Submit your papersSubmit Now
For Enquiries: [email protected]
IIARD LogoIIARD

Threat Modeling in Health Care Sector

Chisom Elizabeth Alozie

Abstract

Strong security measures are required when integrating digital systems for managing sensitive patient data in the quickly changing healthcare industry. In order to discover, evaluate, and mitigate potential security vulnerabilities related to digital healthcare systems, this study examines the crucial role that threat modelling plays. Through the analysis of three well-known threat models -STRIDE, PASTA, and Attack Trees, this study seeks to identify the best course of action for guaranteeing the confidentiality and security of medical data. The study emphasizes how crucial it is to integrate security engineering into healthcare modelling to control IoT- related cyberthreats and protect patient data privacy. It also emphasizes the necessity of straightforward threat modelling techniques that are generally applicable and do not necessitate a high level of security expertise. According to the results, enhanced threat and risk modelling as well as scenario planning can greatly improve operational resilience and cybersecurity in healthcare environments. The importance of strategic data management in preserving key services and organisational effectiveness is highlighted in this study, which offers insightful information for security designers and healthcare executives.

References

Alozie, C. (2025). Literature review on the application of blockchain technology initiative. SSRN Electronic Journal. https://doi.org/10.2139/ssrn.5085115 Alozie, C. E., Akerele, J. I., Kamau, E., & Myllynen, T. (2024a). Capacity planning in cloud computing: A site Reliability Engineering approach to optimizing resource allocation. International Journal of Management and Organizational Research, 3(1), 49–61. https://doi.org/10.54660/ijmor.2024.3.1.49-61 Alozie, C. E., Akerele, J. I., Kamau, E., & Myllynen, T. (2024b). Disaster recovery in cloud computing: Site Reliability Engineering strategies for resilience and business continuity. International Journal of Management and Organizational Research, 3(1), 36–48. https://doi.org/10.54660/ijmor.2024.3.1.36-48 Alozie, C. E., Akerele, J. I., Kamau, E., & Myllynen, T. (2024c). Optimizing IT governance and risk management for enhanced business analytics and data integrity in the United States. International Journal of Management and Organizational Research, 3(1), 25– https://doi.org/10.54660/ijmor.2024.3.1.25-35 Alozie, C. E., & Chinwe, E. E. (2025). Developing a cybersecurity framework for protecting critical infrastructure in organizations. ICONIC RESEARCH AND ENGINEERING JOURNALS. https://doi.org/10.5281/ZENODO.14740463 Balamurugan, Sudalaimuthu., & Solomi., S. (2023). An analysis of various cyber threat modeling. 2023 Third International Conference on Artificial Intelligence and Smart Energy (ICAIS). Chinwe, E. E., & Alozie, C. E. (2025). Adversarial tactics, techniques, and procedures (TTPs): A deep dive into modern cyber attacks. ICONIC RESEARCH AND ENGINEERING JOURNALS. https://doi.org/10.5281/ZENODO.14740424 Crothers, E., Japkowicz, N., & Viktor, H. (2022). Machine generated text: A comprehensive survey of threat models and detection methods. In arXiv [cs.CL]. https://doi.org/10.48550/ARXIV.2210.07321 Cybercrime Magazine. (2021, April 27). Cybercrime to cost the world $10.5 trillion annually by 2025. Cybercrime Magazine. https://cybersecurityventures.com/cyberwarfare- report-intrusion/ Hussien, H. M., Yasin, S. M., Udzir, N. I., Ninggal, M. I. H., & Salman, S. (2021). Blockchain technology in the healthcare industry: Trends and opportunities. Journal of Industrial Information Integration, 22(100217), https://doi.org/10.1016/j.jii.2021.100217 Jayapal, C., & Srinivasan, S. (2023). Healthcare system modeling and security engineering. In Intelligent Sustainable Systems (pp. 237–252). Springer Nature Singapore. Karakra, A., Fontanili, F., Taweel, A., Lamine, E., Lamothe, J., & Barghouthi, H. (2022). Digital twin in healthcare: Security threat meta-model. 