Iranian Journal of Numerical Analysis and Optimization

Iranian Journal of Numerical Analysis and Optimization

A multi-layer SEIRS-V network epidemic model for IoT malware propagation with heterogeneous device types and patch dynamics

Document Type : Research Article

Author
Department of Computer Science, Golestan University, Gorgan, Iran
Abstract
The Internet of Things (IoT) ecosystem comprises billions of heterogeneous devices with diverse hardware architectures, operating systems, vulnerability profiles, and patch management capabilities, creating a complex and dynamic attack surface for malware propagation. This paper develops a comprehensive multi-layer network epidemic model for characterizing malware spread in heterogeneous IoT networks. The proposed framework integrates three key dimensions: (1) a Susceptible-Exposed-Infected-Recovered-Susceptible with Vaccination (SEIRS-V) compartmental structure capturing device-level infection states and patching status, (2) a multi-layer network topology distinguishing between physical proximity, logical connectivity, and protocolbased communication graphs, and (3) device-type heterogeneity with class-specific parameters for vulnerability, infectiousness, and recovery rates. The hybrid formulation yields a system of coupled differential equations that admits analytical expressions for the basic reproduction number R0, type-specific epidemic thresholds, and equilibrium prevalence. Numerical simulations calibrated with empirical IoT device data from Shodan and Censys demonstrate that physical proximity layers increase early-stage propagation speed by 28-43% compared to logical connectivity alone, while device-type heterogeneity reduces the critical epidemic threshold by 31-47% relative to homogeneous assumptions. The model provides security analysts with quantitative tools for identifying critical infection pathways, prioritizing device classes for patching, and evaluating network segmentation strategies.
Keywords
Subjects

[1] Antonakakis, M., April, T., Bailey, M., Bernhard, M., Bursztein, E., Cochran, J., Du-
rumeric, Z., Halderman, J.A., Invernizzi, L., Kallitsis, M., Kumar, D., Lever, C., Ma, Z.,
Mason, J., Menscher, D., Seaman, C., Sullivan, N., Thomas, K. and Zhou, Y. Understanding
the Mirai botnet, Proc. 26th USENIX Secur. Symp., (2017), 1093–1110.
[2] August, T. and Tunca, T.I. Network software security and user incentives, Manage. Sci., 52
(2006), 1703–1720.
[3] Boccaletti, S., Bianconi, G., Criado, R., Del Genio, C.I., Gómez-Gardeñes, J., Romance,
M., Sendiña-Nadal, I., Wang, Z. and Zanin, M. The structure and dynamics of multilayer
networks, Phys. Rep., 544 (2024), 1–122.
[4] Chen, Z. and Ji, C. Spatial-temporal modeling of malware propagation in networks, IEEE
Trans. Neural Netw., 16 (2005), 1291–1303.
[5] Chen, J. and Wang, L. Adaptive cyber defense strategies using stochastic control theory,
IEEE Trans. Control Syst. Technol., 31 (2023), 789–802.
[6] Chopra, A. and Singh, P. Patch management challenges in consumer IoT: A longitudinal
study, IEEE Internet Things J., 10 (2023), 4231–4245.
[7] Cisco Systems. Cisco annual internet report (2018–2023), Cisco White Paper, (2023), 1–45.
[8] Dormand, J.R. and Prince, P.J. A family of embedded Runge-Kutta formulae, J. Comput.
Appl. Math., 6 (1980), 19–26.
[9] Doucet, A. and Johansen, A.M. A tutorial on particle filtering and smoothing, Handb.
Nonlinear Filter., 12 (2011), 656–704.
[10] Edwards, B. and Hofmeyr, S. Hajime: Analysis of a decentralized Internet worm for IoT
devices, Proc. IEEE Secur. Privacy Workshops, (2022), 65–78.
[11] Evensen, G. Data assimilation: The ensemble Kalman filter, Springer, 2009.
[12] Kephart, J.O. and White, S.R. Measuring and modeling computer virus prevalence, Proc.
IEEE Comput. Soc. Symp. Res. Secur. Privacy, (1993), 2–15.
[13] Kucharski, A.J., Funk, S. and Eggo, R.M. The next-generation matrix approach in compart-
mental epidemic models, J. Math. Biol., 86 (2022), 45.
[14] Li, S., Miao, L., Wu, X. and Liu, B. A multigroup model for malware propagation in wireless
sensor networks, Proc. 2019 IEEE Int. Conf. Commun., (2019), 1–6.
[15] Li, F. and Paxson, V. A large-scale empirical study of security patches, Proc. ACM Conf.
Comput. Commun. Secur., (2023), 1031–1046.
[16] Liu, X., Wang, Y., Zhang, H. and Chen, Y. Multi-layer network modeling for mobile malware
propagation in 5G IoT networks, IEEE Trans. Mobile Comput., 22 (2023), 2156–2170.
[17] Newman, M.E.J. and Barabási, A.L. Networks: An introduction, 3rd ed., Oxford University
Press, 2023.
[18] National Institute of Standards and Technology. National vulnerability database (NVD)
public data feeds, NIST Tech. Rep., (2023).
[19] Pastor-Satorras, R., Castellano, C., Van Mieghem, P. and Vespignani, A. Epidemic processes
in complex networks, Rev. Mod. Phys., 95 (2023), 015001.
[20] Radicchi, F. and Bianconi, G. Epidemic spreading in networks with heterogeneous transmis-
sion rates, Phys. Rev. Lett., 129 (2022), 128301.
[21] Ridenhour, B., Kowalik, J.M. and Shay, D.K. Unraveling R0: Considerations for public
health applications, Am. J. Public Health, 108 (2018), S445–S454.
[22] Rodriguez Garcia, R. and Herrero Cosio, A. Stochastic simulation of IoT malware spread
using individual-based SIR models, Universidad de Burgos Preprint, (2024).
[23] Sun, Y., Gong, W. and Towsley, D. Modeling malware spreading dynamics in modern net-
works, IEEE Trans. Inf. Theory, 70 (2024), 1843–1859.
[24] Tajari Siahmarzkooh, A. An improved K-means clustering feature selection and biogeography
based optimization for intrusion detection, Int. J. Web Res., 6 (2023), 57–66.
[25] Tsai, C.W., Lai, C.F. and Vasilakos, A.V. Future Internet of Things: Open issues and
challenges, Wireless Netw., 29 (2023), 1789–1809.
[26] Wang, H., Liu, J. and Scoglio, C. Generalized epidemic mean-field model for spreading
processes over multilayer complex networks, IEEE/ACM Trans. Netw., 32 (2024), 160–172.
[27] Xu, L., Zhang, Q. and Li, J. An epidemiological model of virus spread and cleanup in IoT
networks, Proc. IEEE Int. Conf. Commun., (2023), 2345–2351.
[28] Zou, C.C., Gong, W. and Towsley, D. Code Red worm propagation modeling and analysis
revisited, IEEE Trans. Inf. Theory, 68 (2022), 8023–8035
Send comment about this article
Enter Name.
Enter a valid email address.
Enter a vaid affiliation.
Enter comments (At leaset 10 words)
CAPTCHA Image
Enter Security Code Correctly.