IP Library › Granted Patent US 12,619,740
Granted Patent B2
US 12,619,740 · App. 18/845,189 · Granted May 5, 2026

Simulation of malware with changing signatures

Inventors: Alfie Beard (London, GB); Tom Bowman (London, GB)
Assignee: BRITISH TELECOMMUNICATIONS PUBLIC LIMITED COMPANY
G06F21/577G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,619,740
App. No.
18/845,189
Granted
May 5, 2026
Kind
B2
Abstract

A computer-implemented method of simulating a propagation of a malware through a set of computer systems, the method comprising: identifying a simulated computer system infected with a simulated malware; determining a first signature of the simulated malware; determining that a mutation condition for the simulated malware has been met; and in response to determining that the mutation period has been met, changing the first signature of the simulated malware to a second signature.

Claims (41)

1 . A computer-implemented method of simulating a propagation of a malware through a set of computer systems, the method comprising:

identifying a simulated computer system infected with a simulated malware;

determining a first signature of the simulated malware;

determining that a mutation condition for the simulated malware has been met; and

in response to determining that the mutation condition has been met, changing the first signature of the simulated malware to a second signature; wherein:

the determining that the mutation condition has been met comprises determining that a mutation period for the simulated malware has elapsed; and the mutation period is a period of time that begins at a first time point indicating when the simulated computer system was first infected with the simulated malware.

2 . The method of claim 1 , wherein determining that the mutation period for the simulated malware has elapsed comprises:

determining the first time point indicating when the simulated computer system was first infected with the simulated malware; and

determining that the current time point is the same as or later than a sum of the first time point and the mutation period.

3 . The method of claim 1 , wherein the mutation period is fixed.

4 . The method of claim 1 , wherein the mutation period is variable.

5 . The method of claim 1 , further comprising obtaining the mutation condition for the simulated malware using the first signature.

6 . The method of claim 5 , wherein obtaining the mutation condition for the simulated malware comprises looking up the first signature in a list.

7 . The method of claim 6 , further comprising adding the second signature to the list.

8 . The method of claim 1 , wherein at least one of the first signature and the second signature comprises one or more digits, a string, or a hash.

9 . The method of claim 1 , further comprising randomly generating the second signature.

10 . A computer-implemented malware protection method to protect at least a subset of a set of computer systems from a malware, the method comprising:

accessing a model of the set of computer systems;

simulating a propagation of the malware through the set of computer systems using the model, wherein the simulating comprises

identifying a simulated computer system infected with a simulated malware;

determining a first signature of the simulated malware;

determining that a mutation condition for the simulated malware has been met; and

in response to determining that the mutation condition has been met, changing the first signature of the simulated malware to a second signature; wherein:

the determining that the mutation condition has been met comprises determining that a mutation period for the simulated malware has elapsed; and the mutation period is a period of time that begins at a first time point indicating when the simulated computer system was first infected with the simulated malware; and

identifying one or more malware protection measures to be deployed to one or more of the set of computer systems based on the simulating.

11 . The method of claim 10 , comprising:

deploying the one or more malware protection measures to the one or more computer systems.

12 . A system simulating a propagation of a malware through a set of computer systems, the system comprising:

one or more processors and a memory storing instructions that, when executed by the one or more processors so that the system for simulating the propagation of malware in a network is at least configured to:

identify a simulated computer system infected with a simulated malware;

determine a first signature of the simulated malware;

determine that a mutation condition for the simulated malware has been met; and

in response to the determination that the mutation condition has been met, change the first signature of the simulated malware to a second signature; wherein:

the determination that the mutation condition has been met comprises a determination that a mutation period for the simulated malware has elapsed; and the mutation period is a period of time that begins at a first time point indicating when the simulated computer system was first infected with the simulated malware.

13 . The system of claim 12 , wherein, to determine that the mutation period for the simulated malware has elapsed, the system is at least further configured to:

determine the first time point indicating when the simulated computer system was first infected with the simulated malware; and

determine that the current time point is the same as or later than a sum of the first time point and the mutation period.

14 . The system of claim 12 , wherein the mutation period is fixed.

15 . The system of claim 12 , wherein the mutation period is variable.

16 . The system of claim 12 , wherein the system is further configured to randomly generate the second signature.

