Computing Reviews
Today's Issue Hot Topics Search Browse Recommended My Account Log In
Review Help
Search
A multi-level grey evaluation model for harms of computer virus
Liu M., Han L., Peng B., Zheng C.  ISPAW 2011 (Proceedings of the 9th IEEE International Symposium on Parallel and Distributed Processing with Applications Workshops, Busan, Korea, May 26-28, 2011)21-26.2011.Type:Proceedings
Date Reviewed: Nov 9 2012

Ensuring antivirus security is a mission-critical task for enterprises in view of the increasing number of malicious attacks and their destructive potential. The authors of this paper focus on the problem of evaluating the potential harm caused by computer viruses.

The authors define a computer virus’ harm in terms of four criteria, each with multiple indexes:

  • Current infection scale, which includes four indexes: the number of infected independent sites, the number of general infected computers, the number of infected areas, and the number of infected trades.
  • Way of transmission, which includes indexes on transmission by file, by email, by local area network (LAN), by Internet, by system vulnerability, by system configuration defect, by social engineering, and by operation free from person.
  • Destructive behavior, which includes indexes on actions that delete/modify files, trigger events, block networks, actively and sustainably disseminate via network, paralyze systems, access sensitive information, reduce network performance, and modify system configuration, as well as other active attacks.
  • Self-complexity, which includes the following indexes: prevent computer from getting latest patch, utilizing new attack method, compound mode of transmission, and anti-clear.

The overall harm of the virus is calculated as a combination of all the indexes. Based on the calculated harm number, the virus is assigned a grade ranging from five (devastating) to one (slight). The paper presents a step-by-step description of the evaluation process. Experts use an analytical hierarchy process to assess the weight of each index. They also determine the score indexes for specific viruses. The proposed evaluation model was tested on a specific virus (Worm.WhBoy.h). The paper presents detailed quantitative results.

The paper will interest practitioners and researchers specializing in the evaluation of computer viruses, as well as those studying grey systems as a method to represent uncertainty. Although the authors note that many factors can or should be taken into consideration when evaluating the harm of a virus, they do not provide a rationale for the selection of the factors and indexes used in the proposed method. The authors’ claim that the proposed method is “more objective” is not sufficiently explained. A similar approach has been used for supplier evaluation [1].

Reviewer:  Alexei Botchkarev Review #: CR140661 (1302-0163)
1) Ni, S.; Xu, Q. The research on supplier selection based on grey relation decision-making method. In Proc. of the 2011 International Conference on Information Management, Innovation Management and Industrial Engineering IEEE, 2011, 243–246.
Bookmark and Share
 
Invasive Software (K.6.5 ... )
 
Would you recommend this review?
yes
no
Other reviews under "Invasive Software": Date
Rogue programs: viruses, worms and Trojan horses
Hoffman L. (ed) Van Nostrand Reinhold Co., New York, NY,1990. Type: Divisible Book
Sep 1 1991
Computer viruses and anti-virus warfare
Hruska J., Ellis Horwood, Upper Saddle River, NJ, 1990. Type: Book (9780131710672)
Sep 1 1991
The computer virus handbook
Levin R., Osborne/McGraw-Hill, Berkeley, CA, 1990. Type: Book (9780078816475)
Sep 1 1991
more...

E-Mail This Printer-Friendly
Send Your Comments
Contact Us
Reproduction in whole or in part without permission is prohibited.   Copyright 1999-2024 ThinkLoud®
Terms of Use
| Privacy Policy