Enhancing the Security Posture of OpenEMR with a Focus on Mitigating HTTP Distributed Denial-of-Service (DDoS) Attacks
Open Access DepositedIn an era of interconnected devices, healthcare delivery is critically dependent on applications, making the security and availability of Electronic Health Records (EHRs) imperative. OpenEMR systems experience HTTP DDoS attacks at the application level, preventing patients from accessing their data and causing medical disruptions due to system flooding. This research implements various security posture enhancements to safeguard OpenEMR from HTTP DDoS attacks by maintaining ongoing system availability, improved CPU performance, memory optimization, latency and throughput. A virtual lab environment was setup to contain two OpenEMR systems which operated as separate entities with the Unmodified version alongside a defense-in-depth secured (Modified) version that used rate-limiting, Fail2Ban for IP blocking, and code-level optimizations with dashboard caching and database indexing. Both systems were subjected to identical, sustained HTTP DDoS flood attacks generated from a Kali Linux machine to simulate real-world adversarial conditions. During the HTTP DDoS attack testing phase, the Modified version of OpenEMR demonstrated the effectiveness of the implemented mitigation strategies, as its system functionality was restored within 1 second, whereas the Unmodified version spanned 24 seconds to fully recover from the attack impact. The security improvements brought about system performance enhancement through decreased CPU and memory consumption which resulted in enhanced system throughput and shorter attack recovery times without impacting system availability during the HTTP DDoS attack.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.