ConceptioArchivearXiv CS
arXiv CSopen access

GTI-mSEMP Framework : A Proposed Framework to Simulate Malware Propagation with Inclusion of Attacker-Defender Strategy

Unknown · 2026 · arxiv_cs
arXiv CS · Papers · License: Open Access · 2026
Open Source ↗Direct PDF ↓
distributedsystemsprotocols
networking, internet, protocols, distributed systems

GTI-mSEMP Framework : A Proposed Framework to Simulate Malware Propagation with Inclusion of Attacker-Defender Strategy Shadeeb Hossain1,2,ϯ [ORCID ID: 0000-0002-5224-7684], Kristopher Wilson1, 1

Capitol Technology University, Department of Engineering, Laurel, MD 20708

2

Shadeeb Engineering Lab, Research Division, Brooklyn, NY 11223.

Abstract : The rapid proliferation of automated, multi-vector malware threats poses a significant risk to heterogeneous, resource constrained cyber-physical networks. Conventional epidemiological models often treat security defenses as static parameters, failing to capture the strategic, asymmetric maneuvers between an attacker and a defender. To address the gap, this paper proposes a Game-Theory-Integrated Modified Multi- Wireless Sensor Epidemic Malware Propagation (GTI-mSEMP) framework. This paper analyzed and compared the operational trajectories of Susceptible (S) and Recovered (R) node populations across three different operational regimes: Balanced Matchup, Exploit Surge and Hardened Defense. Numerical simulation results capture the real-time transient dynamics of the network state variables, demonstrating how the epidemic curve shifts when either the defensive or offensive scaling vectors hold an efficiency advantage. The proposed mathematical and numerical framework provides a rigorous foundation that can be deployed in highly adversarial network environments to evaluate dynamic malware propagation and predict localized node population states.

Keywords: Attacker-Defender strategy; Brute Force Attack; Cybersecurity; Malware Propagation; SEIR model.

ϯ

Corresponding author: [email protected]

S. Hossain and K. Wilson

I.

Introduction

With the rise of Internet of Things (IoT) connected smart cities, most wireless systems are now susceptible to malware attacks [1-4]. Some of the malware attacks include: (i) worms, (ii) botnets, (iii) viruses, (iv)trojans, and (v)ransomware among others [5-8]. Malware can allow unauthorized access to the system and thereby contribute to several cybersecurity threats including leaking confidential information, consuming valuable resources or energy and even hostile takeover of the targeted network [9]. The malware spreading through the network can be modeled to assess their rate of compromise and predict their future stake in real time [10]. Cybersecurity analysts require dynamic simulated models to analyze the evolution and spread of malware code through their network. In 2016, the Mirai botnet included a spree of large-scale denial of service (DDos) attack [11]. Antonakakis et al. investigated the Mirai’s botnets growth and DDoS activity between August 1, 2016, to February 28,2017 and created a comprehensive dataset to develop future technical and non-technical defenses for future attacks [12]. Another prominent botnet is the Mozi IoT malware attack in 2019 that was able to infect 1.5 million IoT devices. [13]. Unlike Mirai, which relies on a centralized command-and control (C2) server infrastructure, Mozi utilized a peer-to-peer (P2P) network topology based on a Distributed Hash Table (DHT). Another example of a dangerous cyber threat is the zero-day ransomware Wannacry, that was able to halt the operations of large corporations and hospital facilities from over 150 countries [14]. Wannacry malware relies on the Server Message Block (SMB) protocol which checks the IP address and tries to connect over TCP port 445 [15-17]. Inspite of the security protocols, it becomes critical to have a comprehensive understanding of the propagation model in real-time to limit the spread. Mathematical simulations can play a critical role in such analysis. Susceptible, Exposed, Infected and Recovered (SEIR) are usually the four stages of a malware attack and the model that is used in predicting the malware propagation (particularly worm) in infected networks [18,19]. It is important to understand that most of the traditional compartmental models assume timeinvariant transition rates as it only focuses on a particular attack-and-defense strategy. However, in real case scenarios, the defenders operate under strict operational and computational resource constraints, or the defender can actively change their approach depending on attackers’ action. Stochastic games, which is a combination of game theory and Markov Decision Processes (MDP), can be used to analyze the randomness in the cyber-attack and therefore be included in the conventional SEIR model. Markov Decision Processes extend to a multiplayer competitive environment and can be used to characterize the randomness in cyber-attack and defense strategies [20]. This implies that the recovery rate (𝛾), transmission rate (𝛽) and the effective reproduction number (𝑅𝑡 ) cannot be treated as time-invariant constraints; instead, they function as dynamic variables dependent on the localized strategy profiles executed within the stochastic game framework.