17 . A non-transitory computer-readable storage medium storing a computer program comprising instructions that, when executed by a processor, cause the processor to perform the method of claim 1 .

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 9, 2024
From: BEARD, ALFIE; BOWMAN, TOM
To: BRITISH TELECOMMUNICATIONS PUBLIC LIMITED COMPANY
Reel/Frame 068529/0041 →
Priority Claims (1)
GB 2203355 · Mar 10, 2022 · national
Continuity (1)
Related Publication 20250190583A1 · Jun 12, 2025
References Cited (92)
US 7739740B1 · Nachenberg · 2010 [cited by examiner]
US 8065731B1 · Nucci · 2011 [cited by applicant]
US 8978141B2 · Eliseev · 2015 [cited by applicant]
US 9060018B1 · Yu et al. · 2015 [cited by applicant]
US 9332029B1 · Tikhonov · 2016 [cited by applicant]
US 9473520B2 · Dixon · 2016 [cited by applicant]
US 9607148B1 · Magar · 2017 [cited by applicant]
US 11546767B1 · Shaw · 2023 [cited by applicant]
US 12273376B2 · Wang · 2025 [cited by applicant]
US 20070150957A1 · Hartrell · 2007 [cited by applicant]
US 20080201129A1 · Natvig · 2008 [cited by applicant]
US 20090320133A1 · Viljoen · 2009 [cited by examiner]
US 20110041179A1 · Staahlberg · 2011 [cited by examiner]
US 20130007883A1 · Zaitsev · 2013 [cited by applicant]
US 20130340080A1 · Gostev et al. · 2013 [cited by applicant]
US 20180288087A1 · Hittel · 2018 [cited by applicant]
US 20190052659A1 · Weingarten et al. · 2019 [cited by applicant]
US 20210014240A1 · Wang · 2021 [cited by applicant]
US 20220038467A1 · Kimura · 2022 [cited by applicant]
US 20230123046A1 · Wang · 2023 [cited by applicant]
CN 109190375 · 2019 [cited by applicant]
EP 1990973 · 2008 [cited by applicant]
EP 4222923 · 2024 [cited by applicant]
GB 2574093 · 2019 [cited by applicant]
WO 2006132987 · 2006 [cited by applicant]
WO 2019185404 · 2019 [cited by applicant]
WO 2021001235 · 2021 [cited by applicant]
WO 2021001237 · 2021 [cited by applicant]
WO 2021165256 · 2021 [cited by applicant]
WO 2021165257 · 2021 [cited by applicant]
WO WO2021198295A1 · 2021 [cited by applicant]
WO 2022069401 · 2022 [cited by applicant]
Joachim Fabini et al. (“Malware propagation in smart grid networks: metrics, simulation and comparison of three malware types”, Aug. 28, 2018, Journal of Computer Virology and Hacking Techniques, vol. 15, pp. 109-125.) … [cited by examiner]
Muhammed Khan, et al. (“Cognitive Function of Polymorphic Malware Using Fractal Based Semantic Characterization”, Apr. 25, 2017, 2017 IEEE International Symposium on Technologies for Homeland Security, pp. 1-7.) (Year: … [cited by examiner]
Wanping Liu, Shouming Zhong, “Web malware spread modelling and optimal control strategies”, published on Feb. 10, 2017 (19 pages). [cited by applicant]
Wright Rob, “What is polymorphic virus?—Definition from WhatIs.com”, 2021, pp. 1-5 URL: httQs:/Iweb.archive.org/webI20211127061825/httQs:/Iwww.techtarget.co (5 pages). [cited by applicant]
Jia Zhi-Juan et al., 2017 29th Chinese Control and Decision Conference (CCDC), 2017, “Research on computer virus source modeling with immune characteristics”, pp. 4616-4619 p. 1, line 10, p. 2, col. 2, lines 16-17, p. 3… [cited by applicant]
Faghani Mohammad et al., 5th International Conference on New Technologies, Mobility and Security (NTMS), 2012, “A Study of Trojan Propagation in Online Social Networks”, pp. 1-5 p. 3, col. 2, lines 11-16, 2012 (5 pages). [cited by applicant]
Beyah R A et al: “The case for collaborative distributed wireless intrusion detection systems”, Granular Computing, 2006 IEEE International Conference on Atlanta, GA, USA May 10-12, 2006, Piscataway, NJ, USA, IEEE, May … [cited by applicant]
