• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

开发一个开源、用户友好、符合 OWASP 标准的医疗保健 Web 应用程序测试架构。

Developing an Open-Source, User-Friendly, OWASP-Compliant Architecture for Healthcare Web Application Testing.

机构信息

Department of Informatics, Bioengineering, Robotics and System Engineering (DIBRIS), University of Genoa, Genoa, Italy.

Departament d'Arquitectura de Computadors (DAC), Universitat Politècnica de Catalunya - BarcelonaTech (UPC), Spain.

出版信息

Stud Health Technol Inform. 2024 Aug 22;316:1209-1213. doi: 10.3233/SHTI240628.

DOI:10.3233/SHTI240628
PMID:39176598
Abstract

Nowadays, web applications are fundamental in the healthcare sector. However, with the widespread use of this technology, risks related to cybersecurity attacks also increase. To mitigate this phenomenon, every 3-4 years, the nonprofit foundation Open Worldwide Application Security Project (OWASP) compiles a top 10 ranking of the most critical web application security risks. Along with the top 10 Web Application Security Risks, OWASP also provides the Web Security Testing Guide, which offers comprehensive guidelines for conducting security tests. This guide includes suggestions for specific tools to use when performing different tests, among other valuable insights. However, the use of these recommended tools can be costly and can require advanced technical skills and a deep understanding of security best practices and web technologies. In addition, since the OWASP work on web security is generic, it would be useful to restrict and adapt it to the healthcare area. This would help in reducing the overhead when dealing with the needed tools. The goal of this study is to make web application security assessment in healthcare more accessible by developing tools that simplify the process and makes it user- friendly. Before developing such tools, an in-depth feasibility study must be conducted to verify the existence of open-source libraries to carry out the necessary testing procedures. It will be also necessary to identify how tools could be simplified and enhanced when focusing on healthcare.

摘要

如今,网络应用在医疗保健领域至关重要。然而,随着这项技术的广泛应用,与网络安全攻击相关的风险也在增加。为了减轻这种现象,非营利组织 Open Worldwide Application Security Project (OWASP) 每 3-4 年就会编制一份最关键的网络应用安全风险前 10 名排名。除了前 10 名的 Web 应用程序安全风险外,OWASP 还提供了 Web 安全测试指南,其中包含了进行安全测试的全面指南。该指南包括在执行不同测试时使用特定工具的建议,以及其他有价值的见解。然而,这些推荐工具的使用可能会很昂贵,并且需要先进的技术技能和对安全最佳实践和网络技术的深入理解。此外,由于 OWASP 的网络安全工作是通用的,将其限制并适用于医疗保健领域将很有用。这有助于减少在处理所需工具时的开销。本研究的目的是通过开发简化流程并使其用户友好的工具,使医疗保健领域的网络应用安全评估更易于实现。在开发此类工具之前,必须进行深入的可行性研究,以验证是否存在可用于执行必要测试程序的开源库。还需要确定如何在关注医疗保健时简化和增强工具。

相似文献

1
Developing an Open-Source, User-Friendly, OWASP-Compliant Architecture for Healthcare Web Application Testing.开发一个开源、用户友好、符合 OWASP 标准的医疗保健 Web 应用程序测试架构。
Stud Health Technol Inform. 2024 Aug 22;316:1209-1213. doi: 10.3233/SHTI240628.
2
Smart Home-based IoT for Real-time and Secure Remote Health Monitoring of Triage and Priority System using Body Sensors: Multi-driven Systematic Review.基于智能家居的物联网,利用身体传感器实现分诊和优先级系统的实时安全远程健康监测:多驱动系统评价。
J Med Syst. 2019 Jan 15;43(3):42. doi: 10.1007/s10916-019-1158-z.
3
Cybersecurity in Internet of Medical Vehicles: State-of-the-Art Analysis, Research Challenges and Future Perspectives.医疗车物联网的网络安全:现状分析、研究挑战与未来展望。
Sensors (Basel). 2023 Sep 27;23(19):8107. doi: 10.3390/s23198107.
4
Influence of Human Factors on Cyber Security within Healthcare Organisations: A Systematic Review.人为因素对医疗机构网络安全的影响:系统综述。
Sensors (Basel). 2021 Jul 28;21(15):5119. doi: 10.3390/s21155119.
5
Clinical software development for the Web: lessons learned from the BOADICEA project.临床软件开发的网络应用:从 BOADICEA 项目中获得的经验教训。
BMC Med Inform Decis Mak. 2012 Apr 10;12:30. doi: 10.1186/1472-6947-12-30.
6
Enhancing Security of Web-Based IoT Services via XSS Vulnerability Detection.通过跨站脚本攻击漏洞检测增强基于Web的物联网服务安全性
Sensors (Basel). 2023 Nov 25;23(23):9407. doi: 10.3390/s23239407.
7
Hash and Physical Unclonable Function (PUF)-Based Mutual Authentication Mechanism.基于哈希和物理不可克隆函数(PUF)的相互认证机制。
Sensors (Basel). 2023 Jul 11;23(14):6307. doi: 10.3390/s23146307.
8
[Standard technical specifications for methacholine chloride (Methacholine) bronchial challenge test (2023)].[氯化乙酰甲胆碱支气管激发试验标准技术规范(2023年)]
Zhonghua Jie He He Hu Xi Za Zhi. 2024 Feb 12;47(2):101-119. doi: 10.3760/cma.j.cn112147-20231019-00247.
9
Technical note: ShinyAnimalCV: open-source cloud-based web application for object detection, segmentation, and three-dimensional visualization of animals using computer vision.技术说明:ShinyAnimalCV:一个开源的基于云的网络应用程序,用于使用计算机视觉进行动物的目标检测、分割和三维可视化。
J Anim Sci. 2024 Jan 3;102. doi: 10.1093/jas/skad416.
10
Session management for web-based healthcare applications.基于网络的医疗保健应用程序的会话管理。
Proc AMIA Symp. 1999:999-1003.