GTI-mSEMP Framework The primary objective of this paper is to propose a Game-Theory-Integrated Modified MultiWireless Sensor Epidemic Malware Propagation (GTI-mSEMP) framework. This model accommodates a (i) time-variant (attacker-defender response) recovery rate, (ii) time dependent (attacker-defender response) transmission rate, and a (iii) dynamic effective reproduction number, thereby establishing a highly realistic simulation environment for active cyber defense-attack scenarios. The paper is divided into the following sections: Section II: Relevant studies and background information, Section III: Proposed GTI-mSEMP framework, Section IV: Simulation Parameters, Section V: Results and Discussion, Section V: Conclusion. II.

Relevant Studies and Background Information

There are different types of epidemic models to stimulate the spread of malware viruses or worms through a system of connected wireless networks [21-25]. Understanding these models are critical to design defense mechanisms and determine critical responses. The common state of the malware attack and defense mechanisms include: (i)

(ii)

(iii)

(iv)

III.

Susceptible (S) state: During this state, the wireless sensor nodes are still not exposed to the malware attack but are still susceptible to potential attack. The probability of susceptible nodes transitioning to exposed state is p. A stronger cybersecurity network will have a lower magnitude of p, compared to its counterparts. Exposed (E) state : During this state, the sensor nodes are exposed to the malware and will be infected as a function of time unless an effective defense mechanism is adopted by the cybersecurity team of defense. Awasthi et al. (2023) proposed Exposed State1(E1) and Exposed State -2 (E2) to replicate two types of malware attack [21]. Infected (I) state: During this state, the infected sensor nodes can infect other neighboring sensor nodes. The rate of recovery, 𝛾 , depend on both the defense and attacker’s strategy and there is a possibility of the infected node to either transition to Recovered state or crash due to malfunction. Recovered (R) state: The Recovered (R) state includes when the sensory nodes have actively recovered from their infectious state. The rate of re-susceptibility is given by 𝛿. This state is usually considered the last state of the cyber-attack cycle.

Proposed GTI-mSEMP framework

A. Susceptible State In the foundational state, the operational wireless sensor nodes have not been exposed to the malicious payload but possess inherent vulnerabilities that render them susceptible to potential exploits. The probability of a susceptible node transitioning to the latent Exposed (E) state within a discrete time epoch is denoted by p, where p ∈ [0,1]. Mathematically, p is not a static scalar, but 3

S. Hossain and K. Wilson a dynamic conditional probability distribution formulated as a function of the network’s spatial node density (or clustering coefficient), the attacker’s operational intensity, and the defender’s responsive security policy and is given by the equation (1): (1)

𝑝 = 𝑓(𝜌, 𝑎𝐴 , 𝑑𝐷 )

where, 𝜌 is the spatial density of the Wireless Sensor Network (WSN) deployment layer, 𝑎𝐴 ∈ A signifies the offensive strategy chosen from the attacker’s action space, and 𝑑𝐷 ∈ D denotes the dynamic mitigation protocol executed from the defender’s policy repository. To capture the multi-layered nature of advanced persistent threats (APT) in WSN ecosystem, the offensive strategy 𝑎𝐴 is used. It is the strategy action matrix as shown in equation (2), which determines the offensive resource or energy to allocate across different target choices and attack vectors at time step, t. 𝑎11 𝐴=( ⋮ 𝑎𝑛1

⋯ ⋱ ⋯

𝑎1𝑚 ⋮ ) 𝑎𝑛𝑚

(2)

where 𝑎𝑖𝑗 is the specific offensive investment or scan intensity directed at Node class i using Exploit vector j. To counter the multi-layered operational profiles of APTs, the defender’s strategy profile 𝑑𝐷 , can be formalized as n x m matrix that matches the dimension of the attacker’s matrix. 𝑑11 𝐷=( ⋮ 𝑑𝑛1

