A Framework for Open Source Intelligence Penetration Testing of Virtual Health Care Systems

C DeCusatis, P Peko, J Irving, M Teache, C Laibach, J Hodge

2022 IEEE 12TH ANNUAL COMPUTING AND COMMUNICATION WORKSHOP AND CONFERENCE (CCWC)(2022)

引用 1|浏览7
暂无评分
摘要
There is a need for affordable, accessible ethical penetration testing methodologies in the online health care industry. In this paper, we propose and experimentally demonstrate an approach for initial ethical penetration testing of remote health care services based on free, open source tools and open systems intelligence. We develop an approach which concentrates on the most common health care vulnerabilities (social engineering attacks, network-based attacks, and website attacks) using OWASP ZAP, Nmap with Firewalk, and various other tools. Experimental results of penetration testing on a production level mental health care provider are presented. The effectiveness of different approaches is compared, and we enumerate common vulnerabilities and recommend mitigation techniques.
更多
查看译文
关键词
OSINT, health, penetration, test, cybersecurity
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要