首页> 外文会议>IEEE International Conference on Healthcare Informatics >Using Access Control to Mitigate Insider Threats to Healthcare Systems
【24h】

Using Access Control to Mitigate Insider Threats to Healthcare Systems

机译:使用访问控制缓解内部威胁对医疗保健系统的影响

获取原文

摘要

Rapid and reliable sharing of patient information across healthcare systems is a major technological factor in improving healthcare. Although such sharing would lower costs, applicable laws and regulations, e.g., HIPAA in the United States, impose security and privacy guarantees that necessitate appropriate access control mechanisms to protect healthcare data. Many currently used access control models in healthcare systems are inadequate, as demonstrated by the constant successful attacks on these systems. As protecting healthcare information and systems from malicious or inadvertent attacks by authorized insiders is crucial, this paper investigates insider threats and develops an approach to protect such information from unauthorized or improper use, disclosure, alteration, and destruction by healthcare personnel. A threat model is designed and constructed for access control in healthcare systems, and used to assess the effectiveness of common access control models such as Role-Based Access Control and Attribute-Based Access Control.
机译:跨医疗保健系统快速可靠地共享患者信息是改善医疗保健的主要技术因素。尽管这样的共享将降低成本,但是适用的法律和法规,例如美国的HIPAA,强加了安全性和隐私保证,这需要适当的访问控制机制来保护医疗数据。正如对这些系统不断成功的攻击所证明的那样,医疗保健系统中许多当前使用的访问控制模型是不够的。由于保护医疗保健信息和系统免受授权内部人的恶意或无意攻击至关重要,因此本文研究了内部威胁,并开发了一种方法来保护此类信息免遭医疗保健人员未经授权或不正当使用,披露,更改和破坏。威胁模型是为医疗保健系统中的访问控制而设计和构建的,用于评估常见访问控制模型(例如基于角色的访问控制和基于属性的访问控制)的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号