Content area

Abstract

The healthcare sectors have constantly faced significant challenge due to the rapid rise of cyber threats. These threats can pose any potential risk within the system context and disrupt the critical healthcare service delivery. It is therefore necessary for the healthcare organisations to understand and tackle the threats to ensure overall security and resilience. However, threats are continuously evolved and there is large amount of unstructured security-related textual information is available. This makes the threat assessment and management task very challenging. There are a number of existing works that consider Machine Learning models for detection and prediction of cyber attack but they lack of focus on the Natural Language Processing (NLP) to extract the threat information from unstructured security-related text. To this end, this work proposes a novel method to assess and manage threats by adopting natural language processing. The proposed method has been tailored for the healthcare ecosystem and allows to identify and assess the possible threats within healthcare information infrastructure so that appropriate control and mitigation actions can be taken into consideration to tackle the threat. In detail, NLP techniques are used to extract the useful threat information related to specific assets of the healthcare ecosystems from the largely available security-related information on Internet (e.g. cyber security news), to evaluate the level of the identified threats and to select the required mitigation actions. We have performed experiments on real healthcare ecosystems in Fraunhofer Institute for Biomedical Engineering, considering in particular three different healthcare scenarios, namely implantable medical devices, wearables, and biobank, with the purpose of demonstrating the feasibility of our approach, which is able to provide a realistic manner to identify and assess the threats, evaluate the threat level and suggest the required mitigation actions.

Details

10000008
Title
Cyber threat assessment and management for securing healthcare ecosystems using natural language processing
Author
Silvestri, Stefano 1 ; Islam, Shareful 2 ; Amelin, Dmitry 3 ; Weiler, Gabriele 3 ; Papastergiou, Spyridon 4 ; Ciampi, Mario 1 

 Institute for High Performance Computing and Networking of the National Research Council of Italy, ICAR-CNR, Naples, Italy (GRID:grid.5326.2) (ISNI:0000 0001 1940 4177) 
 Science Anglia Ruskin University, School of Computing and Information, Cambridge, UK (GRID:grid.5115.0) (ISNI:0000 0001 2299 5510); Focal Point, Waterloo, Belgium (GRID:grid.5115.0) 
 Fraunhofer Institute for Biomedical Engineering IBMT, Sulzbach, Germany (GRID:grid.452493.d) (ISNI:0000 0004 0542 0741) 
 Focal Point, Waterloo, Belgium (GRID:grid.452493.d); University of Piraeus, Department of Informatics, Piraeus, Greece (GRID:grid.4463.5) (ISNI:0000 0001 0558 8585) 
Publication title
Volume
23
Issue
1
Pages
31-50
Publication year
2024
Publication date
Feb 2024
Publisher
Springer Nature B.V.
Place of publication
Heidelberg
Country of publication
Netherlands
Publication subject
ISSN
16155262
e-ISSN
16155270
Source type
Scholarly Journal
Language of publication
English
Document type
Journal Article
Publication history
 
 
Online publication date
2023-10-27
Milestone dates
2023-10-05 (Registration)
Publication history
 
 
   First posting date
27 Oct 2023
ProQuest document ID
2917414650
Document URL
https://www.proquest.com/scholarly-journals/cyber-threat-assessment-management-securing/docview/2917414650/se-2?accountid=208611
Copyright
© The Author(s) 2023. This work is published under http://creativecommons.org/licenses/by/4.0/ (the “License”). Notwithstanding the ProQuest Terms and Conditions, you may use this content in accordance with the terms of the License.
Last updated
2025-11-19
Database
ProQuest One Academic