⋯ ⋱ ⋯

𝑑1𝑚 ⋮ ) 𝑑𝑛𝑚

(3)

where 𝑑𝑖𝑗 represents the percentage of security assets, defensive compute cycles, or network bandwidth that the defender allocates to protect Node class i against Exploit layer j. The transition probability, 𝑝𝑖𝑗 can be modelled as a ratio shown in equation (4). For simplicity, we are keeping the node density, 𝜌 constant. 𝑎

𝑖𝑗 𝑝𝑖𝑗 (𝐴, 𝐷) = 𝑎 +𝛼𝑑 +∈ 𝑖𝑗

𝑖𝑗

(4)

where, 𝛼 is the defensive efficiency coefficient (the effectiveness of the defensive tool) and ∈ is the baseline network vulnerability when no defensive actions are taken. The rate of change of Susceptible (S) stage which incorporates both the offensive and defensive strategy is given by the following equation (5). 𝑑𝑆 𝑑𝑡

= 𝑏 + 𝛿𝑖𝑗 𝑅 − (𝑝𝑖𝑗 𝜌)𝑆𝐼 − 𝜔𝑆 − 𝜎𝑆

(5)

GTI-mSEMP Framework where, b denotes the new node provisioning or join rate, 𝛿 represents re-susceptibility coefficient characterizing recovered nodes that revert to a vulnerable state due to patch expiration or configuration resets. The parameter 𝑝𝑖𝑗 defines the conditional transition probability of a susceptible node entering the latent state as shown in equation (5). The 𝜔 signifies the proactive immunization rate driven by administrative security mechanisms (for example, automated anti-virus deployment), while 𝜎 denotes the hardware attrition rate accounting for sensor node failures induced by operational energy and battery constraints. B. Exposed State (E) Similarly, the exposed state E is given by equation (6). 𝑑𝐸 𝑑𝑡

= [𝑝𝑖𝑗 (𝐴, 𝐷)𝜌]𝑆𝐼 − (𝜆1 + 𝜎)𝐸

(6)

where, [𝑝𝑖𝑗 (𝐴, 𝐷)𝜌]𝑆𝐼 denotes active transmission rate of malware propagation from Susceptible (S) to the latent Exposed (E) state. The (𝜆1 + 𝜎)𝐸 dictates the cumulative exit rate from the latent state. The 𝜆1 represents the transition rate at which an Exposed node (E) transitions to Infectious node (I). In classic epidemic models, 𝜆1 (the incubation or transition rate from Exposed to Infected) is a fixed hardware or software constant representing how long a virus naturally takes to execute. However, in an advanced cyber-warfare scenario, this transition window is actively manipulated by the defender-attacker parties involved. The latent transition rate coefficient is bounded such that 𝜆1 ∈ [0,1] within the discrete -time execution environment. This coefficient characterizes the operational latency of the malware payload: a value of 𝜆1 =0 implies absolute execution suppression while 𝜆1 =1 denotes instantaneous, single epoch initialization of the malicious process thread moving from latent Exposed (E) compartment to the active Infectious (I) compartment. Mathematically, the latent transition coefficient 𝜆1 = 𝑓(𝜌, 𝑎𝐴 , 𝑑𝐷 ) can be written as equation (7). 1+𝜇𝑎

𝜆1 = 𝜆𝑜 (1+ƞ𝑑 𝐴.𝑒𝑥𝑒𝑐 ) 𝐷.𝑎𝑢𝑑𝑖𝑡

(7)

where, 𝜆𝑜 is the baseline hardware execution speed of the malware binary, 𝑎𝐴.𝑒𝑥𝑒𝑐 is the attacker’s strategic investment in payload optimization, 𝑑𝐷.𝑎𝑢𝑑𝑖𝑡 is the defender’s runtime auditing intensity in that specific node layer. If the attacker’s execution acceleration coefficient, 𝜇 is large, then the malware is highly optimized for the target architecture allowing small tactical investments to drastically accelerate to outbreak speed. Similarly, the defender’s detection efficiency coefficient, ƞ is a measure of how effective the defender’s auditing tools are at actively discovering, slowing down or sandboxing an unauthorized process thread. 5

