Home▸Cybersecurity▸3D Network Intrusion Defense — Spread, Detection & Quarantine

🛰️ 3D Network Intrusion Defense — Spread, Detection & Quarantine

A 3D companion to the Cybersecurity Simulator: a live network topology built around a hardened core server, an intrusion that spreads node-to-node along real edges, and a monitoring layer that detects and quarantines infected nodes under the defense, attack, coverage and response-time settings you choose.

Cybersecurity3DModerate60 FPS📱 Mobile-adapted⇄ 2D version
3d-improved-advanced-cybersecurity-simulator ↗ Open standalone

🌐 A network, not a particle field

Topology

A hardened core server sits at the centre with 24 perimeter nodes placed on a Fibonacci sphere around it — five flagged as internet-facing gateways. Every perimeter node links to the core, plus two lateral links to its nearest neighbours, giving the intrusion more than one path to travel.

spread P(edge) = 0.10 · attack · wormBoost · hardening(target) · (1 − 0.75 · defense)
hardening(core) = 0.35, hardening(perimeter) = 1.0

Detection

Every infected node is re-rolled against the monitoring layer once per tick; the roll succeeds more often as monitoring coverage rises, moving the node into "detected" (amber) before it is isolated.

P(detect per tick) = 0.06 + 0.30 · monitoringCoverage
quarantine time = detection time + responseTime

Metrics

The HUD tracks how many nodes are compromised right now, how many have been quarantined, the detection rate (detected ÷ ever-infected), the mean time to detect, and a composite security score that falls as the breach and the quarantine count grow.

🎛️ What each control does

Defense strength

Scales down the spread probability on every edge — the strongest lever against an intrusion already inside the network.

Attack intensity

Raises the per-edge spread probability and shortens the gap between spontaneous new intrusion waves.

Monitoring coverage

Raises the chance an infected node is caught on any given tick — the main lever against dwell time.

Response time

The delay, in milliseconds, between a node being detected and actually being quarantined — a slow response lets a detected node keep spreading in the meantime.

❓ Frequently Asked Questions

1. Why does the core resist infection better than the other nodes?
It carries a 0.35× hardening multiplier on the incoming spread probability — modelling the extra layers of defense a real organisation puts around its most valuable server.
2. What's the difference between the three attack patterns?
Random probe seeds new intrusions at a random open gateway; Worm boosts the spread probability roughly 1.9× so the infection self-propagates aggressively; Targeted core tries to enter through the core itself whenever it's still safe.
3. Can a quarantined node be re-infected?
No — quarantine removes it from further spread rolls for the rest of the run; only Reset network clears it back to safe.
4. What does the security score measure?
A composite that starts at 100 and falls faster for every node currently infected than for every node already quarantined, so an unfolding breach costs more than its cleanup.
5. Why do detection and response time interact?
Detection only starts the clock — the node keeps its "detected" (not yet isolated) status, and can still infect neighbours, until the response-time delay elapses and it's quarantined.
⚙ Under the hood

3D network-security lab: a live topology of servers around a hardened core, an intrusion that spreads node-to-node, and a monitoring layer that detects and quarantines it, all driven by real defense/attack/coverage/response-time parameters rather than decorative sliders.

network securityintrusion detectionquarantinethreat propagationdefense in depth

3D · WebGL · Three.js r128 · 60 FPS target · runs fully client-side, no install

What did you find?

Add reproduction steps (optional)