Computer Worm (SIR Epidemic Model) & Botnet C2 Jitter Simulator (2026)

Simulate network worm propagation dynamics (Morris, WannaCry SMBv1, SQL Slammer) using the differential SIR epidemiological model alongside C2 beacon jitter entropy and sinkhole containment.

Computer Worm (SIR Model) & Botnet C2 Jitter Simulator — Interactive Console
Runs locally in your browser • Instant output
Fleet Hosts (N)10,000
Worm Scan Rate (β)0.65
EDR Quarantine (γ)0.15
VLAN Micro-Segmentation
SIR Epidemic Propagation Curve (R₀ = 4.33 | Peak Infected = 4,482 hosts)
■ Susceptible (S)■ Infected (I)■ Patched/EDR Isolated (R)
Callback Window: [45s – 75s]
NDR Detection: 64% (MODERATE — Detectable via Histogram Skew)
Ready
Embed / Cite This Tool (Markdown & HTML)
GitHub / Reddit Markdown Badge[![Computer Worm (SIR Model) & Botnet C2 Jitter Simulator](https://img.shields.io/badge/ZerosUniverse-Free_Tool-ff6a00)](https://www.zerosuniverse.com/tools/worm-epidemic-botnet-propagation-simulator/)
Blog / Documentation HTML Citation<a href="https://www.zerosuniverse.com/tools/worm-epidemic-botnet-propagation-simulator/">Computer Worm (SIR Model) & Botnet C2 Jitter Simulator — ZerosUniverse</a>

2026 Quick-Reference Cheat Sheet & Benchmark Table: Computer Worm (SIR Model) & Botnet C2 Jitter Simulator

Quick Answer & 2026 Technical Summary (computer worm propagation simulator)Updated 2026 Standard

Originally developed by Kermack and McKendrick for biological epidemics, the SIR model divides a network of N hosts into three compartments: Susceptible (S: unpatched and reachable), Infectious (I: actively scanning and exploiting peers at rate β), and Removed/Recovered (R: patched, quarantined by EDR, or offline at rate γ). The coupled differential equations dS/dt = −βSI/N, dI/dt = βSI/N − γI, and dR/dt = γI accurately predict worm velocity. Use this interactive computer worm propagation simulator above to test sir epidemic model malware propagation, botnet c2 beacon jitter calculator, and basic reproduction number r0 cybersecurity locally in your browser with zero server uploads.

Target Keyword Spec: computer worm propagation simulator | Modules: Interactive SIR Epidemiological Differential Solver • Historical Outbreak Presets (Slammer, WannaCry, Conficker, Mirai) • Basic Reproduction Number (R0) & Herd Immunity Calculator
Primary Focus: computer worm propagation simulator
Core Capability: sir epidemic model malware propagation
Privacy Mode: 100% Client-Side (Zero Upload)
Technical Parameter / ModuleStandard / Keyword SpecArchitecture & Validation RuleOperational Use Case (2026)
Interactive SIR Epidemiological Differential Solversir epidemic model malware propagationSimulate Susceptible S(t), Infectious I(t), and Patched/Quarantined R(t) ho...SOC Incident Response & Network Segmentation Modeling
Historical Outbreak Presets (Slammer, WannaCry, Conficker, Mirai)botnet c2 beacon jitter calculatorLoad real-world propagation profiles for SQL Slammer (UDP 1434 random scann...Threat Hunting for C2 Beaconing in Firewall & Proxy Logs
Basic Reproduction Number (R0) & Herd Immunity Calculatorbasic reproduction number r0 cybersecurityCalculate exact cyber R0 = β / γ, critical pre-outbreak patch coverage thre...Cybersecurity Education & Malware Epidemiology Labs
Execution & Privacy Architecture100% Client-Side WebCrypto / JS Sandbox0 Bytes Sent to External ServersSafe for internal SOC & authorized lab artifacts
NIST SP 800-53 / OWASP AlignmentOWASP ASVS v4.0.3 / NIST CSF 2.0Deterministic Rule & Header VerificationMaps findings to actionable hardening controls
Cryptographic & Entropy StandardSHA-256 / AES-256-GCM / Argon2id≥ 128-bit Effective Security MarginMeets 2026 post-quantum & zero-trust baselines
In-Depth ZerosUniverse Tutorial

What is a Computer Worm & Botnet Architecture?

Read our complete step-by-step editorial guide, architecture breakdown, and defensive best practices on ZerosUniverse.

