NHS WannaCry勒索软件攻击:漏洞、利用和对策的技术解释

Mohammad Aljaidi, A. Alsarhan, G. Samara, Raed Alazaidah, S. Almatarneh, Muhammad Khalid, Y. Al-Gumaei
{"title":"NHS WannaCry勒索软件攻击:漏洞、利用和对策的技术解释","authors":"Mohammad Aljaidi, A. Alsarhan, G. Samara, Raed Alazaidah, S. Almatarneh, Muhammad Khalid, Y. Al-Gumaei","doi":"10.1109/EICEEAI56378.2022.10050485","DOIUrl":null,"url":null,"abstract":"To ascertain the consequences of the 2017 WannaCry ransomware attack on the National Health Service (NHS), a systematic investigation of Hospital Episodes Statistics (HES) data was conducted to identify the missed appointments, fatalities, and financial expenses linked to the WannaCry ransomware attack. Outpatient appointment cancellations, hospital emergency and elective admissions, visits to accident and emergency (A&E), and deaths in A&E were the key output tracked. During the week of the ransomware incident, there was no appreciable difference in overall activity between all trusts compared to the baseline. Trusts had 1% fewer accident and emergency visits a day than at baseline, and 1% more admission to the emergency departments. Although there were much fewer elective and emergency admissions in hospitals that had been directly infected by the ransomware, there was nevertheless a daily drop in admissions of roughly 6%, with 4% fewer emergency departments visits, and 9% fewer elective admissions. There was no discernible mortality difference. The reduced activity at the affected trusts over this time had a total economic impact of £5.9 million, which included £0.6 million in lost accident and emergency activity, £1.3 million in lost outpatient consultations, and £4 million in missed inpatient admissions. There was a considerable drop in attendance and admissions among hospitals targeted and affected by the WannaCry ransomware attack, resulting to a loss of hospital activity of £5.9 million. Even though this is a rudimentary indicator of patient damage, there was no documented increase in mortality. To fully understand how a cyberattack or IT problems may affect patient safety and care delivery, more research is required.","PeriodicalId":426838,"journal":{"name":"2022 International Engineering Conference on Electrical, Energy, and Artificial Intelligence (EICEEAI)","volume":"204 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-11-06","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"NHS WannaCry Ransomware Attack: Technical Explanation of The Vulnerability, Exploitation, and Countermeasures\",\"authors\":\"Mohammad Aljaidi, A. Alsarhan, G. Samara, Raed Alazaidah, S. Almatarneh, Muhammad Khalid, Y. Al-Gumaei\",\"doi\":\"10.1109/EICEEAI56378.2022.10050485\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"To ascertain the consequences of the 2017 WannaCry ransomware attack on the National Health Service (NHS), a systematic investigation of Hospital Episodes Statistics (HES) data was conducted to identify the missed appointments, fatalities, and financial expenses linked to the WannaCry ransomware attack. Outpatient appointment cancellations, hospital emergency and elective admissions, visits to accident and emergency (A&E), and deaths in A&E were the key output tracked. During the week of the ransomware incident, there was no appreciable difference in overall activity between all trusts compared to the baseline. Trusts had 1% fewer accident and emergency visits a day than at baseline, and 1% more admission to the emergency departments. Although there were much fewer elective and emergency admissions in hospitals that had been directly infected by the ransomware, there was nevertheless a daily drop in admissions of roughly 6%, with 4% fewer emergency departments visits, and 9% fewer elective admissions. There was no discernible mortality difference. The reduced activity at the affected trusts over this time had a total economic impact of £5.9 million, which included £0.6 million in lost accident and emergency activity, £1.3 million in lost outpatient consultations, and £4 million in missed inpatient admissions. There was a considerable drop in attendance and admissions among hospitals targeted and affected by the WannaCry ransomware attack, resulting to a loss of hospital activity of £5.9 million. Even though this is a rudimentary indicator of patient damage, there was no documented increase in mortality. To fully understand how a cyberattack or IT problems may affect patient safety and care delivery, more research is required.\",\"PeriodicalId\":426838,\"journal\":{\"name\":\"2022 International Engineering Conference on Electrical, Energy, and Artificial Intelligence (EICEEAI)\",\"volume\":\"204 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2022-11-06\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2022 International Engineering Conference on Electrical, Energy, and Artificial Intelligence (EICEEAI)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/EICEEAI56378.2022.10050485\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 International Engineering Conference on Electrical, Energy, and Artificial Intelligence (EICEEAI)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/EICEEAI56378.2022.10050485","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

摘要

为了确定2017年WannaCry勒索软件攻击对英国国家医疗服务体系(NHS)的影响,对医院事件统计(HES)数据进行了系统调查,以确定与WannaCry勒索软件攻击相关的错过预约、死亡和财务费用。门诊预约取消、医院急诊和选择性入院、急诊(A&E)就诊以及在A&E死亡是跟踪的主要产出。在勒索软件事件发生的一周内,与基线相比,所有信任之间的总体活动没有明显差异。与基线相比,信托每天的事故和急诊访问量减少了1%,急诊室的入院人数增加了1%。尽管直接感染了勒索软件的医院的选择性和紧急入院人数要少得多,但入院人数每天仍下降了约6%,急诊室就诊人数减少了4%,选择性入院人数减少了9%。没有明显的死亡率差异。在这段时间里,受影响的信托机构减少的活动造成了590万英镑的总经济影响,其中包括60万英镑的事故和紧急活动损失,130万英镑的门诊咨询损失,400万英镑的住院病人错过。受WannaCry勒索软件攻击和影响的医院的上座率和入院人数大幅下降,导致医院活动损失590万英镑。尽管这是患者损伤的基本指标,但没有证据表明死亡率增加。为了充分了解网络攻击或IT问题如何影响患者安全和医疗服务,还需要进行更多的研究。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
NHS WannaCry Ransomware Attack: Technical Explanation of The Vulnerability, Exploitation, and Countermeasures
To ascertain the consequences of the 2017 WannaCry ransomware attack on the National Health Service (NHS), a systematic investigation of Hospital Episodes Statistics (HES) data was conducted to identify the missed appointments, fatalities, and financial expenses linked to the WannaCry ransomware attack. Outpatient appointment cancellations, hospital emergency and elective admissions, visits to accident and emergency (A&E), and deaths in A&E were the key output tracked. During the week of the ransomware incident, there was no appreciable difference in overall activity between all trusts compared to the baseline. Trusts had 1% fewer accident and emergency visits a day than at baseline, and 1% more admission to the emergency departments. Although there were much fewer elective and emergency admissions in hospitals that had been directly infected by the ransomware, there was nevertheless a daily drop in admissions of roughly 6%, with 4% fewer emergency departments visits, and 9% fewer elective admissions. There was no discernible mortality difference. The reduced activity at the affected trusts over this time had a total economic impact of £5.9 million, which included £0.6 million in lost accident and emergency activity, £1.3 million in lost outpatient consultations, and £4 million in missed inpatient admissions. There was a considerable drop in attendance and admissions among hospitals targeted and affected by the WannaCry ransomware attack, resulting to a loss of hospital activity of £5.9 million. Even though this is a rudimentary indicator of patient damage, there was no documented increase in mortality. To fully understand how a cyberattack or IT problems may affect patient safety and care delivery, more research is required.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信