Intrusion Detection System for Healthcare Systems Using Medical and Network Data: A Comparison Study

Intrusion Detection System for Healthcare Systems Using Medical and Network Data: A Comparison Study
复制标题

DOI:
10.1109/access.2020.3000421
复制
发表时间:
2020-01-01
期刊:
影响因子:
3.9
通讯作者:
Jain, Raj
Jain, Raj
中科院分区:
计算机科学3区
文献类型:
--
作者:
Hady, Anar A.;Ghubaish, Ali;Jain, Raj

文献摘要

被引文献

相似文献

将物联网系统引入医疗保健应用程序使远程监控患者成为可能& x2019;在需要的时候提供适当的诊断。然而,提供高安全性功能,保证患者的正确性和保密性& x2019;数据是一个重大挑战。对数据的任何更改都可能影响患者& x2019;治疗,在紧急情况下导致人员伤亡。由于此类系统中涉及的数据具有高维性和突出的动态性,因此机器学习有望为入侵检测提供有效的解决方案。然而,大多数可用的医疗保健入侵检测系统要么使用网络流量指标,要么使用患者[x2019;生物特征数据来建立他们的数据集。本文旨在表明结合网络和生物特征作为特征比仅使用两种类型的特征中的一种表现更好。我们已经建立了一个实时增强医疗监控系统(EHMS)测试平台来监控患者& x2019;生物识别和收集网络流量指标。监测到的数据被发送到远程服务器,以便进行进一步的诊断和治疗决策。已经使用了中间人网络攻击,并创建了超过16,000条正常和攻击医疗保健数据记录的数据集。然后,系统应用不同的机器学习方法来训练和测试数据集以对抗这些攻击。结果表明,性能提高了7& x0025;至25& x0025;在某些情况下,这表明所提出的系统在提供适当的入侵检测方面具有鲁棒性。
Introducing IoT systems to healthcare applications has made it possible to remotely monitor patients& x2019; information and provide proper diagnostics whenever needed. However, providing high-security features that guarantee the correctness and confidentiality of patients& x2019; data is a significant challenge. Any alteration to the data could affect the patients& x2019; treatment, leading to human casualties in emergency conditions. Due to the high dimensionality and prominent dynamicity of the data involved in such systems, machine learning has the promise to provide an effective solution when it comes to intrusion detection. However, most of the available healthcare intrusion detection systems either use network flow metrics or patients& x2019; biometric data to build their datasets. This paper aims to show that combining both network and biometric metrics as features performs better than using only one of the two types of features. We have built a real-time Enhanced Healthcare Monitoring System (EHMS) testbed that monitors the patients& x2019; biometrics and collects network flow metrics. The monitored data is sent to a remote server for further diagnostic and treatment decisions. Man-in-the-middle cyber-attacks have been used, and a dataset of more than 16 thousand records of normal and attack healthcare data has been created. The system then applies different machine learning methods for training and testing the dataset against these attacks. Results prove that the performance has improved by 7& x0025; to 25& x0025; in some cases, and this shows the robustness of the proposed system in providing proper intrusion detection.