TWC: Medium: Digital Healthcare-Associated Infection: Measurement, Defense and Prevention in a Modern Digital Healthcare Ecosystem
TWC: Medium: Digital Healthcare-Associated Infection: Measurement, Defense and Prevention in a Modern Digital Healthcare Ecosystem
批准号:
1562485
负责人:
Patrick Traynor
金额:
$120.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-06-01 至 2022-09-30
中文摘要
随着最近的医疗立法鼓励病历系统的互操作,医院系统的数字化和互联的步伐大大加快。除了普通的业务运营数据外,医院企业网络现在还传输来自治疗系统(例如,核医学、透析临床系统)的患者记录数据和生命关键数据流。不幸的是,这种至关重要的系统相互连接的安全影响在很大程度上还没有得到研究。该项目正在对佛罗里达大学卫生系统进行大规模分析,以检测恶意软件和安全漏洞的存在,并确定安全最佳实践和技术是否足以保护生命关键和隐私敏感的医疗系统。虽然最近的多项研究表明,单个医疗设备容易受到攻击,但没有一项评估跨医疗组织的当前规模的安全状态。该项目正在对佛罗里达大学卫生系统的当前安全态势进行大规模分析,以提供数据驱动的漏洞缓解方法。研究人员首先通过基于网络的恶意软件存在测量(通过域名系统(DNS)解析)和使用适当的加密做法(通过检查X.509证书)来表征系统的安全态势。该项目的下一步是开发动态指纹和限制危险通信模式的技术,并向通信流中注入强大的证书。最后,该项目正在开发预测处于风险中的设备的技术,使用通过接触图检测异常通信模式的算法。
英文摘要
The pace of digitization and interconnection of hospital systems has increased tremendously as recent healthcare legislation has encouraged the interoperation of medical record systems. In addition to ordinary business operations data, hospital enterprise networks now carry patient record data and life-critical data streams from therapy systems (e.g., nuclear medicine, dialysis clinical systems). Unfortunately, the security implications of interconnecting such life-critical systems has been largely unstudied. This project is performing a large-scale analysis of the University of Florida Health System to detect the presence of malware and security weaknesses and determine whether security best-practices and techniques are sufficient to protect life-critical and privacy-sensitive medical systems.While multiple recent studies have shown that individual medical devices are vulnerable to attack, none have assessed the current state of security at scale across medical organizations. This project is conducting a large-scale analysis of the current security posture of the University of Florida Health System to inform a data-driven approach to vulnerability mitigation. The researchers are first characterizing the security posture of the system through network-based measurements of malware presence (via Domain Name System (DNS) resolutions) and use of proper encryption practices (via inspection of X.509 certificates). The project is next developing techniques to dynamically fingerprint and limit risky communications patterns and inject strong certificates into communication flows. Finally, the project is developing techniques to predict devices at risk using algorithms that detect abnormal communication patterns via contact graphs.
期刊论文(9)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1109/tnet.2019.2933868
发表时间:
2019-10-01
期刊:
IEEE-ACM TRANSACTIONS ON NETWORKING
影响因子:
3.7
作者:
[Yang, Tong, Zhang, Haowei, Li, Xiaoming]
通讯作者:
Li, Xiaoming
DOI:
10.1109/globecom38437.2019.9014022
发表时间:
2019-12
期刊:
2019 IEEE Global Communications Conference (GLOBECOM)
影响因子:
--
作者:
[Olufemi O. Odegbile;Shigang Chen;Youlin Zhang]
通讯作者:
Olufemi O. Odegbile;Shigang Chen;Youlin Zhang
DOI:
10.1145/3366699
发表时间:
2019-12
期刊:
Proceedings of the ACM on Measurement and Analysis of Computing Systems
影响因子:
--
作者:
[You Zhou;Youlin Zhang;Chaoyi Ma;Shigang Chen;Olufemi O. Odegbile]
通讯作者:
You Zhou;Youlin Zhang;Chaoyi Ma;Shigang Chen;Olufemi O. Odegbile
DOI:
10.1109/infocom.2018.8485804
发表时间:
2018-04
期刊:
IEEE INFOCOM 2018 - IEEE Conference on Computer Communications
影响因子:
--
作者:
[You Zhou;Yian Zhou;Shigang Chen;Youlin Zhang]
通讯作者:
You Zhou;Yian Zhou;Shigang Chen;Youlin Zhang
DOI:
10.1109/infocom41043.2020.9155525
发表时间:
2020-07
期刊:
IEEE INFOCOM 2020 - IEEE Conference on Computer Communications
影响因子:
--
作者:
[Yu-E. Sun;He Huang;Chaoyi Ma;Shigang Chen;Yang Du;Qingjun Xiao]
通讯作者:
Yu-E. Sun;He Huang;Chaoyi Ma;Shigang Chen;Yang Du;Qingjun Xiao
共 7 条
SaTC: CORE: Medium: Securing the Voice Processing Pipeline Against Adversarial Audio
-
批准号:1933208
-
项目类别:Standard Grant
-
资助金额:$120.0万
-
财政年份:2019
-
负责人:Patrick Traynor
-
依托单位:
Workshop: Addressing the Technical Security Challenges of Emerging Digital Financial Services
-
批准号:1745573
-
项目类别:Standard Grant
-
资助金额:$5.0万
-
财政年份:2017
-
负责人:Patrick Traynor
-
依托单位:
WiFIUS: Collaborative Research: SELIOT: Securing Lifecycle of Internet-of-Things
-
批准号:1702879
-
项目类别:Standard Grant
-
资助金额:$15.0万
-
财政年份:2017
-
负责人:Patrick Traynor
-
依托单位:
TWC: Small: Designing Strong End-to-End Authentication Mechanisms for Modern Telephony Systems
-
批准号:1617474
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2016
-
负责人:Patrick Traynor
-
依托单位:
TWC: Small: Evaluating and Improving Security in Emerging Branchless Banking Systems
-
批准号:1526718
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2015
-
负责人:Patrick Traynor
-
依托单位:
CAREER: Protecting User Data on Lost, Stolen and Damaged Mobile Phones
-
批准号:1464088
-
项目类别:Continuing Grant
-
资助金额:$16.75万
-
财政年份:2014
-
负责人:Patrick Traynor
-
依托单位:
TWC: Small: Collaborative: Characterizing the Security Limitations of Accessing the Mobile Web
-
批准号:1464087
-
项目类别:Standard Grant
-
资助金额:$13.93万
-
财政年份:2014
-
负责人:Patrick Traynor
-
依托单位:
TWC: Small: Collaborative: Characterizing the Security Limitations of Accessing the Mobile Web
-
批准号:1222699
-
项目类别:Standard Grant
-
资助金额:$16.7万
-
财政年份:2012
-
负责人:Patrick Traynor
-
依托单位:
CAREER: Protecting User Data on Lost, Stolen and Damaged Mobile Phones
-
批准号:0952959
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2010
-
负责人:Patrick Traynor
-
依托单位:
TC: Small: Provably Anonymous Networking Through Secure Function Evaluation
-
批准号:0916031
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2009
-
负责人:Patrick Traynor
-
依托单位:
TC: Small: Characterizing and Mitigating Device-Based Attacks in Cellular Telecommunications Networks
-
批准号:0916047
-
项目类别:Standard Grant
-
资助金额:$45.0万
-
财政年份:2009
-
负责人:Patrick Traynor
-
依托单位:
海外基金