论文标题

减轻勒索软件攻击对医疗保健系统的影响

Mitigating the Effects of Ransomware Attacks on Healthcare Systems

论文作者

Gopinath, Sreejith, Olmsted, Aspen

论文摘要

医疗保健信息系统处理与患者有关的大量个人身份信息,例如出生和社会保险号,患者健康信息和历史以及信用卡详细信息和银行帐户等财务信息。大多数医疗机构从商业供应商那里购买信息系统,并且维护这些系统所需的内部专业知识最少。大多数机构缺乏研究不断发展的威胁并保持艰难的安全姿势所需的专业知识。我们提出了一个基于风险转移的系统体系结构,该系统体系结构将敏感数据移到系统边界之外,将其移入具有严格有效的安全性协议管理的数据存储。

Healthcare information systems deal with a large amount of Personally Identifiable Information related to patients like dates of birth and social security numbers, patients health information and history, and financial information like credit card details and bank accounts. Most healthcare institutions purchase information systems from commercial vendors and have minimal inhouse expertise required to maintain these systems. Most institutions lack the expertise required to research evolving threats and maintain a tough security posture. We propose a risk transference based system architecture that moves sensitive data outside the system boundary, into data stores that are managed with stringent and efficient security protocols.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源