S. Hossain and K. Wilson Similarly, the defender’s detection efficiency coefficient, ƞ is a measure of how effective the defender’s auditing tools are at actively discovering, slowing down or sandboxing an unauthorized process thread. If there are separate simultaneous malware attacks in the network, then the exposed state can be represented by En and the corresponding transition rate as 𝜆𝑛 , where n∈ {1,2,3 … … 𝑁}. C. Infectious State (I) During the Infectious (I) state, compromised sensor nodes possess active, executing malware payloads and propagate malicious packets to neighboring susceptible and latent nodes across the WSN topology. The effective recovery rate, 𝛾𝑖𝑗 (𝐴, 𝐷) is formalized as a joint function of the attacker-defender strategy profiles. From the infectious compartment, a node can transition into either pathway: (i) Recovered pathways via administrative patch deployment and mitigation vectors, (ii) Permanently exits the network topology due to operational crashing or hardware malfunction induced by malicious resource exhaustion. Mathematically, the infectious state (I), is given by equation (8): 𝑑𝐼 𝑑𝑡

= 𝜆1 𝐸 − 𝛾𝑖𝑗 (𝐴, 𝐷)𝐼 − 𝜎𝐼

(8)

where, 𝛾𝑖𝑗 (𝐴, 𝐷)𝐼is the strategic outflow rate of nodes being successfully patched and moved to recovered state. However, for simultaneous malware attacks, the inflow of latent nodes initializing their payloads is given by the following equation (9): inflow of latent nodes initializing their payloads = ∑𝑁 𝑛=1 𝜆𝑛 𝐸𝑛

(9)

The strategic recovery rate includes the dynamic attacker-defender strategy profiles as similar to our susceptible probability. Mathematically, 𝛾𝑖𝑗 = 𝑓(𝜌, 𝑎𝐴 , 𝑑𝐷 ) can be expressed as equation (10): (1+ƞ𝐼 𝑑 )

𝛾𝑖𝑗 (𝐴, 𝐷) = 𝛾𝑜 ( 1+𝜇 𝑎𝑖𝑗 ) 𝐼 𝑖𝑗

(10)

where, 𝛾𝑜 is the baseline network recovery rate that could include automated backup or reboot frequency. Similarly, ƞ𝐼 and 𝜇𝐼 is the scaling sensitivity coefficients that define the operational effectiveness of each player’s active strategy during the recovery phase. D. Recovered State (I) This encompasses the sub-population of sensor nodes that have been successfully remediated and immunized against the active malware strains. Nodes enter this state through two distinct channels: (i) proactively from the Susceptible (S) pool via administrative security broadcasting, or (ii) reactively from the Infectious (I) pool following successful local firmware patching (𝛾𝑖𝑗 𝐼).

GTI-mSEMP Framework The rate of re-susceptibility, wherein a recovered node sheds its immunity and reverts to the Susceptible (S) state is governed by the strategic function,𝛿𝑖𝑗 (A, D). This functional formulation captures the real-time competitive friction between the adversaries, aij and dij. Mathematically, the Recovered state is given by equation (11): 𝑑𝑅 𝑑𝑡

= 𝜔𝑆 + 𝛾𝑖𝑗 (𝐴, 𝐷)𝐼 − 𝛿𝑖𝑗 (𝐴, 𝐷)𝑅 − 𝜎𝑅

(11)

where, 𝜔𝑆 is the proactive background defense channel and 𝜎𝑅 is the background mortality rate. The game dependent re-susceptibility coefficient, 𝛿𝑖𝑗 = 𝑓(𝜌, 𝑎𝐴 , 𝑑𝐷 )is given by equation (12): 1+𝜇𝑅 𝑎𝑖𝑗

𝛿𝑖𝑗 (𝐴, 𝐷) = 𝛿𝑜 (1+ƞ 𝑑 ) 𝑅 𝑖𝑗

(12)

where, 𝛿𝑜 is the baseline natural rate of patch degradation and 𝜇𝑅 , ƞ𝑅 is the scaling sensitivity coefficients. IV.

