Verifying Graceful Degradation in a Distributed Malware-Detection System with SPIN
This study addresses the vulnerability of distributed malware detection systems to endpoint misclassification caused by server failures. To mitigate this, we construct a Promela model based on Bitdefender’s production architecture and formally verify its graceful degradation fallback chain mechanism using the SPIN model checker combined with Linear Temporal Logic (LTL). This work presents the first formal verification of the fault-handling layer within a production-grade security system, thereby bridging a significant research gap in the field. Experimental results demonstrate that the system is free from deadlocks and false positives while guaranteeing unique verdicts, ensuring that degradation behaviors remain orderly and controllable under failure conditions.