Department of Informatics, Bioengineering, Robotics and System Engineering (DIBRIS), University of Genoa, Genoa, Italy.
Departament d'Arquitectura de Computadors (DAC), Universitat Politècnica de Catalunya - BarcelonaTech (UPC), Spain.
Stud Health Technol Inform. 2024 Aug 22;316:1209-1213. doi: 10.3233/SHTI240628.
Nowadays, web applications are fundamental in the healthcare sector. However, with the widespread use of this technology, risks related to cybersecurity attacks also increase. To mitigate this phenomenon, every 3-4 years, the nonprofit foundation Open Worldwide Application Security Project (OWASP) compiles a top 10 ranking of the most critical web application security risks. Along with the top 10 Web Application Security Risks, OWASP also provides the Web Security Testing Guide, which offers comprehensive guidelines for conducting security tests. This guide includes suggestions for specific tools to use when performing different tests, among other valuable insights. However, the use of these recommended tools can be costly and can require advanced technical skills and a deep understanding of security best practices and web technologies. In addition, since the OWASP work on web security is generic, it would be useful to restrict and adapt it to the healthcare area. This would help in reducing the overhead when dealing with the needed tools. The goal of this study is to make web application security assessment in healthcare more accessible by developing tools that simplify the process and makes it user- friendly. Before developing such tools, an in-depth feasibility study must be conducted to verify the existence of open-source libraries to carry out the necessary testing procedures. It will be also necessary to identify how tools could be simplified and enhanced when focusing on healthcare.
如今,网络应用在医疗保健领域至关重要。然而,随着这项技术的广泛应用,与网络安全攻击相关的风险也在增加。为了减轻这种现象,非营利组织 Open Worldwide Application Security Project (OWASP) 每 3-4 年就会编制一份最关键的网络应用安全风险前 10 名排名。除了前 10 名的 Web 应用程序安全风险外,OWASP 还提供了 Web 安全测试指南,其中包含了进行安全测试的全面指南。该指南包括在执行不同测试时使用特定工具的建议,以及其他有价值的见解。然而,这些推荐工具的使用可能会很昂贵,并且需要先进的技术技能和对安全最佳实践和网络技术的深入理解。此外,由于 OWASP 的网络安全工作是通用的,将其限制并适用于医疗保健领域将很有用。这有助于减少在处理所需工具时的开销。本研究的目的是通过开发简化流程并使其用户友好的工具,使医疗保健领域的网络应用安全评估更易于实现。在开发此类工具之前,必须进行深入的可行性研究,以验证是否存在可用于执行必要测试程序的开源库。还需要确定如何在关注医疗保健时简化和增强工具。