We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.CR

Change to browse by:

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Computer Science > Cryptography and Security

Title: Modeling Self-Propagating Malware with Epidemiological Models

Abstract: Self-propagating malware (SPM) has recently resulted in large financial losses and high social impact, with well-known campaigns such as WannaCry and Colonial Pipeline being able to propagate rapidly on the Internet and cause service disruptions. To date, the propagation behavior of SPM is still not well understood, resulting in the difficulty of defending against these cyber threats. To address this gap, in this paper we perform a comprehensive analysis of a newly proposed epidemiological model for SPM propagation, Susceptible-Infected-Infected Dormant-Recovered (SIIDR). We perform a theoretical analysis of the stability of the SIIDR model and derive its basic reproduction number by representing it as a system of Ordinary Differential Equations with continuous time. We obtain access to 15 WananCry attack traces generated under various conditions, derive the model's transition rates, and show that SIIDR fits best the real data. We find that the SIIDR model outperforms more established compartmental models from epidemiology, such as SI, SIS, and SIR, at modeling SPM propagation.
Subjects: Cryptography and Security (cs.CR); Dynamical Systems (math.DS); Applications (stat.AP)
Cite as: arXiv:2208.03276 [cs.CR]
  (or arXiv:2208.03276v1 [cs.CR] for this version)

Submission history

From: Alesia Chernikova [view email]
[v1] Fri, 5 Aug 2022 16:51:20 GMT (766kb,D)
[v2] Fri, 9 Jun 2023 23:47:37 GMT (3522kb,D)
[v3] Fri, 4 Aug 2023 01:26:20 GMT (8555kb,D)

Link back to: arXiv, form interface, contact.