Simulation Parameters

To evaluate the operational dynamics of the proposed GTI-mSEMP framework, the baseline simulation model categorizes the network topology into three distinct heterogeneous node classes: (i) Core Gateway, (ii) Intermediate Routing Nodes, and (iii) Low-Power Peripheral Sensors. Correspondingly, two primary adversarial vectors are evaluated to represent varying tiers of threat severity: (i) Brute-Force Attack (BFA), characterized by automated credential guessing routines, and (ii) Zero-Day Exploits, representing sophisticated attacks targeting undocumented software or hardware vulnerabilities [26-29]. The strategic resource allocation profiles of both the attacker and defender are mapped to a joint 3 x 2 game matrix (A, D ∈ 𝑅 3 𝑥2 ), where the row vectors correspond to the targeted topological node layers and column vectors quantify the relative capital assigned to each exploit scenario. To analyze the systemic sensitivity under varying tactical conditions, three foundational operational regimes are investigated: Case I- Balanced Equilibrium Matchup (which establishes a baseline symmetric resource allocation between both players), Case II- Evasive Exploit Surge (simulating a strategic mismatch where the defender is severely outmaneuvered), Case III- Aggressive Quarantine (characterizing a hardened network posture reinforced by enhanced administrative defense controls). To mathematically, evaluate the three strategic regimes, the resource allocation matrices for the Attacker (A) and Defender (D) are parameterized across the network layers (Row 1: Gateways, Row 2: Routing Nodes, Row 3: Peripherals) and exploit vectors (Column 1: BFA and Column 2: Zero Day Attack). Case I: Balanced Equilibrium Matchup

7

S. Hossain and K. Wilson 0.40 0.20 𝐴1 = (0.30 0.10) 0.00 0.00

0.40 𝐷1 = (0.30 0.00

0.20 0.10) 0.00

Case II: Evasive Exploit Surge 0.00 0.10 ( 𝐴2 = 0.00 0.90) 0.00 0.00

0.50 0.10 ( 𝐷2 = 0.30 0.10) 0.00 0.00

Case III: Aggressive Quarantine 0.80 0.10 𝐷2 = (0.10 0.00) 0.00 0.00

0.50 0.20 𝐴2 = (0.20 0.10) 0.00 0.00

To evaluate the performance of the proposed GTI-mSEMP framework, a dynamic simulation environment was developed in MATLAB, and the results are compared in Fig. 1. The system of coupled differential equations was solved numerically using the 4th order Runge-Kutta (RK4) method with a fixed integration step of 0.02 over a simulation horizon of t ∈ [0,50] epochs. The network configuration consists of a heterogeneous sensor topology distributed across three localized operational layers. For a comparative study to evaluate the dynamic closed-loop trajectories of the Susceptible, Exposed, Infected and Recovered (SEIR) states within the proposed network framework, a MATLAB simulation was implemented using the parameters outlined in Table-I. In this reactive and evasive matchup (Case II), defensive resources are allocated dynamically to sectors where the malicious footprint is currently spiking. This inadvertently exposes a residual vector space that an evasive attacker can strategically exploit, outmaneuvering the defense and leading to a prolonged epidemic footprint. Mathematically, this closed loop optimization mechanism is governed by equation (13) and (14). The real time state trajectories of this model and the corresponding defender resource allocation tracking per node class are illustrated in Fig.2. (𝐼 (𝑡)+2𝐸 (𝑡)

𝐷𝑤𝑒𝑖𝑔ℎ𝑡,𝑖 (𝑡) = ∑3 [𝐼𝑖 (𝑡)+2𝐸𝑖 (𝑡)]+∈

(13)

𝐷𝑤𝑒𝑖𝑔ℎ𝑡,1 (𝑡) ∗ 0.6 𝐷𝑤𝑒𝑖𝑔ℎ𝑡,1 (𝑡) ∗ 0.4 𝐷(𝑡) = (𝐷𝑤𝑒𝑖𝑔ℎ𝑡,2 (𝑡) ∗ 0.6 𝐷𝑤𝑒𝑖𝑔ℎ𝑡,2 (𝑡) ∗ 0.4) 𝐷𝑤𝑒𝑖𝑔ℎ𝑡,3 (𝑡) ∗ 0.6 𝐷𝑤𝑒𝑖𝑔ℎ𝑡,3 (𝑡) ∗ 0.4

(14)

𝑖=1 𝑗

𝑗

GTI-mSEMP Framework Let i ∈ {1,2,3} denote the specific network layer (Gateway, Routing and Peripheral, respectively). The defense allocation weight vector, 𝐷𝑤𝑒𝑖𝑔ℎ𝑡,𝑖 (𝑡) is dynamically computed each time epoch based on the active infection footprint.

Table I: Parameters used in the GTI-mSEMP Framework simulation Parameters b 𝜔 𝜎 𝜌 𝛼 ∈ 𝜆𝑜 𝛾𝑜 𝛿𝑜

V.