Chenxi Wang et al: “On computer viral infection and the effect of immunization”, Computer Security Applications, 2000, ACSAC '00. 16th Annual Conference E New Orleans, LA, USA Dec. 11-15, 2000, Los Alamitos, CA, USA, IE… [cited by applicant]
Combined Search & Exam Report for GB2203361.7 dated Oct. 17, 2022 (12 pages). [cited by applicant]
Combined Search & Exam Report for GB2203366.6 dated Oct. 21, 2022 (12 pages). [cited by applicant]
Combined Search and Exam Report for 2203371.6 dated Nov. 3, 2022 (12 pages). [cited by applicant]
Combined Search and Exam Report for 2004994.6 dated Jul. 13, 2020. [cited by applicant]
Combined Search and Exam Report for GB2002121.8 Dated Aug. 4, 2020. [cited by applicant]
Piet Van Mieghem, Computer Communications, vol. 35, Apr. 18, 2012, “The viral conductance of a network”, pp. 1494-1506 see Abstract Section 2 (8 pages). [cited by applicant]
Eder-Neuhauser Peter et al: “Malware propagation in smart grid networks: metrics, simulation and comparison of three malware types”, Journal of Computer Virology and Hacking Techniques, Springer Paris, Paris, vol. 15, N… [cited by applicant]
Exam Report for GB2002122.6 dated Nov. 30, 2021. [cited by applicant]
Faghani Mohammad R. et al: “A Study of Trojan Propagation in Online Social Networks” , 2012 5th International Conference on New Technologies, Mobility and Security (NTMS) , May 1, 2012 (May 1, 2012), pp. 1-5, XP05596635… [cited by applicant]
Combined Search & Exam Report for GB2020915.1 dated May 11, 2021 5 pages). [cited by applicant]
Combined Search & Exam Report for GB2203355.9 dated Oct. 10, 2022. [cited by applicant]
Hernandez Guillen J D et al: “A mathematical model for malware spread on WSNs with population dynamics”, Physica A, North-Holland, Amsterdam, NL, vol. 545, Nov. 22, 2019 (Nov. 22, 2019), XP086098687 (11 pages). [cited by applicant]
Hosseini Soodeh Ed—Vega-Rodriguez Miguel A et al: “Defense against malware propagation in complex heterogeneous networks”, Cluster Computing, Baltzer Science Publishers, Bussum, NL, vol. 24, No. 2, Sep. 12, 2020 (Sep. 1… [cited by applicant]
Khan Muhamad Salman et al., IEEE International Symposium on Technologies for Homeland Security (HST), 2017, “Cognitive modeling of polymorphic malware using fractal based semantic characterization”, pp. 1-7 p. 2, col. 1… [cited by applicant]
International Preliminary Report on Patentability for PCT/EP2021/058360 issued Aug. 11, 2022 (14 pages). [cited by applicant]
International Preliminary Report on Patentability for PCT/EP2021/053763 dated Sep. 1, 2022 (9 pages). [cited by applicant]
International Preliminary Report on Patentability for PCT/EP2021/053764 dated Sep. 1, 2022 (9 pages). [cited by applicant]
International Report on Patentability for PCT/EP2021/083783 dated Jul. 13, 2023 (8 pages). [cited by applicant]
International Search Report & Written Opinion for PCT/EP2023/053489 dated Apr. 13, 2023 (16 pages). [cited by applicant]
International Search Report & Written Opinion for PCT/EP2023/053486 dated Apr. 13, 2023 (16 pages). [cited by applicant]
International Search Report & Written Opinion for PCT/EP2023/053493 dated Apr. 21, 2023 (16 pages). [cited by applicant]
International Search Report & Written Opinion for PCT/EP2023/053494 dated Apr. 21, 2023 (17 pages). [cited by applicant]
International Search Report & Written Opinion for FOR PCT/EP2021/053763 dated Mar. 9, 2021 (13 pages). [cited by applicant]
International Search Report & Written Opinion for PCT/EP2021/053764 dated Mar. 9, 2021 (13 pages). [cited by applicant]
International Search Report & Written Opinion for PCT/EP2021/083783 dated Mar. 1, 2022 (15 pages). [cited by applicant]
