Security defense tools like firewalls and antivirus softwares are not sufficient to defend against dynamic threats to database systems. Successful attacks could not only seriously impair the integrity of a database but also potentially harm the business operation, assets, and profitability. A better understanding of the attack behavior and its degree of spreading is needed. In this paper, we provide a careful analysis of threats to database security and their propagation in a database system. Based on the classical Susceptible-Infected-Susceptible (SIS) epidemic model, a stochastic damage propagation model is proposed. This model leads to a better understanding and prediction of the scale and speed of damage propagation in a database system. The parameters in this model are calculated from real values, such as average transaction arrival rate and database size. This makes the model easy to be adopted to different database applications. Instead of applying models to calculate the number...