SADI: Deciphering the Dynamics of Modern Social Worms in Hierarchical Networks
SADI: A Novel Model to Study the Propagation of Social Worms in Hierarchical Networks
This paper introduces SADI, a novel Susceptible-Active-Dormant-Immune model designed to simulate social worm propagation. It integrates two previously overlooked factors: message notification triggers and the temporal characteristics of human mobility within hierarchical network topologies.
TL;DR
The spread of social worms is no longer a simple matter of contact lists. The SADI (Susceptible-Active-Dormant-Immune) model bridges the gap between social logic and physical hardware. By accounting for the fact that one user operates multiple devices across different locations (Human Mobility) and responds to instant pings (Message Notification), SADI provides the most accurate mathematical framework to date for predicting large-scale cyber outbreaks.
The "One-to-One" Fallacy: Why Old Models Fail
Historically, researchers treated social networks as simple graphs where a node is both a "user" and a "computer." However, in our multi-device era, this is a dangerous oversimplification.
- Structural Imperfection: A single user might use a laptop at home, a desktop at work, and a public terminal at a library. This creates a "many-to-many" relationship.
- Temporal Blindness: Traditional models ignored when a user checks their messages. Modern apps "push" notifications, drastically shortening the time an infection stays dormant.
Methodology: The Hierarchical Approach
The authors propose a dual-layer architecture to solve the structural problem:
- Social Logical Layer: The "friend" network where trust is exploited.
- Actual Physical Layer: The specific hosts (IP addresses) in various locations.

The SADI Model uses a state-transition mechanism (Susceptible Active/Dormant Immune) guided by human mobility distributions (Power-law vs. Exponential). It calculates the infection probability by considering if a user is currently at a location and if they have received a notification trigger.
Mathematizing the Threshold
One of the paper's key theoretical contributions is refining the propagation threshold. While previous work relied on average connectivity , the authors prove that in hierarchical networks, the threshold is governed by the maximum eigenvalue of a propagation probability matrix: This revision proves that social worms are actually more virulent than previously thought because the underlying physical connectivity is denser than the logical social connectivity ().
Experimental Validation
Using data from the Nyxem Email worm outbreak, the authors compared SADI against several baselines, including the SII and Markov models.

Key Findings:
- Accuracy: SADI closely tracks real-world simulation curves, while other models result in a massive "infection gap" (the difference in the graph above).
- Human Factor: High "resting time" in one location can actually slow the total network spread, whereas frequent mobility accelerates it by acting as a "carrier" across different subnets.
- Notification Impact: Instant checking of messages (high ) significantly increases the speed of the initial outbreak, shrinking the window available for defenders to respond.
Critical Insight & Conclusion
The SADI model's superiority lies in its recognition of interdisciplinarity. Security is no longer just about software vulnerabilities; it is about human habits.
Takeaway for Security Architects: If you want to stop a worm, you can't just look at the social graph. You must understand the "sharing rate" of hardware and the "notification latency." SADI proves that by the time a user gets a "Ping," the physical network may already be compromised at a scale that logical-layer defenses cannot see.
Limitations
While mathematically robust, the model relies on mobility data (GPS/Resting time) which is increasingly difficult to obtain due to privacy regulations (GDPR/CCPA). Future work will likely need to integrate "privacy-preserving" data gathering to fuel these predictive models.