Magnitude 0.5 0.05 0.002 0.002 5 0.02 0.15 0.08 0.04

Description New node provisioning rate Proactive immunization rate Hardware attrition rate Node density Defensive efficiency coefficient Baseline network vulnerability Baseline hardware execution speed Baseline network recovery rate Baseline natural rate of patch degradation

Results and Discussion

Fig. 1 illustrates the operational trajectories of the Susceptible (S) and Recovered (R) node populations across the three investigated regimes. Under Case III (Aggressive Quarantine), the susceptible node population exhibits the sharpest initial decline towards a steady state threshold at 7.5 seconds. While Case III features a hardened posture at the core gateways, this aggressive concentration of defensive assets leaves intermediate routing and peripheral layer resources vulnerable. The adversaries can then exploit these unhardened sectors, accelerating the systemwide depletion of healthy nodes compared to the more gradual decay observed in Case II. This structural vulnerability is further reflected in the recovery trajectories; Case I (Balanced Matchup) achieved the highest global remediation ceiling (~ 435 nodes). This demonstrates that a balanced distribution of defensive capital across all topological layers yields superior long term network resilience compared to a hyper-localized asymmetric defensive strategy. The transient and steady state behaviors of the dynamic closed loop game is illustrated in Fig.2. As shown in the initial state configurations, the Peripheral layer begins with the largest population size of 500 nodes and an active infectious footprint of 15 nodes. Conversely, the Gateway infrastructure contains a highly restrictive baseline footprint of 150 nodes with only 5 nodes initially compromised. This initial distribution directly drives the optimization tracking engine shown in Fig.2 (Right) because the localized threat volume is overwhelmingly concentrated at the network edge, the defender’s allocation fraction is maximized at the Peripheral and minimized at the Gateway tier.

9

S. Hossain and K. Wilson

Fig. 1: Operational trajectories of the Susceptible (S) and Recovered (R) node populations for Case I: Balanced Matchup, Case II: Exploit Surge and Case III: Hardened Defense. Left: Susceptible Node Trajectories. Right: Recovered Node Trajectories

However, across the transient time horizon 𝑡 ∈ [0,50] epochs, a rapid epidemic cascade occurs, characterized by a sharp decline in Susceptible (S) nodes alongside a simultaneous rise and eventual suppression of the Exposed (E) and Infectious (I) populations. Concurrently, the Recovered (R) compartment scales up rapidly before achieving steady state equilibrium as shown in Fig.2 (Left). This successful stabilization is directly attributed to the fluid closed loop game mechanics: as threat vectors propagate across layers, the defender dynamically updates its strategy matrix, steadily increasing resource allocation towards Gateway defense while engineering a controlled reduction in Peripheral budget share. This proves that continuously updating resource distribution in real time successfully counters the attacker’s evasive strategy and directly dictates the recovery rate of the broader cyber-physical network. It must be highlighted that on Fig.2, the game-theoretic scaling vectors favor the defender (ƞ > 𝜇, ƞ𝐼 > 𝜇𝐼 , ƞ𝑅 > 𝜇𝑅 ), granting the security infrastructure a significant operational advantage. When these asymmetric scaling relationships are reversed, a different epidemic footprint is observed as detailed in comparative analysis of Fig.3. To evaluate the sensitivity of the GTI-mSEMP framework under highly adverse conditions, Fig.3 illustrates the system state trajectories when the game-theoretic scaling vectors are inverted to favor the offensive capabilities (, 𝜇𝐼 = 5.0, ƞ𝐼 = 2.0 , 𝜇𝑅 = 6.0 and ƞ𝑅 = 1.5 ). Under this asymmetric configuration, the network undergoes a severe epidemic cascade. As shown in Fig.3 (Left), the Infectious (I) population experiences a massive, unchecked surge, peaking at

GTI-mSEMP Framework approximately 450 nodes -which is significantly higher by more than 400% compared to the defender strategy used in Fig.2.

Fig.2 : Closed Loop Evasive Game Analysis (Case II). Left: Temporal evolution of cumulative sensor node counts distributed across SEIR compartments. Right: Dynamic convergence of defensive resource allocation tracking across heterogeneous network layers.