James Atwood et al: “Fair treatment allocations in social networks”, arxiv.org, Cornell University Library, 201 Olin Libray Cornell University Ithaca, NY 14853, Nov. 1, 2019 (Nov. 1, 2019), XP081531701 (11 pages). [cited by applicant]
Lev Muchnik et al: “Initial growth rates of epidemics fail to predict their reach: A lesson from large scale malware spread analysis”, arxiv.org, Cornell University Library, 201 Olin Library Cornell University Ithaca, N… [cited by applicant]
Liu Guannan et al: “An Approach to finding the cost-effective immunization target for information assurance”, Decision Support Systems, Elsevier, Amsterdam, NL, vol. 67, Aug. 19, 2014 (Aug. 19, 2014), pp. 40-52, XP02902… [cited by applicant]
Matsubara Yasuko et al., “Nonlinear Dynamics of Information Diffusion in Social Networks”, ACM Transactions on the Web (TWEB), ACM New York, 03 NY, USA, 2 Penn Plaza, Suite 701 New York NY 10121-0701 USA, 04 vol. 11, No… [cited by applicant]
Search Report for GB2002122.6 dated Nov. 30, 2021 (3 pages). [cited by applicant]
Examination Report for EP21824337.6 dated Jul. 1, 2024 (5 pages). [cited by applicant]
Extended European Search Report for EP 20157627.9 dated Jun. 12, 2020 (9 pages). [cited by applicant]
Extended European Search Report for EP 20157626.1 dated Jun. 12, 2020 (10 pages). [cited by applicant]
Extended European Search Report for 20168112.9 dated Sep. 4, 2020 (9 pages). [cited by applicant]
International Search Report and Written Opinion for PCT/EP2021/058360 dated Jun. 2, 2021 (12 pages). [cited by applicant]
US Non-Final Office Action for U.S. Appl. No. 17/904,453 dated Jun. 21, 2024 (12 pages). [cited by applicant]
Written Opinion for PCT/EP2021/058360 dated Apr. 22, 2022 (7 pages). [cited by applicant]
Xu Sheng et al: “Analysis of Malware-Induced Cyber Attacks in Cyber-Physical Power Systems”, IEEE Transactions on Circuits and Systems II: Express Briefs, IEEE, USA, vol. 67, No. 12, Dec. 2020, pp. 3482-3486, XPO1182270… [cited by applicant]
International Preliminary Report on Patentability dated Sep. 19, 2024, issued for International Application No. PCT/EP2023/053486 (9 pages). [cited by applicant]
International Preliminary Report on Patentability dated Sep. 19, 2024, issued for International Application No. PCT/EP2023/053494 (10 pages). [cited by applicant]
International Preliminary Report on Patentability dated Sep. 19, 2024, issued for International Application No. PCT/EP2023/053489 (9 pages). [cited by applicant]
International Preliminary Report on Patentability dated Sep. 19, 2024, issued for International Application No. PCT/EP2023/053493 (9 pages). [cited by applicant]
Office Action dated Sep. 29, 2024, issued for U.S. Appl. No. 17/995,365 (33 pages). [cited by applicant]
Notice of Allowance dated May 14, 2025 issued for U.S. Appl. No. 17/904,467 (12 pages). [cited by applicant]
Office Action dated Dec. 2, 2024 issued for U.S. Appl. No. 17/904,467 (13 pages). [cited by applicant]
Notice of Allowance dated Dec. 31, 2024 issued for U.S. Appl. No. 17/904,453 (9 pages). [cited by applicant]
Office Action dated Apr. 3, 2025 issued for U.S. Appl. No. 17/904,453 (5 pages). [cited by applicant]
Notice of Allowance dated May 1, 2025 issued for U.S. Appl. No. 17/995,365 (10 pages). [cited by applicant]
Office Action dated Dec. 16, 2025, issued for U.S. Appl. No. 18/844,729 (9 pages). [cited by applicant]
Notice of Allowance dated Jan. 21, 2026, issued for U.S. Appl. No. 18/845,144 (10 pages). [cited by applicant]
Office Action dated Nov. 24, 2025 issued for U.S. Appl. No. 18/845,144 (9 pages). [cited by applicant]
Office Action dated Nov. 24, 2025 issued for U.S. Appl. No. 18/844,731 (12 pages). [cited by applicant]