The rapid diffusion of rumors in a large population may yield serious consequences. Debunking rumors by releasing clarifying messages is a common means of containing rumor spreading. In the process of rumor spreading, there exist time delays and saturated effects. This paper addresses the problem of debunking a rumor in the presence of four time delays and four saturated rates. First, a novel controlled rumor spreading model is advised. Thereby, the original problem is reduced to an optimal control model. The optimality system for the optimal control model is deduced. An iterative algorithm for solving the optimal control model is presented. The convergence and superiority of the algorithm are validated through computer experiments. The possibility of estimating some key factors in the optimal control model is explored. Finally, the robustness of the algorithm to the initial conditions, the time delays, and the decay indices, is corroborated through simulation experiments. This work contributes to effective rumor debunking.
Most previous computer virus propagation (CVP) models are smooth, meaning that their right-hand sides are continuously differentiable. However, recovery resources for compromised hosts are often limited, and the aggregate recovery rate may decrease once the number of bursting nodes exceeds a defense threshold. To describe this resource-constrained mechanism, this article proposes a nonsmooth susceptible–latent–bursting–susceptible (SLBS) model with a two-level recovery function and a Holling-II saturated infection rate. Well-posedness, positivity, and positive invariance of the feasible region are first proved. The basic reproduction number is derived by the next-generation matrix method, and its normalized sensitivity indices is provided. The virus-endemic equilibria are obtained by reducing the equilibrium equations to a strictly increasing scalar equation, with special attention to the threshold case at the nonsmooth switching surface. Local stability is established by piecewise linearization and explicit Routh–Hurwitz criteria. Finally, vector-graphic numerical simulations, convergence checks, and parameter robustness tests are reported. The results clarify how limited recovery capacity and saturated infection jointly affect hierarchical control of network viruses.
Advanced Persistent Threat (APT) presents a significant challenge to the cybersecurity of contemporary organizations. This challenge is further exacerbated when APT actors collaborate with malicious insiders. The involvement of the insider transforms a bilateral adversarial scenario into a triadic strategic interaction, introducing additional layers of complexity in modeling and defense planning. Effective defense against insider-facilitated APT necessitates a comprehensive treatment of two critical aspects: (i) the dynamic strategic interactions among the three players—the defender, the insider, and the APT actor—and (ii) the impact of these interactions on the evolving state of the intranet. However, both dimensions are insufficiently addressed in existing research. To bridge this gap, we first develop an expected state evolution model that captures the real-time influence of the dynamic strategies of the players on the expected compromise state of the intranet. Building upon this, we formulate a three-player differential game model that explicitly incorporates the dynamic interactions of all participants. The associated optimality system is derived and numerically solved using a proposed iterative algorithm. The proposed algorithm achieves a 27.5% improvement in the organization’s expected payoff compared to baseline permissible strategies. Subsequently, we analyze key properties of the proposed framework and empirically evaluate the cost-effectiveness of the resulting defense strategy. To the best of our knowledge, this work represents the first application of three-player differential game theory in the domain of cybersecurity, offering a novel approach to defending against insider-facilitated APT.
Cyber threats have evolved in complexity, aiming at a wide range of sectors using advanced methods and tools. This evolving threat landscape challenges existing cybersecurity frameworks, many of which lack the adaptability to counteract the complex tactics of sophisticated adversaries. Developing robust cyber defense strategies requires simulating dynamic interactions between attackers and defenders across high, moderate, and low-impact scenarios. The Flip-It cyber game serves as an intelligent framework for simulating these interactions, enabling the analysis of adaptive strategies in cybersecurity. This paper aims to address the problem of mitigating malware prevalence with full consideration of attack/defense capabilities in arbitrary network topologies. This paper proposes a sophisticated discrete-time epidemic model to characterize security state transitions over time for all three scenarios within the Flip-It game framework. On this basis, the original problem is modeled as a closed-loop control problem to seek the optimal containment strategy. Deep Reinforcement Learning (DRL) is then used to tackle the problem, generating efficient defense strategies that are well-adapted to changing cybersecurity environments. Numerical simulations based on small-world networks, scale-free networks, and router networks are then carried out to generate corresponding strategies. Additionally, we have evaluated the performance of the proposed method against the State-Of-The-Art (SOTA) in terms of attack/defense objective function, control actions, number of devices under the control of the attacker and defender, stability, execution time, and scalability. This comprehensive approach integrates epidemiological modeling, game theory, and advanced machine learning to effectively tackle the complexities of contemporary cybersecurity threats.
