Application of Models from Epidemiology to Metrics for Computer Virus Risk
Joan L. Aron, Ronald A. Gove · 1998
One aspect of maintaining integrity in information systems is establishing an organizational environment that will prevent the damage caused by external agents. One particularly insidious such agent is the computer virus. It can alter data often without the owner or user of that data being aware. Establishing such an environment can often rely on the availability of metrics for organizational characteristics associated with harm to data integrity. This paper will focus on the development of organizational metrics for the threat of computer viruses. It is expected that many of these metrics will apply to other threats to data integrity although we have not pursued that line of research. In the case of computer viruses and some other types of malicious code, the formal analogies to the infection dynamics of biological viruses permit the utilization of epidemiological concepts in the development of metrics. This paper demonstrates how a simple epidemiological model of computer viruses provides insights about the importance of several metrics: