Decision support for healthcare cyber security

Decision support for healthcare cyber security
复制标题

DOI:
10.1016/j.cose.2022.102865
复制
发表时间:
2022-08
期刊:
Comput. Secur.
影响因子:
--
通讯作者:
Ferda Özdemir Sönmez;Christiana C. Hankin;P. Malacaria
Ferda Özdemir Sönmez;Christiana C. Hankin;P. Malacaria
中科院分区:
其他
文献类型:
--
作者:
Ferda Özdemir Sönmez;Christiana C. Hankin;P. Malacaria

文献摘要

被引文献

相似文献

疫情表明,医疗系统是攻击者的主要目标。寻找最佳的安全控制集是卫生组织的一个持续挑战,其中成本是一个主要考虑因素。本文的目的是展示一个医疗成本优化系统,以及一个案例研究的基础上,两个IT设置配置,已评估的医疗专家和IT专家。这些配置将有助于传达决策参数的复杂性,并演示CySecTool如何处理这一难题。在这项研究中,64种不同的安全控制措施与70个漏洞有关,这些漏洞可能发生在医院系统的任何级别,处理内部和外部攻击/风险。该研究还包括一个新的可视化方案,允许观察漏洞及其基于Microsoft STRIDE分类的子类别。
The pandemic has demonstrated that healthcare systems are prime targets for attackers. Finding an optimal security control set is a constant challenge for health organizations, where cost is a major consideration. The purpose of this paper is to demonstrate a healthcare cost optimization system as well as a case study based on two IT setup configurations that have been evaluated by medical experts as well as IT experts. These configurations would aid in conveying the complexity of the decision parameters and demonstrating how CySecTool handles this difficulty. In the study, 64 different security controls were linked to 70 vulnerabilities that could occur at any level of a hospital system dealing with both internal and external attacks/risks. The study also includes a novel visualization scheme that allows for the observation of vulnerabilities and also their subcategories based on Microsoft's STRIDE categorization.