Computer virus propagation (CVP) models translate malware movement in a network into analyzable dynamical systems. Two features are especially important for modern networks: infected hosts may remain latent before a damaging burst, and infection efficiency is usually saturated by limited contacts, filtering, isolation, or response resources. This article develops a two-dimensional Caputo fractional susceptible–latent–bursting–susceptible (SLBS) CVP model in which the susceptible–latent and susceptible–bursting channels have different Holling type-II incidence functions. The fractional derivative represents memory effects in the propagation process, while the two incidence functions allow the latent and bursting stages to have separate transmission strengths and saturation levels. Non-negativity, boundedness, and well-posedness are established. The system is then used to derive the basic reproduction number, classify all endemic equilibria, and obtain local asymptotic stability criteria for the virus-free, latency-free burst-endemic, and latency–burst coexistence equilibria. Numerical simulations based on an Adams predictor–corrector scheme illustrate the theoretical thresholds and suggest global convergence in representative parameter regions. The results provide a stage-sensitive modeling tool for analyzing and designing targeted defense policies against computer virus outbreaks.
Despite notable advancements in applying epidemic models to cybersecurity, current approaches often underperform in practice. Research indicates that these models can produce substantial prediction errors due to challenges in parameter estimation, the complexity and heterogeneity of real-world networks, and limitations in accurately evaluating model performance against empirical data. Prior models frequently rely on generalized or static parameters, which can further exacerbate prediction inaccuracies, particularly when estimating infection spread in complex and heterogeneous network environments. Such inaccuracies limit their ability to support timely and effective threat response. To address this gap, this article presents a novel hybrid framework that integrates attack graphs with epidemic modeling. Attack graphs provide a structured representation of potential attack paths and interdependencies within a network, enabling the incorporation of real, context-aware values into the epidemic model. This integration enhances parameter accuracy and improves predictive capability. Experimental evaluations demonstrate that the proposed framework (PFW) achieves a 91.25% improvement in performance. More specifically, the results indicate that the average number of infected devices using the proposed method with an attack graph for multivulnerabilities is 5, while for single-vulnerability cases it is 18. In comparison, traditional epidemic models without attack graph integration result in an average of 70 infected devices. These findings highlight the effectiveness of our approach in minimizing infection spread under diverse vulnerability conditions. Overall, the results demonstrate the value of grounding epidemic models in realistic network conditions, thereby advancing adaptive threat modeling, proactive defense strategies, and informed decision-making. Our work bridges the gap between theoretical modeling and real-world application, offering a significant step toward practical epidemic-based approaches in cybersecurity.
While there has been considerable research into optimal control formulations for mitigating cyber threats, a significant gap persists between the theoretical and numerical insights derived from such research and the practical implementation of these optimal mitigation strategies in real-time scenarios. This paper introduces a multifaceted approach to enhance and optimize optimal control strategies by seamlessly integrating reinforcement learning (RL) algorithms with model predictive control (MPC) techniques for the purpose of malware propagation control. Optimal control is a critical aspect of various domains, ranging from industrial processes and robotics to epidemiological modeling and cybersecurity. The traditional approaches to optimal control, particularly open-loop strategies, have limitations in adapting to dynamic and uncertain environments. This paper addresses these limitations by proposing a novel roadmap that leverages RL algorithms to fine-tune and adapt MPC parameters within the context of malware propagation containment. In sum, this practical roadmap is anticipated to serve as a valuable resource for researchers and practitioners engaged in the development of cybersecurity solutions.
