首页> 外文OA文献 >Insider threat mitigation and access control in healthcare systems
【2h】

Insider threat mitigation and access control in healthcare systems

机译:医疗保健系统中的内部威胁缓解和访问控制

摘要

Rapid and reliable information sharing of patient healthcare information has become critical for achieving better care with lower costs. However, such healthcare information sharing requires to be done securely with privacy guarantees, as required by law. Among its other requirements, the Health Insurance Portability and Accountability Act (HIPAA) requires the use of appropriate access control mechanisms to protect healthcare information. Despite these legal requirements, currently implemented access control models in the healthcare domain are typically inadequate as demonstrated by the large and increasing numbers of successful attacks on healthcare systems. In particular, current access control models do not provide sufficient protection for healthcare systems from attacks by insiders, i.e., authorized healthcare personnel. This paper examines how healthcare information can be protected from unauthorized or improper use, disclosure, alteration, and destruction by health- care providers. Using a holistic approach toward modeling access control, the authors construct a threat model for access control in healthcare systems. The constructed model is then used to assess the effectiveness of current access control mechanisms such as Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC), as well as the BiLayer Access Control (BLAC) model, which was proposed as a flexible, higher-performance replacement for both RBAC and ABAC.
机译:快速,可靠地共享患者医疗信息的信息对于以更低的成本获得更好的医疗服务至关重要。但是,根据法律的要求,此类医疗保健信息共享需要在确保隐私的前提下安全进行。在其其他要求中,《健康保险可移植性和责任法案》(HIPAA)要求使用适当的访问控制机制来保护医疗保健信息。尽管有这些法律要求,但在医疗保健领域中当前实施的访问控制模型通常不足,如对医疗保健系统的大量成功攻击所证明的那样。特别地,当前的访问控制模型不能为医疗保健系统提供足够的保护,使其免受内部人员(即授权医疗保健人员)的攻击。本文研究了如何保护医疗保健信息,以防止医疗保健提供者未经授权或不正当使用,披露,更改和破坏医疗信息。使用整体方法对访问控制进行建模,作者构建了用于医疗保健系统中访问控制的威胁模型。然后,使用构建的模型来评估当前访问控制机制(例如基于角色的访问控制(RBAC)和基于属性的访问控制(ABAC))以及BiLayer访问控制(BLAC)模型的有效性。作为RBAC和ABAC的灵活,高性能替代品。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号