IoMT-SAF: Internet of Medical Things Security Assessment Framework

IoMT-SAF: Internet of Medical Things Security Assessment Framework
复制标题

DOI:
10.1016/j.iot.2019.100123
复制
发表时间:
2019-12-01
期刊:
影响因子:
5.9
通讯作者:
Shiva, Sajjan
Shiva, Sajjan
中科院分区:
计算机科学3区
文献类型:
--
作者:
Alsubaei, Faisal;Abuhussein, Abdullah;Shiva, Sajjan

文献摘要

被引文献

相似文献

医疗物联网(IoMT)的出现在促进疾病管理,改善疾病诊断和治疗方法,减少医疗成本和错误方面带来了巨大的变化。这一变化极大地影响了患者和所有一线医护人员的医疗质量。然而,由于市场上有各种各样的IoMT供应商和产品,以及大量将敏感医疗数据无线传输到云端的设备,IoMT远不能免受安全和隐私漏洞的影响。医疗保健用户缺乏安全意识(例如,病人、医务人员)的缺陷,并可能助长危及病人生命的攻击。因此,确保物联网的安全性和隐私性成为一个值得进一步研究和解决的紧迫问题。如果安全性无法衡量,就无法对其进行规划、管理、监控或控制。然而,安全评估在选择足够和强大的安全措施时给IoMT新手带来了问题。因此,我们开发了一个基于Web的IoMT安全评估框架(IoMT-SAF),该框架基于一种新颖的基于本体论的方法来推荐IoMT中的安全功能,并评估IoMT解决方案中的保护和威慑。IoMT-SAF支持选择与利益相关者的安全目标相匹配的解决方案,并支持决策过程。IoMT-SAF的新奇在于其粒度、可扩展性以及适应新利益相关者的能力,并符合技术和医疗标准。(C)2019爱思唯尔B. V.保留所有权利。
The emergence of the Internet of Medical Things (IoMT) has introduced a monumental change in facilitating the management of diseases, improving diseases diagnosis and treatment methods, and reducing healthcare cost and errors. This change has greatly impacted the quality of healthcare for both patients and all frontline healthcare workers. However, the IoMT is far from being immune to security and privacy breaches due to the wide variety IoMT vendors and products available on the market as well as the massive number of devices transmitting sensitive medical data wirelessly to the cloud. The lack of security awareness among healthcare users (e.g., patients, medical staff) aggravates the deficiencies and can facilitate attacks that jeopardize the patients' lives. Therefore, ensuring the security and privacy of the IoMT becomes an urgent issue worthy of further investigation and resolution. Security cannot be planned for, managed, monitored, or controlled if it cannot be measured. However, security assessment poses problems for novice IoMT adopters when choosing security measures that are both sufficient and robust. Accordingly, we developed a web-based IoMT Security Assessment Framework (IoMT-SAF) based on a novel ontological scenario-based approach to recommend security features in IoMT and assess protection and deterrence in IoMT solutions. IoMT-SAF supports the selection of a solution that matches the stakeholder's security objectives and supports the decision-making process. The novelty of IoMT-SAF lies in its granularity, extensibility, as well as its ability to adapt to new stakeholders, and conformance to technology and medical standards. (C) 2019 Elsevier B.V. All rights reserved.