Time delay and nonlinear incidence functions have a significant effect on rumor-spreading. In this article, a rumor-spreading model with two unequal time delays and a saturation effect is proposed. The existence, uniqueness, and non-negativity of the solution to this model are shown. The basic reproduction number is determined. A criterion for the existence of a rumor-endemic equilibrium is derived. It is found that there is an interesting conditional forward bifurcation. As a consequence, a complex bifurcation phenomenon is exhibited. A collection of criteria for the asymptotic stability of the rumor-free equilibrium are outlined. In the absence of a time delay, a criterion for the local asymptotic stability of the rumor-endemic equilibrium is presented. In the presence of small time delays, a criterion for the local asymptotic stability of the rumor-endemic equilibrium is established by applying our recently developed technique. Finally, a rumor-spreading control problem is reduced to an optimal control model, which is tackled in the framework of optimal control theory. This work facilitates the understanding of the influence of time delays and the saturation effect on rumor-spreading.
Recent advancements in large language models (LLMs) have enabled the development of diverse applications through efficient fine-tuning and prompt engineering. With the increasing frequency of cyberattacks targeting computer networks and connected devices, the accurate and timely detection of emerging cyber threats has become more critical than ever. This paper proposes a deep neural framework that integrates large language model and variational autoencoder (VAE) for anomaly detection, that aid in detecting emerging cyberattacks. Further, the proposed framework explores three fusion mechanisms, combining the generic representations of LLMs with the data-specific representations of VAEs, and utilising a one-class support vector machine for anomaly detection. Evaluation on benchmark datasets and ablation study demonstrates the superiority of the proposed approach in improving the anomaly detection performance by achieving F1-scores greater than 0.95 across all benchmark datasets.
Time delays and saturation effects are critical elements describing complex rumor spreading behaviors. In this article, a rumor spreading model with three time delays and two saturation functions is proposed. The basic properties of the model are reported. The structure of the rumor-endemic equilibria is deduced. A criterion for the global asymptotic stability of the rumor-free equilibrium is derived. In the presence of very small delays, a criterion for the local asymptotic stability of a rumor-endemic equilibrium is provided. The influence of the delays and the saturation effects on the dynamics of the model is made clear through simulation experiments. In particular, it is found that (a) extended time delays lead to slower change in the number of spreaders or stiflers and (b) lifted saturation coefficients lead to slower change in the number of spreaders or stiflers. This work helps to deepen the understanding of complex rumor spreading phenomenon and develop effective rumor-containing schemes.
Cyber propaganda has become an increasingly sophisticated tool for manipulating public perception and discourse within online social networks (OSNs). The effectiveness of cyber propaganda is strongly influenced by the interplay between individual awareness and the underlying topology of OSNs that facilitates the spread of propaganda. However, existing interventions primarily focus on continuous control strategies, which may not be feasible in certain real-world scenarios. Therefore, effectively suppressing the spread of cyber propaganda while taking into account the above impact factors remains a challenging problem. In this study, we propose a methodology that combines the optimal impulse control (OIC) theory with a novel propagation model to address this problem. Our propagation model is the first to take into account the effects of the cognitive differences and interconnectivity of OSNs on the dynamics of cyber propaganda. By employing the OIC framework and our newly developed propagation model, we formulate an OIC problem. The goal is to find impulse strategies that optimally balance the cost of intervention against its effectiveness. Using the impulse maximum principle, we establish the necessary conditions for optimal impulse strategies and construct an algorithm to solve the OIC problem. Our numerical experiments, conducted on three distinct social networks, demonstrated that: 1) awareness levels play a crucial role in effectively suppressing the spread of cyber propaganda on OSNs; and 2) our impulse strategies are significantly superior to random strategies in terms of suppression effect, thereby evidencing their cost-effectiveness.
