Keep an eye on your personal belongings! The security of personal medical devices and their ecosystems
- PMID: 31201966
- DOI: 10.1016/j.jbi.2019.103233
Keep an eye on your personal belongings! The security of personal medical devices and their ecosystems
Abstract
Today, personal medical devices (PMDs) play an increasingly important role in healthcare ecosystems as patient life support equipment. As a result of technological advances, PMDs now encompass many components and functionalities that open the door to a variety of cyber-attacks. In this paper we present a taxonomy of ten widely-used PMDs based on the five diseases they were designed to treat. We also provide a comprehensive survey that covers 17 possible attacks aimed at PMDs, as well as the attacks' building blocks. For each PMD type, we create an ecosystem and data and attack flow diagram, which comprehensively describes the roles and interactions of the players associated with the PMD and presents the most vulnerable vectors and components within the PMDs' ecosystems; such knowledge can increase security awareness among PMD users and their healthcare providers. We also present the basic, yet important, building blocks that constitute the steps by which each of the attacks presented is carried out. Doing so allowed us to establish the foundations for the future development of a novel risk analysis methodology for medical devices. For each attack we mapped the building blocks required to carry out the attack and found that 50% of the attacks rely upon the ability to remotely connect to the PMD, while 61% of them rely on the physical proximity of the attacker to the PMD. Finally, by surveying 21 existing security mechanisms and mapping their coverage for the attacks, we identify the gaps between PMDs' security mechanisms and the possible attacks. We show that current security mechanisms generally fail to provide protection from all of the attacks against PMDs and suggest the development of a comprehensive framework to secure PMDs and protect the patients that rely upon them.
Keywords: Attack; Cyber; Detection; Implanted; Malware; Medical device; Pacemaker; Security.
Copyright © 2019 Elsevier Inc. All rights reserved.
Similar articles
-
A Cyber Risk Assessment Approach to Federated Identity Management Framework-Based Digital Healthcare System.Sensors (Basel). 2024 Aug 15;24(16):5282. doi: 10.3390/s24165282. Sensors (Basel). 2024. PMID: 39204976 Free PMC article.
-
Security of implantable medical devices with wireless connections: The dangers of cyber-attacks.Expert Rev Med Devices. 2018 Jun;15(6):403-406. doi: 10.1080/17434440.2018.1483235. Epub 2018 Jun 13. Expert Rev Med Devices. 2018. PMID: 29860880 Review. No abstract available.
-
Cyber resilience: a review of critical national infrastructure and cyber security protection measures applied in the UK and USA.J Bus Contin Emer Plan. 2013-2014 Winter;7(2):149-62. J Bus Contin Emer Plan. 2013. PMID: 24457326 Review.
-
Cybersecurity Challenges in Healthcare.Stud Health Technol Inform. 2022 Oct 26;300:190-202. doi: 10.3233/SHTI220951. Stud Health Technol Inform. 2022. PMID: 36300412
-
Brainjacking: Implant Security Issues in Invasive Neuromodulation.World Neurosurg. 2016 Aug;92:454-462. doi: 10.1016/j.wneu.2016.05.010. Epub 2016 May 13. World Neurosurg. 2016. PMID: 27184896 Review.
Cited by
-
A Data Taxonomy for Adaptive Multifactor Authentication in the Internet of Health Care Things.J Med Internet Res. 2023 Aug 29;25:e44114. doi: 10.2196/44114. J Med Internet Res. 2023. PMID: 37490633 Free PMC article. Review.
-
A Comprehensive Survey on Security and Privacy for Electronic Health Data.Int J Environ Res Public Health. 2021 Sep 14;18(18):9668. doi: 10.3390/ijerph18189668. Int J Environ Res Public Health. 2021. PMID: 34574593 Free PMC article. Review.
-
Patient informed consent, ethical and legal considerations in the context of digital vulnerability with smart, cardiac implantable electronic devices.PLOS Digit Health. 2024 May 23;3(5):e0000507. doi: 10.1371/journal.pdig.0000507. eCollection 2024 May. PLOS Digit Health. 2024. PMID: 38781144 Free PMC article. Review.
-
Cyber Attacks on Healthcare Devices Using Unmanned Aerial Vehicles.J Med Syst. 2019 Dec 14;44(1):29. doi: 10.1007/s10916-019-1489-9. J Med Syst. 2019. PMID: 31838588
-
A Cyber Risk Assessment Approach to Federated Identity Management Framework-Based Digital Healthcare System.Sensors (Basel). 2024 Aug 15;24(16):5282. doi: 10.3390/s24165282. Sensors (Basel). 2024. PMID: 39204976 Free PMC article.
Publication types
MeSH terms
LinkOut - more resources
Full Text Sources
Research Materials