Hospital computer networks, unlike humans, are not born with immune systems to protect themselves from virus attacks, hackers, or other maladies lurking in cyberspace. Yet networks do not exist in sterile bubbles either. Those in charge of protecting a
Hospital computer networks, unlike humans, are not born with immune systems to protect themselves from virus attacks, hackers, or other maladies lurking in cyberspace.
Yet networks do not exist in sterile bubbles either. Those in charge of protecting a network and its assets - while still providing service - must find the elusive balance between security and user benefit.
Sam Dwyer, Ph.D., a professor of radiology at the University of Virginia, lists several questions that must be answered in planning network security:
?What's being protected?
?What's the value of these assets?
?What vulnerabilities exist?
?Who's most likely to attack and by what methods?
?What would the consequences of a successful attack be?
?What protection is available?
"The depth of detail of network functionality, like the study of human anatomy, can be highly involved," said Thomas Siu, a network analyst at NASA's Glenn Research Center in Brookpark, OH. "Luckily, people don't die in these situations. But when medical care is dependent upon confidentiality, integrity, and availability of information accessed via the network, the management of security risks takes on greater significance."
Siu recommends constructing a network defense system that relies on multiple layers to provide security from threats from outside its perimeter as well as within.
"The security layers of perimeter defense, internal diagnostics, and user practices make up the high-level structure of a very detailed environment that protects the information within the network," he said.
The term 'perimeter defense' implies a firewall, a bastion of defense against outside invaders, Siu said.
"Such a defense consists of multiple systems that work synchronously to enforce an access-control policy, to permit only certain network traffic to pass through the boundary," he said.
With perimeter security, you can either permit all services but deny only specific risky traffic, or you can deny all traffic and permit only specifically allowed traffic. The first policy means users may introduce security risks to the network. The second policy avoids those risks, but users are disempowered, Siu said.
Inside the perimeter, some form of intrusion detection is important.
"It won't do you much good to know how people are likely to break into your network if you don't have a way of knowing when an attack is taking place," Dwyer said.
Study Reaffirms Low Risk for csPCa with Biopsy Omission After Negative Prostate MRI
December 19th 2024In a new study involving nearly 600 biopsy-naïve men, researchers found that only 4 percent of those with negative prostate MRI had clinically significant prostate cancer after three years of active monitoring.
Study Examines Impact of Deep Learning on Fast MRI Protocols for Knee Pain
December 17th 2024Ten-minute and five-minute knee MRI exams with compressed sequences facilitated by deep learning offered nearly equivalent sensitivity and specificity as an 18-minute conventional MRI knee exam, according to research presented recently at the RSNA conference.
Can Radiomics Bolster Low-Dose CT Prognostic Assessment for High-Risk Lung Adenocarcinoma?
December 16th 2024A CT-based radiomic model offered over 10 percent higher specificity and positive predictive value for high-risk lung adenocarcinoma in comparison to a radiographic model, according to external validation testing in a recent study.