Security Analysis and Threat Modeling of Research Management Applications [Extended Version]

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Sindala, Boniface M., Hasan, Ragib
Formato: Preprint
Publicado: 2025
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866909823665176576
author Sindala, Boniface M.
Hasan, Ragib
author_facet Sindala, Boniface M.
Hasan, Ragib
contents Research management applications (RMA) are widely used in clinical research environments to collect, transmit, analyze, and store sensitive data. This data is so valuable making RMAs susceptible to security threats. This analysis, analyzes RMAs' security, focusing on Research Electronic Data Capture (REDCap) as an example. We explore the strengths and vulnerabilities within RMAs by evaluating the architecture, data flow, and security features. We identify and assess potential risks using the MITRE ATT\&CK framework and STRIDE model. We assess REDCap's defenses against common attack vectors focusing on security to provide confidentiality, integrity, availability, non-repudiation, and authentication. We conclude by proposing recommendations for enhancing the security of RMAs, ensuring that critical research data remains protected without compromising usability. This research aims to contribute towards a more secure framework for managing sensitive information in research-intensive environments.
format Preprint
id arxiv_https___arxiv_org_abs_2510_03407
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Security Analysis and Threat Modeling of Research Management Applications [Extended Version]
Sindala, Boniface M.
Hasan, Ragib
Cryptography and Security
Research management applications (RMA) are widely used in clinical research environments to collect, transmit, analyze, and store sensitive data. This data is so valuable making RMAs susceptible to security threats. This analysis, analyzes RMAs' security, focusing on Research Electronic Data Capture (REDCap) as an example. We explore the strengths and vulnerabilities within RMAs by evaluating the architecture, data flow, and security features. We identify and assess potential risks using the MITRE ATT\&CK framework and STRIDE model. We assess REDCap's defenses against common attack vectors focusing on security to provide confidentiality, integrity, availability, non-repudiation, and authentication. We conclude by proposing recommendations for enhancing the security of RMAs, ensuring that critical research data remains protected without compromising usability. This research aims to contribute towards a more secure framework for managing sensitive information in research-intensive environments.
title Security Analysis and Threat Modeling of Research Management Applications [Extended Version]
topic Cryptography and Security
url https://arxiv.org/abs/2510.03407