Understanding the effect of time delays on rumor spreading is of special importance to curbing the spread of rumors. This article proposes a rumor-spreading model with three identical time delays: a delay associated with the negative influence of a spreader on an exposed ignorant individual, a delay associated with the natural change from a spreader to a stifler, and a delay associated with the positive influence of a stifler on an exposed spreader. The basic reproduction number for the model is determined. A criterion for the existence of rumor-endemic equilibrium is provided. Interestingly, the model undergoes a conditional forward bifurcation. A collection of criteria for the asymptotic stability of the rumor-free equilibrium is derived. In the absence of a time delay, a criterion for the asymptotic stability of the rumor-endemic equilibrium is presented. By developing a novel technique for dealing with small time delays, a criterion for the asymptotic stability of the rumor-endemic equilibrium is established. Finally, the effect of some factors on the existence of rumor-endemic equilibrium is investigated. In particular, the effect of the time delay on rumor spreading is revealed. This work facilitates a deep understanding of the dynamics of rumor-spreading models with time delays.
Antivirus (patch) is one of the most powerful tools for defending against malware spread. Distributed patching is superior to its centralized counterpart in terms of significantly lower bandwidth requirement. Under the distributed patching mechanism, a novel malware propagation model with double delays and double saturation effects is proposed. The basic properties of the model are discussed. A pair of thresholds, i.e., the first threshold R0 and the second threshold R1, are determined. It is shown that (a) the model admits no malware-endemic equilibrium if R0≤1, (b) the model admits a unique patch-free malware-endemic equilibrium and admits no patch-endemic malware-endemic equilibrium if 1R1. A criterion for the global asymptotic stability of the malware-free equilibrium is given. A pair of criteria for the local asymptotic stability of the patch-free malware-endemic equilibrium are presented. A pair of criteria for the local asymptotic stability of the patch-endemic malware-endemic equilibrium are derived. Using cybersecurity terms, these theoretical outcomes have the following explanations: (a) In the case where the first threshold can be kept below unity, the malware can be eradicated through distributed patching. (b) In the case where the first threshold can only be kept between unity and the second threshold, the patches may fail completely, and the malware cannot be eradicated through distributed patching. (c) In the case where the first threshold cannot be kept below the second threshold, the patches may work permanently, but the malware cannot be eradicated through distributed patching. The influence of the delays and the saturation effects on malware propagation is examined experimentally. The relevant conclusions reveal the way the delays and saturation effects modulate these outcomes.
The epidemic modeling of computer virus propagation is identified as an effective approach to understanding the mechanism of virus spread. Fraction-order virus spread models exhibit remarkable advantages over their integer-order counterparts. Based on a type of bursting virus, a fractional computer virus propagation model with saturation effect is suggested. The basic properties of the model are discussed. The basic reproduction number of the model is determined. The virus–endemic equilibria of the model are determined. A criterion for the global asymptotic stability of the virus-free equilibrium is derived. For a pair of potential virus–endemic equilibria, criteria for the local asymptotic stability are presented. Some interesting properties of the model, ranging from the impact of the fractional order and the saturation index on virus spread to their coupling effect, are revealed through numerical simulations. This work helps gain a deep insight into the laws governing virus propagation.
Human beings are often considered the weakest link in cybersecurity. Social engineering attacks exploit this vulnerability, posing significant threats to the digital assets of organizations. A highly effective strategy to protect users from falling into traps set by attackers is to implement comprehensive security awareness training focused on social engineering. In this context, the organization needs to find a cost-effective policy of allocating the security awareness training cost. We refer to the problem of finding such a policy as the security awareness training (SAT) problem. This paper addresses the SAT problem. First, an opinion dynamics-based security awareness evolution model is introduced. On this basis, the SAT problem is reduced to an optimal control model (the SAT model). Second, by deriving the optimality system for the SAT problem, an algorithm of solving the SAT model is proposed. Next, the feasibility of the proposed algorithm is validated through numerical experiments. Additionally, further exploration of the SAT algorithm are conducted. Finally, for greater versatility, the problem is formulated as a discrete-time problem (the discrete SAT problem), and the discrete SAT algorithm is proposed to solve it. This work takes the first step toward the prevention of social engineering attack through optimal control approach.
