Cargando…

Artificial Intelligence–Based Ethical Hacking for Health Information Systems: Simulation Study

BACKGROUND: Health information systems (HISs) are continuously targeted by hackers, who aim to bring down critical health infrastructure. This study was motivated by recent attacks on health care organizations that have resulted in the compromise of sensitive data held in HISs. Existing research on...

Descripción completa

Detalles Bibliográficos
Autores principales: He, Ying, Zamani, Efpraxia, Yevseyeva, Iryna, Luo, Cunjin
Formato: Online Artículo Texto
Lenguaje:English
Publicado: JMIR Publications 2023
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC10170356/
https://www.ncbi.nlm.nih.gov/pubmed/37097723
http://dx.doi.org/10.2196/41748
_version_ 1785039210096361472
author He, Ying
Zamani, Efpraxia
Yevseyeva, Iryna
Luo, Cunjin
author_facet He, Ying
Zamani, Efpraxia
Yevseyeva, Iryna
Luo, Cunjin
author_sort He, Ying
collection PubMed
description BACKGROUND: Health information systems (HISs) are continuously targeted by hackers, who aim to bring down critical health infrastructure. This study was motivated by recent attacks on health care organizations that have resulted in the compromise of sensitive data held in HISs. Existing research on cybersecurity in the health care domain places an imbalanced focus on protecting medical devices and data. There is a lack of a systematic way to investigate how attackers may breach an HIS and access health care records. OBJECTIVE: This study aimed to provide new insights into HIS cybersecurity protection. We propose a systematic, novel, and optimized (artificial intelligence–based) ethical hacking method tailored specifically for HISs, and we compared it with the traditional unoptimized ethical hacking method. This allows researchers and practitioners to identify the points and attack pathways of possible penetration attacks on the HIS more efficiently. METHODS: In this study, we propose a novel methodological approach to ethical hacking in HISs. We implemented ethical hacking using both optimized and unoptimized methods in an experimental setting. Specifically, we set up an HIS simulation environment by implementing the open-source electronic medical record (OpenEMR) system and followed the National Institute of Standards and Technology’s ethical hacking framework to launch the attacks. In the experiment, we launched 50 rounds of attacks using both unoptimized and optimized ethical hacking methods. RESULTS: Ethical hacking was successfully conducted using both optimized and unoptimized methods. The results show that the optimized ethical hacking method outperforms the unoptimized method in terms of average time used, the average success rate of exploit, the number of exploits launched, and the number of successful exploits. We were able to identify the successful attack paths and exploits that are related to remote code execution, cross-site request forgery, improper authentication, vulnerability in the Oracle Business Intelligence Publisher, an elevation of privilege vulnerability (in MediaTek), and remote access backdoor (in the web graphical user interface for the Linux Virtual Server). CONCLUSIONS: This research demonstrates systematic ethical hacking against an HIS using optimized and unoptimized methods, together with a set of penetration testing tools to identify exploits and combining them to perform ethical hacking. The findings contribute to the HIS literature, ethical hacking methodology, and mainstream artificial intelligence–based ethical hacking methods because they address some key weaknesses of these research fields. These findings also have great significance for the health care sector, as OpenEMR is widely adopted by health care organizations. Our findings offer novel insights for the protection of HISs and allow researchers to conduct further research in the HIS cybersecurity domain.
format Online
Article
Text
id pubmed-10170356
institution National Center for Biotechnology Information
language English
publishDate 2023
publisher JMIR Publications
record_format MEDLINE/PubMed
