Artificial Intelligence-Based Ethical Hacking for Health Information Systems: Simulation Study.

Artificial Intelligence-Based Ethical Hacking for Health Information Systems: Simulation Study.
复制标题

DOI:
10.2196/41748
复制
发表时间:
2023-04-25
影响因子:
7.4
通讯作者:
Luo, Cunjin
Luo, Cunjin
中科院分区:
医学2区
文献类型:
--
作者:
He, Ying;Zamani, Efpraxia;Yevseyeva, Iryna;Luo, Cunjin

文献摘要

参考文献

相似文献

卫生信息系统(HIS)不断成为黑客的目标,他们的目标是摧毁关键的卫生基础设施。这项研究的动机是最近对医疗保健组织的攻击,这些攻击导致HIS中的敏感数据受到损害。医疗保健领域的现有网络安全研究对保护医疗设备和数据的关注不平衡。缺乏系统的方法来调查攻击者如何破坏HIS并访问医疗保健记录。本研究旨在为HIS网络安全保护提供新的见解。我们提出了一个系统的,新颖的,和优化的(基于人工智能的)道德黑客方法专门为HIS量身定制,我们将其与传统的未优化的道德黑客方法进行了比较。这使得研究人员和从业人员能够更有效地识别HIS上可能的渗透攻击的点和攻击路径。在这项研究中,我们提出了一种新的方法论方法,在HIS的道德黑客。我们在实验环境中使用优化和未优化的方法实现了道德黑客。具体来说,我们通过实施开源电子病历(OpenEMR)系统建立了一个HIS模拟环境,并遵循美国国家标准与技术研究所的道德黑客框架来发动攻击。在实验中,我们使用未优化和优化的道德黑客方法发起了50轮攻击。使用优化和未优化的方法都成功地进行了道德黑客攻击。结果表明,优化后的道德黑客攻击方法在平均使用时间、平均攻击成功率、攻击次数和成功攻击次数等方面均优于未优化的方法。我们能够确定成功的攻击路径和漏洞利用,这些攻击与远程代码执行、跨站点请求伪造、不正确的身份验证、Oracle Business Intelligence Publisher中的漏洞、特权提升漏洞(在联发科中)和远程访问后门(在Linux虚拟服务器的Web图形用户界面中)有关。这项研究展示了使用优化和未优化的方法对HIS进行系统的道德黑客攻击,以及一套渗透测试工具来识别漏洞并将它们结合起来执行道德黑客攻击。这些发现有助于HIS文献,道德黑客方法和主流的基于人工智能的道德黑客方法,因为它们解决了这些研究领域的一些关键弱点。这些发现对医疗保健部门也具有重要意义,因为OpenEMR被医疗保健组织广泛采用。我们的研究结果为HIS的保护提供了新的见解,并允许研究人员在HIS网络安全领域进行进一步的研究。
Health information systems (HISs) are continuously targeted by hackers, who aim to bring down critical health infrastructure. This study was motivated by recent attacks on health care organizations that have resulted in the compromise of sensitive data held in HISs. Existing research on cybersecurity in the health care domain places an imbalanced focus on protecting medical devices and data. There is a lack of a systematic way to investigate how attackers may breach an HIS and access health care records. This study aimed to provide new insights into HIS cybersecurity protection. We propose a systematic, novel, and optimized (artificial intelligence–based) ethical hacking method tailored specifically for HISs, and we compared it with the traditional unoptimized ethical hacking method. This allows researchers and practitioners to identify the points and attack pathways of possible penetration attacks on the HIS more efficiently. In this study, we propose a novel methodological approach to ethical hacking in HISs. We implemented ethical hacking using both optimized and unoptimized methods in an experimental setting. Specifically, we set up an HIS simulation environment by implementing the open-source electronic medical record (OpenEMR) system and followed the National Institute of Standards and Technology’s ethical hacking framework to launch the attacks. In the experiment, we launched 50 rounds of attacks using both unoptimized and optimized ethical hacking methods. Ethical hacking was successfully conducted using both optimized and unoptimized methods. The results show that the optimized ethical hacking method outperforms the unoptimized method in terms of average time used, the average success rate of exploit, the number of exploits launched, and the number of successful exploits. We were able to identify the successful attack paths and exploits that are related to remote code execution, cross-site request forgery, improper authentication, vulnerability in the Oracle Business Intelligence Publisher, an elevation of privilege vulnerability (in MediaTek), and remote access backdoor (in the web graphical user interface for the Linux Virtual Server). This research demonstrates systematic ethical hacking against an HIS using optimized and unoptimized methods, together with a set of penetration testing tools to identify exploits and combining them to perform ethical hacking. The findings contribute to the HIS literature, ethical hacking methodology, and mainstream artificial intelligence–based ethical hacking methods because they address some key weaknesses of these research fields. These findings also have great significance for the health care sector, as OpenEMR is widely adopted by health care organizations. Our findings offer novel insights for the protection of HISs and allow researchers to conduct further research in the HIS cybersecurity domain.
DOI: 10.1109/3477.484436
发表时间: 1996-02-01
影响因子: --
作者:
Dorigo, M;Maniezzo, V;Colorni, A
通讯作者: Colorni, A
DOI: 10.1038/s41746-019-0161-6
发表时间: 2019-10-02
影响因子: 15.2
作者:
Ghafur, S.;Kristensen, S.;Aylin, P.
通讯作者: Aylin, P.
DOI: 10.1038/s41746-021-00424-5
发表时间: 2021-03-25
影响因子: 15.2
作者:
Gordon WJ;Coravos AR;Stern AD
通讯作者: Stern AD
DOI: 10.1177/1932296816677576
发表时间: 2017-03-01
影响因子: 5
作者:
Khera, Mandeep
通讯作者: Khera, Mandeep
COVID-19 气候下的医疗保健网络安全挑战和解决方案:范围界定审查
DOI: 10.2196/21747
发表时间: 2021-04-20
影响因子: 7.4
作者:
He Y;Aliyu A;Evans M;Luo C
通讯作者: Luo C