Read Full Guide

How to Use Computer Worm (SIR Model) & Botnet C2 Jitter Simulator

01

Select a Famous Worm Preset or Custom Network Topology

Pick SQL Slammer (2003), WannaCry (2017), Mirai IoT (2016), or customize Total Vulnerable Hosts (N), Scan/Infection Rate (β), and Patch/Isolation Rate (γ).

02

Adjust Pre-Outbreak Patching & Killswitch Containment

Slide the Initial Patch Coverage (%) and Emergency Sinkhole/Segmentation response time to observe how the S(t), I(t), and R(t) curves shift in real time.

03

Inspect R0, Peak Concurrent Infections & Time-to-Saturation

Review the calculated Basic Reproduction Number (R0), critical vaccination threshold, and maximum concurrent infected hosts.

04

Simulate Botnet C2 Sleep Jitter & NDR Detection Score

Configure C2 base callback interval (e.g., 60s) and jitter percentage (0%–50%) to view the inter-arrival histogram and RITA/Zeek periodicity detection score.

Key Capabilities & Technical Architecture

Interactive SIR Epidemiological Differential Solver

Simulate Susceptible S(t), Infectious I(t), and Patched/Quarantined R(t) host populations across 100 time steps with live SVG epidemic curves and peak infection telemetry.

Historical Outbreak Presets (Slammer, WannaCry, Conficker, Mirai)

Load real-world propagation profiles for SQL Slammer (UDP 1434 random scanning), WannaCry (EternalBlue SMBv1 + Killswitch), Mirai IoT Telnet, and Local Subnet worms.

Basic Reproduction Number (R0) & Herd Immunity Calculator

Calculate exact cyber R0 = β / γ, critical pre-outbreak patch coverage threshold (1 − 1/R0), doubling time, and network saturation bandwidth impact.

Botnet C2 Beacon Jitter & FFT Periodicity Detector

Model Command & Control callback sleep intervals with configurable jitter percentage (0%–50%) to see how NDR/SIEM periodicity algorithms detect fixed-interval beacons.

Practical Use Cases

SOC Incident Response & Network Segmentation Modeling

Demonstrate how micro-segmentation (reducing contact rate β) and automated EDR isolation (increasing removal rate γ) collapse R0 below 1.0 to halt lateral movement.

Threat Hunting for C2 Beaconing in Firewall & Proxy Logs

Understand how Cobalt Strike, Sliver, and botnet implants apply uniform or Gaussian sleep jitter to evade inter-arrival time standard deviation (σ/μ) anomaly detection.

Cybersecurity Education & Malware Epidemiology Labs

Visualize why UDP stateless scanning worms (SQL Slammer) double every 8.5 seconds compared to TCP three-way handshake worms (WannaCry, Conficker).

Frequently Asked Questions (FAQs)

How does the epidemiological SIR model apply to computer worms?+

Originally developed by Kermack and McKendrick for biological epidemics, the SIR model divides a network of N hosts into three compartments: Susceptible (S: unpatched and reachable), Infectious (I: actively scanning and exploiting peers at rate β), and Removed/Recovered (R: patched, quarantined by EDR, or offline at rate γ). The coupled differential equations dS/dt = −βSI/N, dI/dt = βSI/N − γI, and dR/dt = γI accurately predict worm velocity.

What does the Basic Reproduction Number (R0) mean in network security?+

In cybersecurity, R0 = (β / γ) × (1 − p) represents the average number of vulnerable machines a single infected host compromises before being isolated or patched. If R0 > 1, a worm triggers an exponential network-wide outbreak; if micro-segmentation and automated EDR containment push R0 < 1, the outbreak dies out organically.

Why did the 2003 SQL Slammer worm infect 75,000 hosts in under 10 minutes?+

SQL Slammer fit inside a single 376-byte UDP packet targeting MS SQL Server Resolution Service port 1434. Because UDP is connectionless, Slammer never waited for TCP SYN-ACK timeouts—it fired random IPv4 packets as fast as the NIC allowed, achieving an initial doubling time of 8.5 seconds.

How did Marcus Hutchins' DNS sinkhole stop WannaCry in 2017?+

Before running its EternalBlue SMBv1 propagation routine, WannaCry queried an unregistered hardcoded domain (`iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com`) as an anti-sandbox check. When that domain was registered and pointed to a sinkhole server returning HTTP 200, new infections immediately exited—instantaneously spiking the removal rate γ.

How do NDR tools like Zeek and RITA detect Botnet C2 beacons despite jitter?+

While a 20%–30% random sleep jitter defeats simple fixed-interval cron checks, Network Detection and Response (NDR) tools analyze 24-hour connection time series using Fast Fourier Transforms (FFT), skewness of inter-arrival times, and uniform payload byte-size consistency to flag persistent C2 channels.