Towards Autonomic Security Management of Healthcare Information Systems

被引:9
|
作者
Chen, Qian [1 ]
Lambright, Jonathan [1 ]
Abdelwahed, Sherif [2 ]
机构
[1] Savannah State Univ, Dept Engn Technol, Savannah, GA 31404 USA
[2] Mississippi State Univ, Dept Elect & Comp Engn, Mississippi State, MS 39762 USA
关键词
D O I
10.1109/CHASE.2016.58
中图分类号
R318 [生物医学工程];
学科分类号
0831 ;
摘要
With the fast development of information and communication technologies over the past decade, Healthcare Information Technology (HIT) has been widely implemented for health stakeholders to access, modify, share Electronic Health Records (EHR) with a low cost of the facility, data and application maintenance. Due to the high value of healthcare data and lack of investment in cyber security, vulnerabilities of Healthcare Information Systems (HISs), especially data of EHR systems are exposed to attackers [1], [2]. This paper first introduces the network structure of the HIS and the communication standards for health data transmission among patients, hospitals, pharmacies, and insurance companies. After that, we introduce the Health Level 7 (HL7) standard in details and discuss the current security challenges of HISs. We also illustrate how to simulate attacks that exploit HL7 message vulnerabilities. An Autonomic Security Management (ASM) approach is designed for proactively self-protecting a HIS from internal and external attacks. The performance of a HIS can be monitored in real time, and potential attacks that may disrupt HIS services are predicted by the intrusion estimation module. The functionality and feasibility of intrusion detection systems for detecting known and unknown cyber attacks threatening the confidentiality and integrity of EHRs are presented. The intrusion response system of the ASM approach selects the most appropriate protection mechanisms to recover the compromised HIS back to normal with little or no human intervention.
引用
收藏
页码:113 / 118
页数:6
相关论文
共 50 条
  • [1] Information Security Management Systems in the Healthcare Context
    Tyali, S.
    Pottas, D.
    [J]. PROCEEDINGS OF THE SOUTH AFRICAN INFORMATION SECURITY MULTI-CONFERENCE, 2010, : 177 - 187
  • [2] Towards Automation in Information Security Management Systems
    Brunner, Michael
    Sillaber, Christian
    Breu, Ruth
    [J]. 2017 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY AND SECURITY (QRS), 2017, : 160 - 167
  • [3] The EDITH approach: The management of authorisations and security in healthcare information systems
    Ferrara, FM
    [J]. TOWARDS SECURITY IN MEDICAL TELEMATICS: LEGAL AND TECHNICAL ASPECTS, 1996, 27 : 200 - 213
  • [4] Security in healthcare information systems
    Omogbadegun, Z. O.
    [J]. Information Processing in the Service of Mankind and Health, 2006, : 185 - 206
  • [5] Security and Autonomic Management in System of Systems
    Maksuti, Silia
    Zsilak, Mario
    Tauber, Markus
    Delsing, Jerker
    [J]. INFOCOMMUNICATIONS JOURNAL, 2021, 13 (03): : 66 - 75
  • [6] Towards a practical healthcare information security model for healthcare institutions
    Dwivedi, A
    Bali, RK
    Belsis, MA
    Naguib, RNG
    Every, P
    Nassar, NS
    [J]. ITAB 2003: 4TH INTERNATIONAL IEEE EMBS SPECIAL TOPIC CONFERENCE ON INFORMATION TECHNOLOGY APPLICATIONS IN BIOMEDICINE, CONFERENCE PROCEEDINGS: NEW SOLUTIONS FOR NEW CHALLENGES, 2003, : 114 - 117
  • [7] An overview in healthcare information systems security
    Bourka, A
    Polemi, N
    Koutsouris, D
    [J]. MEDINFO 2001: PROCEEDINGS OF THE 10TH WORLD CONGRESS ON MEDICAL INFORMATICS, PTS 1 AND 2, 2001, 84 : 1242 - 1246
  • [8] The Enhancement of Security in Healthcare Information Systems
    Chia-Hui Liu
    Yu-Fang Chung
    Tzer-Shyong Chen
    Sheng-De Wang
    [J]. Journal of Medical Systems, 2012, 36 : 1673 - 1688
  • [9] The Enhancement of Security in Healthcare Information Systems
    Liu, Chia-Hui
    Chung, Yu-Fang
    Chen, Tzer-Shyong
    Wang, Sheng-De
    [J]. JOURNAL OF MEDICAL SYSTEMS, 2012, 36 (03) : 1673 - 1688
  • [10] Towards knowledge management in autonomic systems
    Cofino, T
    Doganata, Y
    Drissi, Y
    Tong, F
    Kozakov, L
    Laker, M
    [J]. EIGHTH IEEE INTERNATIONAL SYMPOSIUM ON COMPUTERS AND COMMUNICATION, VOLS I AND II, PROCEEDINGS, 2003, : 789 - 794