Since the attacker outmatches the localized patching and suppression rates, the I (t) curve remains prominently above the Recovered (R) curve for majority of the transient horizon, and healthy Susceptible (S) node population is reduced to critically low at 125. The corresponding optimization tracking in Fig.3 (Right) exhibits high early-stage volatility as the defender shifts budget allocation to suppress aggressive multi-layer malware propagation, eventually stabilizing at a steady state equilibrium. VI.

Conclusion

This paper presented a novel Game-Theory-Integrated Modified Multi- Wireless Sensor Epidemic Malware Propagation (GTI-mSEMP) framework tailored for resource constrained cyber-physical networks. By modeling the security environment as a dynamic closed loop evasive game (Case II), this paper mathematically formulated a reactive defender interaction with an adversary capable of predicting and exploiting residual defensive gaps. Numerical simulations executed via 4th Order Range -Kutta integration validated the proposed model when the defensive scaling factors have an operational efficiency advantage, which was represented via suppressed epidemic footprint and a flattened Infectious (I) peak in the simulation output. Conversely, a sensitivity analysis under an offensive -dominant scenario was also evaluated, where an active Infectious (I) peak was observed with a rapid decline in the vulnerable Susceptible (S) node population. These findings validate that 11

S. Hossain and K. Wilson real-time state dependent resource optimization is vital to disrupting automated propagation engines like Brute Force Attack (BFA) and Zero-Day threats. .

Fig.3 : Systemic trajectory under reverted scaling vectors (Variant II). Left: Unchecked epidemic cascade suppressed susceptible node due to heightened attacker capabilities. Right: Dynamic optimization tracking across heterogeneous node layers under severe network stress.

Conflict of Interest The authors have no conflict of interest. Funding Declaration No funding was received for this study.

References [1] Aboubakar, M., Kellil, M., & Roux, P. (2022). A review of IoT network management: Current status and perspectives. Journal of King Saud University-Computer and Information Sciences, 34(7), 4163-4176. [2] Olivier, Flauzac, Gonzalez Carlos, and Nolot Florent. "New security architecture for IoT network." Procedia Computer Science 52 (2015): 1028-1033.

GTI-mSEMP Framework [3] Czajkowski, A., Remiorz, L., Pawlak, S., Remiorz, E., Szyguła, J., Marek, D., ... & Antemijczuk, O. (2021). Global water crisis: Concept of a new interactive shower panel based on IoT and cloud computing for rational water consumption. Applied Sciences, 11(9), 4081. [4] Hossain, S., & Abdelgawad, A. (2018, October). Smart refrigerator based on internet of things (iot) an approach to efficient food management. In Proceedings of the 2nd International conference on smart digital environment (pp. 15-18). [5] Wang, Z., Nie, X., & Liao, M. (2021). Stability Analysis of a Fractional‐Order SEIR‐KS Computer Virus‐ Spreading Model with Two Delays. Journal of Mathematics, 2021(1), 6144953. [6] Gouvea, C. M., Leal, R. H., & Piqueira, J. R. (2025). Investigating the impact of nonlinearity on virus spread in computer networks with quarantine compartments. Nonlinear Science, 100097. [7] Zhang, Z., Zhang, W., Nisar, K. S., Gul, N., & Ahmed, Z. (2023). Bifurcation and global exponential stability of a mathematical model for malware dissemination on wireless sensor networks. Fractals, 31(10), 2340165. [8] Basole, S., & Stamp, M. (2020). Cluster analysis of malware family relationships. In Malware analysis using artificial intelligence and deep learning (pp. 361-379). Cham: Springer International Publishing. [9] Yan, S., Ren, J., Wang, W., Sun, L., Zhang, W., & Yu, Q. (2022). A survey of adversarial attack and defense methods for malware classification in cyber security. IEEE Communications Surveys & Tutorials, 25(1), 467-496. [10] Kharabsheh, M., Al-aiash, I., Mughaid, A., & Almiani, M. (2024, September). The seir model for predicting malware propagation in computer networks. In 2024 International Conference on Intelligent Computing, Communication, Networking and Services (ICCNS) (pp. 108-113). IEEE. [11] Krebs, B. (2016). KrebsOnSecurity hit with record DDoS. KrebsOnSecurity, Sept, 21. [12] Antonakakis, M., April, T., Bailey, M., Bernhard, M., Bursztein, E., Cochran, J., ... & Zhou, Y. (2017). Understanding the mirai botnet. In 26th USENIX security symposium (USENIX Security 17) (pp. 1093-1110). [13] Sahota, J., & Vlajic, N. (2021, December). Mozi IoT malware and its botnets: From theory to real-world observations. In 2021 International Conference on Computational Science and Computational Intelligence (CSCI) (pp. 698-703). IEEE. [14] Chen, Q., & Bridges, R. A. (2017, December). Automated behavioral analysis of malware: A case study of wannacry ransomware. In 2017 16th IEEE International Conference on machine learning and applications (ICMLA) (pp. 454-460). IEEE. [15] Kao, D. Y., & Hsiao, S. C. (2018, February). The dynamic analysis of WannaCry ransomware. In 2018 20th International conference on advanced communication technology (ICACT) (pp. 159-166). IEEE. [16] Kumar, M. S., Ben-Othman, J., & Srinivasagan, K. G. (2018, June). An investigation on wannacry ransomware and its detection. In 2018 IEEE Symposium on Computers and Communications (ISCC) (pp. 1-6). IEEE. [17] Hsiao, S. C., & Kao, D. Y. (2018, February). The static analysis of WannaCry ransomware. In 2018 20th international conference on advanced communication technology (ICACT) (pp. 153-158). IEEE. [18] Wierman, J. C. (2004). A Susceptible-Infected-Susceptible Model with Reintroduction for Computer Virus Epidemics. In Statistical Methods in Computer Security (pp. 181-192). CRC Press. [19] Kharabsheh, M., Al-aiash, I., Mughaid, A., & Almiani, M. (2024, September). The seir model for predicting malware propagation in computer networks. In 2024 International Conference on Intelligent Computing, Communication, Networking and Services (ICCNS) (pp. 108-113). IEEE.

