Potecting Patient Privacy: Understanding and Classifying Attacks and Vulnerabilities in Web-Based Healthcare Records
摘要
In recent times, the web has undergone significant changes in terms of its application architecture, development technologies, and user interactions. On a daily basis, millions of users engage in various online activities, such as consulting of medical records, accessing bank and insurance accounts, making payments, and purchasing products, while also sharing their personal information. However, this evolution has introduced new challenges that aim to make the lives of web users easier and meet their demands. The lack of awareness of security issues, along with deficiencies in the design and implementation of applications, has been identified as the primary reason for web vulnerabilities. Attackers can exploit these vulnerabilities to engage in illegal activities or disrupt application operations, compromising the privacy of users and their sensitive data transmitted over the internet, and resulting in financial losses for application owners. This manuscript provides an in-depth analysis of the most critical web attacks. Our review includes various taxonomies of vulnerabilities, including the OWASP ranking to help developers and designers better understand attack scenarios and make sure to follow fundamental security principles in medical record management applications. We propose a comprehensive taxonomy to address the issues related to web attacks. This taxonomy is based on three dimensions that consider the attack vector, attack target, and vulnerability category. The first dimension covers the attack vector and identifies the primary attacker or the main culprits. The second dimension classifies the attack targets, which can be the client side or the server side. While the third dimension classifies vulnerabilities based on the category or behavior of the attack. Together, these dimensions provide a holistic approach to the taxonomy of web attacks.