Running head: STRIDE AND PRIVACY ATTACKS IN THE HEALTHCARE INDUSTR 1
STRIDE and Privacy Attacks in the Healthcare Industry
ISOL 536
Security Architecture & Design
Submitted to
Professor Charles DeSassure
University of the Cumberlands
Submitted in Partial Fulfillment of the Requirements for
Fall 2019
by
12/04/2019
STRIDE AND PRIVACY ATTACKS IN THE HEALTHCARE INDUSTRY 2
Abstract
We live in a world where the use of information systems in key in which various
industries are relying on computer systems in driving their businesses. The use of computer
systems has become so important in which organizations are hard to build sustainable
businesses outside these computer systems. Today both large and small organizations are
relying on the use of computer systems. Primarily, these computer systems house large
volume of data that tends to contain valuable information in which if hackers and other cyber
criminals come into contact, they can use it for the wrong reasons. In this account, one of the
industries that relies heavily on the usage of computer and information systems is the
healthcare industry. Within this industry, various types of information from different walks of
lives of people is being collected which results in the building of patient’s profile that
contains their personal information, medical information and financial information. In the
dark net, such volumes may fetch good amounts of money. In this account, as much as the
healthcare industry is taking the advantage of collecting and using data, there is the need of
protecting this information for the aim of protecting the privacy of its customers. Taking this
into account, the following paper will seek to identify some of the companies within the
healthcare industry that have been victim f STRIDE and privacy attack and the measures
these companies took in addressing such threats from occurring in the future.
STRIDE AND PRIVACY ATTACKS IN THE HEALTHCARE INDUSTRY 3
STRIDE and Privacy Attacks in the Healthcare Industry
The world today is rapidly evolving towards the world of digitalization in which
information is no longer stored in drawers and cabinets rather than in information systems. In
this case, the information from the business environment is collected over time and it is used
in creating the profile of its customers. Within the healthcare industry, much as changed
thanks to the availability of technology and information systems that have facilitated a
number of operations such as decision making and evidence-based practices to be enhanced.
However, as much as a number of advantages are being accrued from deploying the use of
information systems within the healthcare industry, the biggest challenge that comes with the
utilization of these systems is cyber threats. According to Mucchi, Jayousi, Martinelli,
Caputo, & Marcocci (2018), each year, the amount of IT budget that is being allocated in
protecting system keeps on increasing based on the fact that IT related breaches are costly to
these organizations. One of the main reasons that the healthcare industry is always under
constant attacks is the type of information that this industry houses which contains highly
sensitive information of the population (Bharati & Pattnaik, 2015). When one goes to any
healthcare facility, they provide more information such as their names, physical addresses,
email addresses, next of kin and their details, and even bank details. When such information
is collected, it results in the building of a patient’s data that can be collected over time and
when more and more data is collected from other patients, it accumulates to create a database.
STRIDE and Privacy Attacks
When dealing with cyber-attacks, they come in different forms as defined by the
concept f STRIDE. As per Supriya & Padaki (2016), STRIDE refers to attacks that are
related to spoofing, tampering, repudiation, information disclosure, denial of service, and
escalation of privileges.
Spoofing
STRIDE AND PRIVACY ATTACKS IN THE HEALTHCARE INDUSTRY 4
According to Bharati & Pattnaik (2015), most of the information systems today rely
on their users to provide their real identity and authentication for them to use these systems.
If someone fails to provide their identity and authenticity, they are denied access into these
systems. However, with spoofing, a cybercriminal will go ahead and use the credential of a
user without their knowledge and access a system. according to Mucchi et al. (2015) one of
the ways of securing systems is through the use of passwords which acts as the first line of
defense. However, not all people get to practice the required practices when it comes to the
usage of passwords. In this case, users get to use weaker passwords that can be easily be
guessed such as using their personal information as passwords. In this account, Abomhara,
Gerdes & Køien (2015) denote that spoofing relies on weak authentication. As a result, one
of the ways of dealing with spoofing is the implementation of stronger passwords that may