13

S. Hossain and K. Wilson [20] Zhang, Y., & Liu, J. (2019). Optimal Decision‐Making Approach for Cyber Security Defense Using Game Theory and Intelligent Learning. Security and Communication Networks, 2019(1), 3038586. [21] Awasthi, S., Srivastava, P. K., Kumar, N., Ojha, R. P., Pandey, P. S., Singh, R., ... & Bakare, Y. B. (2023). An epidemic model for the investigation of multi‐malware attack in wireless sensor network. IET Communications, 17(11), 1274-1287. [22] Quiroga-Sánchez, L., Montoya, G. A., & Lozano-Garzon, C. (2025). The SEIRS-NIMFA epidemiological model for malware propagation analysis in IoT networks: L. Quiroga-Sánchez et al. Cybersecurity, 8(1), 2. [23] Ghosh, S., & Kumar, V. A. (2026). Internet malware propagation: Dynamics and control through SEIRV epidemic model with relapse and intervention. arXiv preprint arXiv:2603.03712. [24] Kocabiyik, M. (2026). Modeling and Dynamical Analysis of Computer Worm Propagation using a New SEIRRe Model and its Application with the Hausdorff Fractal Derivative. New Mathematics and Natural Computation. [25] Quiroga-Sánchez, L., Montoya, G. A., & Lozano-Garzon, C. (2025). The SEIRS-NIMFA epidemiological model for malware propagation analysis in IoT networks: The SEIRS-NIMFA epidemiological...: L. Quiroga-Sánchez et al. Cybersecurity (2523-3246), 8(1). [26] Stiawan, D., Idris, M. Y., Malik, R. F., Nurmaini, S., Alsharif, N., & Budiarto, R. (2019). Investigating brute force attack patterns in IoT network. Journal of Electrical and Computer Engineering, 2019(1), 4568368. [27] Knudsen, L. R., & Robshaw, M. J. (2011). Brute force attacks. In The Block Cipher Companion (pp. 95-108). Berlin, Heidelberg: Springer Berlin Heidelberg. [28] Waheed, A., Seegolam, B., Jowaheer, M. F., Sze, C. L. X., Hua, E. T. F., & Sindiramutty, S. R. (2024). Zero-day exploits in cybersecurity: Case studies and countermeasure. [29] Seri, B., & Vishnepolsky, G. (2017). The dangers of Bluetooth implementations: Unveiling zero day vulnerabilities and security flaws in modern Bluetooth stacks. ArmisLabs: Palo Alto, CA, USA, 1-38.

Record · ID 321791 · SHA-256 b38519aabc02c861
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.