Social engineering malware, which exploits both technical and human vulnerabilities, presents challenging for individuals and organizations. However, existing studies typically focus on either technical or human vulnerabilities through case studies or questionnaires, ignoring their combined importance in mitigating such threats. This study pioneers the introduction of a mathematical model to analyze and mitigate the dynamics associated with these combined vulnerabilities. To achieve this, this study proposes an innovative framework, which integrates (a) a coupled malware-opinion dynamics model to capture the interplay between both types of vulnerabilities, and (b) an optimal impulse control approach to strategically mitigating social engineering malware. Within this framework, we define an optimization problem, aimed at balancing control costs and malware severity. We derive theoretical conditions for optimal impulse strategies that achieve this balance and develop an iterative algorithm, the convergence and scalability of which have been empirically validated. Experimental results on three real-world social networks and synthetic scale-free networks demonstrate that our strategies consistently achieve an optimal balance by minimizing total expenses, including control costs and losses associated with malware. This finding underscores the effectiveness of routine patching and ongoing security awareness training in standard cybersecurity practices. Further experiments indicate that the strategic, early, and frequent deployment of patches in specific scenarios can effectively reduce unnecessary losses, enhancing overall cybersecurity resilience.
Knowledge sharing is critical for an organization to acquire sustained competitive advantage. Bestowing monetary rewards may possibly the most direct method of stimulating online knowledge sharing. Under the monetary reward mechanism for promoting knowledge sharing, we intend to find a satisfactory knowledge-sharing promotion policy. First, based on a state evolutionary model for the knowledge-sharing community, we reduce the original problem to an optimal control model. Second, applying optimal control theory to the model, we give an algorithm for solving the model. Next, we validate the feasibility of the algorithm. Finally, we inspect the applicability of the algorithm. To our knowledge, this is the first time the optimal control modeling technique is applied to the research of knowledge sharing.
The lag of antivirus (AV) software development relative to malware development makes it necessary to constantly release AV patches. In practice, an AV patch can be deployed on an organization's intranet only when it passes compatibility test. In this context, a subset of hosts may be assigned to perform the test. The function of the fraction of the assigned hosts with respect to time is referred to as an AV patch testing (AVPT) policy, and the problem of finding a satisfactory AVPT policy in terms of the cost benefit is referred to as the AVPT problem. This paper addresses the AVPT problem through optimal control modeling. A new mathematical model of characterizing the evolution of the intranet's expected state is introduced by incorporating the effect of AV patch testing. On this basis, the AVPT problem is modeled as an optimal control problem (the AVPT model). By applying the Pontryagin Maximum Principle to this model, an iterative algorithm of solving the model is presented. The usability of the algorithm, including its convergence and effectiveness, is validated. Finally, the effect of a pair of controllable factors is inspected. This work initiates the study of patch testing-related issues through optimal control modeling.
In this paper, we introduce the concept of “social activity” to describe individual behavior on social networks, acknowledging its potential impact on rumor propagation within complex networks. With this in mind, we develop a dynamic model of rumor propagation based on social behavior and analyze the influence of various parameters on the scale of rumors through static comparison. Using this model, we investigate an optimal solution that balances costs and benefits. Numerical simulations and comparative experiments demonstrate the practical value of these findings for strategies aimed at suppressing rumors.
The rapid proliferation of Internet of Things (IoT) devices in recent years has resulted in a significant surge in the number of cyber-attacks targeting these devices. Recent data indicates that the number of such attacks has increased by over 100 percent, highlighting the urgent need for robust cybersecurity measures to mitigate these threats. In addition, a cyber-attack will begin to spread malware across the network once it has successfully compromised an IoT network. However, to mitigate this attack, a new patch must be applied immediately. In reality, the time required to prepare and apply the new patch can vary significantly depending on the nature of the cyber-attack. In this paper, we address the issue of how to mitigate cyber-attacks before the new patch is applied by formulating an optimal control strategy that reduces the impact of malware propagation and minimise the number of infected devices across IoT networks in the smart home. A novel node-based epidemiological model susceptible, infected high, infected low, recover first, and recover complete(SI_HI_LR_FR_C) is established with immediate response state for the restricted environment. After that, the impact of malware on IoT devices using both high and low infected rates will be analyzed. Finally, to illustrate the main results, several numerical analyses are carried out in addition to simulate the real-world scenario of IoT networks in the smart home, we built a dataset to be used in the experiments.