<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="/oai-pmh.xsl"?>
<OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd">
  <responseDate>2026-09-22T02:39:18Z</responseDate>
  <request identifier="oai:www.ideals.illinois.edu:2142/44198" metadataPrefix="etdms" verb="GetRecord">https://www.ideals.illinois.edu/oai-pmh</request>
  <GetRecord>
    <record>
      <header>
        <identifier>oai:www.ideals.illinois.edu:2142/44198</identifier>
        <datestamp>2023-07-11</datestamp>
        <setSpec>col_2142_5131</setSpec>
        <setSpec>col_2142_10761</setSpec>
        <setSpec>com_2142_5130</setSpec>
        <setSpec>com_2142_10755</setSpec>
        <setSpec>com_2142_234</setSpec>
      </header>
      <metadata>
        <thesis xmlns="http://www.ndltd.org/standards/metadata/etdms/1.1/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:dc="http://purl.org/dc/elements/1.1/" xsi:schemaLocation="http://www.ndltd.org/standards/metadata/etdms/1.1/ http://www.ndltd.org/standards/metadata/etdms/1.1/etdms11.xsd http://purl.org/dc/elements/1.1/ http://www.ndltd.org/standards/metadata/etdms/1.1/etdmsdc.xsd">
          <dc:contributor>Gunter, Carl A.</dc:contributor>
          <dc:creator>Gupta, Siddharth</dc:creator>
          <dc:date>2013-05-24T21:53:58Z</dc:date>
          <dc:date>2013-05-24T21:53:58Z</dc:date>
          <dc:date>2013-05</dc:date>
          <dc:date>2013-05-24T21:53:58Z</dc:date>
          <dc:date>2013-05</dc:date>
          <dc:description>Recent use of Electronic Medical Records in the hospitals has raised many privacy concerns regarding confidential patient information which can be accessed by various users in the hospital's complex and dynamic environment.
There has been considerable success in developing strategies to detect insider threats in healthcare information systems based on what one might call the
random object access model or ROA. This approach models illegitimate users who randomly access records. The goal is to use statistics, machine learning, knowledge of hospital workflows and other techniques to support an anomaly
detection framework that  finds such users.
In this work we introduce and study a random topic access model, RTA, aimed at the users whose access may well be illegitimate but is not fully random because it is focused on common hospital themes. We argue that this
model is appropriate for a meaningful range of attacks and develop a system
based on topic summarization that is able to formalize the model and provide anomalous user detection for it. We also propose a framework for evaluating
the ability to recognize various types of random users called random topic access detection, or RTAD. The proposed RTAD framework is an unsupervised detection model which is a combination of Latent Dirichlet Allocation (LDA), for feature extraction, and a k-nearest neighbor (k-NN) algorithm
for outlier detection. The analysis is done on the dataset from Northwestern Memorial Hospital which consists of over 5 million accesses made by 8000
users to 14,000 patients in a four month time period. Our results show varying degrees of success based on user roles and the anticipated characteristics
of attackers and evaluate the ability to identify different adversarial types
relevant to the hospital ecosystem.</dc:description>
          <dc:description>Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2013-04-23T19:16:30Z
Item was in collections:
University of Illinois Theses &amp; Dissertations (ID: 1)
No. of bitstreams: 1
Gupta_Siddharth.pdf: 3498227 bytes, checksum: 328aa5e240eec85e1667110ad55ed030 (MD5)</dc:description>
          <dc:description>Made available in DSpace on 2013-05-24T21:53:58Z (GMT). No. of bitstreams: 2
Siddharth_Gupta.pdf: 3498227 bytes, checksum: 328aa5e240eec85e1667110ad55ed030 (MD5)
license.txt: 4065 bytes, checksum: 8c4a3d63aad2b58de8db5fa6f551f0b0 (MD5)</dc:description>
          <dc:identifier>http://hdl.handle.net/2142/44198</dc:identifier>
          <dc:language>en</dc:language>
          <dc:rights>Copyright 2013 Siddharth Gupta</dc:rights>
          <dc:subject>Data Mining</dc:subject>
          <dc:subject>Anomaly Detection</dc:subject>
          <dc:subject>Healthcare Security</dc:subject>
          <dc:subject>Electronic Health Records</dc:subject>
          <dc:subject>Access Logs</dc:subject>
          <dc:subject>Insider threats</dc:subject>
          <dc:title>Modeling and detecting anomalous topic access in EMR audit logs</dc:title>
          <dc:type>text</dc:type>
          <degree>
            <department>Computer Science</department>
            <departmentCode>1434</departmentCode>
            <discipline>Computer Science</discipline>
            <disciplineCode>0112</disciplineCode>
            <grantor>University of Illinois at Urbana-Champaign</grantor>
            <level>Thesis</level>
            <name>M.S.</name>
            <program>MS:Computer Science -UIUC</program>
            <programCode>10KS0112MS</programCode>
          </degree>
        </thesis>
      </metadata>
    </record>
  </GetRecord>
</OAI-PMH>
