signatures
View Patent ↗A computer-implemented method of simulating a propagation of a malware through a set of computer systems, the method comprising: identifying a simulated computer system infected with a simulated malware; determining a first signature of the simulated malware; determining that a mutation condition for the simulated malware has been met; and in response to determining that the mutation period has been met, changing the first signature of the simulated malware to a second signature.
1 . A computer-implemented method of simulating a propagation of a malware through a set of computer systems, the method comprising:
identifying a simulated computer system infected with a simulated malware;
determining a first signature of the simulated malware;
determining that a mutation condition for the simulated malware has been met; and
in response to determining that the mutation condition has been met, changing the first signature of the simulated malware to a second signature; wherein:
the determining that the mutation condition has been met comprises determining that a mutation period for the simulated malware has elapsed; and the mutation period is a period of time that begins at a first time point indicating when the simulated computer system was first infected with the simulated malware.
2 . The method of claim 1 , wherein determining that the mutation period for the simulated malware has elapsed comprises:
determining the first time point indicating when the simulated computer system was first infected with the simulated malware; and
determining that the current time point is the same as or later than a sum of the first time point and the mutation period.
3 . The method of claim 1 , wherein the mutation period is fixed.
4 . The method of claim 1 , wherein the mutation period is variable.
5 . The method of claim 1 , further comprising obtaining the mutation condition for the simulated malware using the first signature.
6 . The method of claim 5 , wherein obtaining the mutation condition for the simulated malware comprises looking up the first signature in a list.
7 . The method of claim 6 , further comprising adding the second signature to the list.
8 . The method of claim 1 , wherein at least one of the first signature and the second signature comprises one or more digits, a string, or a hash.
9 . The method of claim 1 , further comprising randomly generating the second signature.
10 . A computer-implemented malware protection method to protect at least a subset of a set of computer systems from a malware, the method comprising:
accessing a model of the set of computer systems;
simulating a propagation of the malware through the set of computer systems using the model, wherein the simulating comprises
identifying a simulated computer system infected with a simulated malware;
determining a first signature of the simulated malware;
determining that a mutation condition for the simulated malware has been met; and
in response to determining that the mutation condition has been met, changing the first signature of the simulated malware to a second signature; wherein:
the determining that the mutation condition has been met comprises determining that a mutation period for the simulated malware has elapsed; and the mutation period is a period of time that begins at a first time point indicating when the simulated computer system was first infected with the simulated malware; and
identifying one or more malware protection measures to be deployed to one or more of the set of computer systems based on the simulating.
11 . The method of claim 10 , comprising:
deploying the one or more malware protection measures to the one or more computer systems.
12 . A system simulating a propagation of a malware through a set of computer systems, the system comprising:
one or more processors and a memory storing instructions that, when executed by the one or more processors so that the system for simulating the propagation of malware in a network is at least configured to:
identify a simulated computer system infected with a simulated malware;
determine a first signature of the simulated malware;
determine that a mutation condition for the simulated malware has been met; and
in response to the determination that the mutation condition has been met, change the first signature of the simulated malware to a second signature; wherein:
the determination that the mutation condition has been met comprises a determination that a mutation period for the simulated malware has elapsed; and the mutation period is a period of time that begins at a first time point indicating when the simulated computer system was first infected with the simulated malware.
13 . The system of claim 12 , wherein, to determine that the mutation period for the simulated malware has elapsed, the system is at least further configured to:
determine the first time point indicating when the simulated computer system was first infected with the simulated malware; and
determine that the current time point is the same as or later than a sum of the first time point and the mutation period.
14 . The system of claim 12 , wherein the mutation period is fixed.
15 . The system of claim 12 , wherein the mutation period is variable.
16 . The system of claim 12 , wherein the system is further configured to randomly generate the second signature.
17 . A non-transitory computer-readable storage medium storing a computer program comprising instructions that, when executed by a processor, cause the processor to perform the method of claim 1 .