2022 IEEE/ACS 19th International Conference on Computer Systems and Applications (AICCSA). Kiyani, A. T., Lasebae, A., Ali, K., Alkhayyat, A., Haq, B., & Naeem, B. (2022). Robust continuous user authentication system using long short term memory network for healthcare. In Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering (pp. 295–307). Springer International Publishing. Mohanty, R. K., Padmaja, C. V. R., Kanaparthi, S. K., & Rajan, A. (2024). Unified threat modeling: Strategies for comprehensive risk assessment in modern systems. In Advances in Educational Technologies and Instructional Design (pp. 429–450). IGI Global. Nvd - cve-2020-14494. (n.d.). Nist.gov. Retrieved February 19, 2025, from https://nvd.nist.gov/vuln/detail/CVE-2020-14494 Nvd - cve-2021-44151. (n.d.). Nist.gov. Retrieved February 19, 2025, from https://nvd.nist.gov/vuln/detail/CVE-2021-44151 Nvd - cve-2023-23923. (n.d.). Nist.gov. Retrieved February 19, 2025, from https://nvd.nist.gov/vuln/detail/CVE-2023-23923 Nvd - cve-2024-21661. (n.d.). Nist.gov. Retrieved February 19, 2025, from https://nvd.nist.gov/vuln/detail/CVE-2024-21661 Ochieng’dola, T., & Korõtko - Computers. (2023). Threat modeling of cyber-physical systems- a case study of a microgrid system. Elsevier PhD Student Of Tashkent University Of Information Technologies Named After Muhammad Al-Khwarizmi, Tashkent, Uzbekistan, & Mohinabonu, A. (2024). Threat model for payment systems. American Journal of Applied Science and Technology, 4(10), 87–94. https://doi.org/10.37547/ajast/volume04issue10-13 Punithavathi, P., & Subbiah, G. (2022). Digital healthcare security issues: Is there a solution in biometrics? In Research Anthology on Securing Medical Systems and Records (pp. 17– 30). IGI Global. Rajasekar, V., Jayapaul, P., Krishnamoorthi, S., & Sara?evi?, M. (2021). Secure remote user authentication scheme on health care, IoT and cloud applications: A multilayer systematic survey. Acta Polytechnica Hungarica, 18(3), 87–106. https://doi.org/10.12700/aph.18.3.2021.3.5 Salami, A. A., Igwenagu, U. T. I., Mesode, C. E., Olaniyi, O. O., & Oladoyinbo, O. B. (2024). Beyond conventional threat defense: Implementing advanced threat modeling techniques, risk modeling frameworks and contingency planning in the healthcare sector for enhanced data security. Journal of Engineering Research and Reports, 26(5), 304–323. https://doi.org/10.9734/jerr/2024/v26i51156 Salau, A., Dantu, R., Morozov, K., Upadhyay, K., & Badruddoja, S. (2022). Towards a threat model and security analysis for data cooperatives. Proceedings of the 19th International Conference on Security and Cryptography. Sharma, G., & Singh, G. (2023). Robust user authentication scheme for IoT-based healthcare applications. In Recent Advancements in Smart Remote Patient Monitoring, Wearable Devices, and Diagnostics Systems (pp. 170–182). IGI Global. Simonjan, J., Taurer, S., & Dieber, B. (2020). A generalized threat model for visual sensor networks. Sensors (Basel, Switzerland), 20(13), https://doi.org/10.3390/s20133629 Sobahi, N., & Bamabad, A. (2024). Cyber-attacks risk analysis of a connected pulse oximeter device: A threat modeling using STRIDE and DREAD models. International Journal for Scientific Research, 3(5), 280–315. https://doi.org/10.59992/ijsr.2024.v3n5p10 Suleski, T., & Ahmed, M. (2023). A data taxonomy for adaptive multifactor authentication in the Internet of Health Care Things. Journal of Medical Internet Research, 25, e44114. https://doi.org/10.2196/44114 Ussatova, O., Makilenov, S., Mukaddas, A., Amanzholova, S., Begimbayeva, Y., & Ussatov, N. (2023). Enhancing healthcare data security: a two-step authentication scheme with cloud technology and blockchain. Eastern-European Journal of Enterprise Technologies, 6(2 (126)), 6–16. https://doi.org/10.15587/1729-4061.2023.289325 Van Landuyt, D., & Joosen, W. (2022). A descriptive study of assumptions in STRIDE security threat modeling. Software & Systems Modeling, 21(6), 2311–2328. https://doi.org/10.1007/s10270-021-00941-7 Van Landuyt, W. (2022). Springer. A descriptive study of assumptions in STRIDE security threat modeling. Software and Systems Modeling. Vir, R., & Sharma, V. (2023). Multi-factor remote user authentication scheme for WSN-IoT based healthcare services. In Emerging Trends in Engineering and Management (pp. 151–172). Soft Computing Research Society. von der Assen, J., Sharif, J., Feng, C., Killer, C., Bovet, G., & Stiller, B. (2024). Asset-centric threat modeling for AI-based systems. In arXiv [cs.CR]. http://arxiv.org/abs/2403.06512 Wang, S., Zhou, X., Wen, K., Weng, B., & Zeng, P. (2023). Security analysis of a user authentication scheme for IoT-based healthcare. IEEE Internet of Things Journal, 10(7), 6527–6530. https://doi.org/10.1109/jiot.2022.3228921

More Articles from INTERNATIONAL JOURNAL OF ENGINEERING AND MODERN TECHNOLOGY