spelling pubmed-101703562023-05-11 Artificial Intelligence–Based Ethical Hacking for Health Information Systems: Simulation Study He, Ying Zamani, Efpraxia Yevseyeva, Iryna Luo, Cunjin J Med Internet Res Original Paper BACKGROUND: Health information systems (HISs) are continuously targeted by hackers, who aim to bring down critical health infrastructure. This study was motivated by recent attacks on health care organizations that have resulted in the compromise of sensitive data held in HISs. Existing research on cybersecurity in the health care domain places an imbalanced focus on protecting medical devices and data. There is a lack of a systematic way to investigate how attackers may breach an HIS and access health care records. OBJECTIVE: This study aimed to provide new insights into HIS cybersecurity protection. We propose a systematic, novel, and optimized (artificial intelligence–based) ethical hacking method tailored specifically for HISs, and we compared it with the traditional unoptimized ethical hacking method. This allows researchers and practitioners to identify the points and attack pathways of possible penetration attacks on the HIS more efficiently. METHODS: In this study, we propose a novel methodological approach to ethical hacking in HISs. We implemented ethical hacking using both optimized and unoptimized methods in an experimental setting. Specifically, we set up an HIS simulation environment by implementing the open-source electronic medical record (OpenEMR) system and followed the National Institute of Standards and Technology’s ethical hacking framework to launch the attacks. In the experiment, we launched 50 rounds of attacks using both unoptimized and optimized ethical hacking methods. RESULTS: Ethical hacking was successfully conducted using both optimized and unoptimized methods. The results show that the optimized ethical hacking method outperforms the unoptimized method in terms of average time used, the average success rate of exploit, the number of exploits launched, and the number of successful exploits. We were able to identify the successful attack paths and exploits that are related to remote code execution, cross-site request forgery, improper authentication, vulnerability in the Oracle Business Intelligence Publisher, an elevation of privilege vulnerability (in MediaTek), and remote access backdoor (in the web graphical user interface for the Linux Virtual Server). CONCLUSIONS: This research demonstrates systematic ethical hacking against an HIS using optimized and unoptimized methods, together with a set of penetration testing tools to identify exploits and combining them to perform ethical hacking. The findings contribute to the HIS literature, ethical hacking methodology, and mainstream artificial intelligence–based ethical hacking methods because they address some key weaknesses of these research fields. These findings also have great significance for the health care sector, as OpenEMR is widely adopted by health care organizations. Our findings offer novel insights for the protection of HISs and allow researchers to conduct further research in the HIS cybersecurity domain. JMIR Publications 2023-04-25 /pmc/articles/PMC10170356/ /pubmed/37097723 http://dx.doi.org/10.2196/41748 Text en ©Ying He, Efpraxia Zamani, Iryna Yevseyeva, Cunjin Luo. Originally published in the Journal of Medical Internet Research (https://www.jmir.org), 25.04.2023. https://creativecommons.org/licenses/by/4.0/This is an open-access article distributed under the terms of the Creative Commons Attribution License (https://creativecommons.org/licenses/by/4.0/), which permits unrestricted use, distribution, and reproduction in any medium, provided the original work, first published in the Journal of Medical Internet Research, is properly cited. The complete bibliographic information, a link to the original publication on https://www.jmir.org/, as well as this copyright and license information must be included.
spellingShingle Original Paper
He, Ying
Zamani, Efpraxia
Yevseyeva, Iryna
Luo, Cunjin
Artificial Intelligence–Based Ethical Hacking for Health Information Systems: Simulation Study
title Artificial Intelligence–Based Ethical Hacking for Health Information Systems: Simulation Study
title_full Artificial Intelligence–Based Ethical Hacking for Health Information Systems: Simulation Study
title_fullStr Artificial Intelligence–Based Ethical Hacking for Health Information Systems: Simulation Study
title_full_unstemmed Artificial Intelligence–Based Ethical Hacking for Health Information Systems: Simulation Study
title_short Artificial Intelligence–Based Ethical Hacking for Health Information Systems: Simulation Study
title_sort artificial intelligence–based ethical hacking for health information systems: simulation study
topic Original Paper
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC10170356/
https://www.ncbi.nlm.nih.gov/pubmed/37097723
http://dx.doi.org/10.2196/41748
work_keys_str_mv AT heying artificialintelligencebasedethicalhackingforhealthinformationsystemssimulationstudy
AT zamaniefpraxia artificialintelligencebasedethicalhackingforhealthinformationsystemssimulationstudy
AT yevseyevairyna artificialintelligencebasedethicalhackingforhealthinformationsystemssimulationstudy
AT luocunjin artificialintelligencebasedethicalhackingforhealthinformationsystemssimulationstudy