TY - GEN
T1 - Threats and Risk on Using Digital Technologies for Remote Health Care Process
AU - Khatiwada, Pankaj
AU - Fauzi, M. Ali
AU - Yang, Bian
AU - Yeng, Prosper
AU - Lin, Jia Chun
AU - Sun, Luyi
N1 - Publisher Copyright:
© 2023 Owner/Author.
PY - 2023/10/24
Y1 - 2023/10/24
N2 - This paper provides a comprehensive exploration of the threats and risk associated with the use of digital technology for remote healthcare. Through our "DigiRemote"research project, we aim to find out the challenges and risks involved in scaling remote health care, with specific focus on its technical and security dimensions. The article delves into the use of digital technologies, including Bluetooth-enabled IoMT devices, for monitoring health metrics in remote care settings. Emphasis is placed on understanding the threats in the generation, storage, and transfer of health data. By, utilizing the STRIDE (Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, and Elevation of privilege) model, we identified major threats, which are visually represented via heatmaps and bar graphs for ease of analysis. The DREAD (Damage, Reproducibility, Exploitability, Affected Users, and Discoverability) model assists in quantifying these threats, categorizing them into distinct risk levels, with detailed description of each threat category. In addition, we also suggest countermeasures for the highest-risk threats. This article serves as a pivotal resource for healthcare organizations and security professionals, shedding light on the risks of remote healthcare and providing mitigation strategies for both the implementation and post-implementation stages.
AB - This paper provides a comprehensive exploration of the threats and risk associated with the use of digital technology for remote healthcare. Through our "DigiRemote"research project, we aim to find out the challenges and risks involved in scaling remote health care, with specific focus on its technical and security dimensions. The article delves into the use of digital technologies, including Bluetooth-enabled IoMT devices, for monitoring health metrics in remote care settings. Emphasis is placed on understanding the threats in the generation, storage, and transfer of health data. By, utilizing the STRIDE (Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, and Elevation of privilege) model, we identified major threats, which are visually represented via heatmaps and bar graphs for ease of analysis. The DREAD (Damage, Reproducibility, Exploitability, Affected Users, and Discoverability) model assists in quantifying these threats, categorizing them into distinct risk levels, with detailed description of each threat category. In addition, we also suggest countermeasures for the highest-risk threats. This article serves as a pivotal resource for healthcare organizations and security professionals, shedding light on the risks of remote healthcare and providing mitigation strategies for both the implementation and post-implementation stages.
KW - DREAD Analysis
KW - IoMT
KW - Remote Care
KW - Risk Assessment
KW - STRIDE Model
KW - Threat
UR - https://www.scopus.com/pages/publications/85182391044
U2 - 10.1145/3626641.3627604
DO - 10.1145/3626641.3627604
M3 - Conference contribution
AN - SCOPUS:85182391044
T3 - ACM International Conference Proceeding Series
SP - 506
EP - 522
BT - SIET 2023 - Proceedings of the 8th International Conference on Sustainable Information Engineering and Technology
PB - Association for Computing Machinery
T2 - 8th International Conference on Sustainable Information Engineering and Technology, SIET 2023
Y2 - 24 October 2023 through 25 October 2023
ER -