Skip to main content
QUICK REVIEW

[논문 리뷰] A New Methodology for Information Security Risk Assessment for Medical Devices and Its Evaluation

Tom Mahler, Yuval Elovici|arXiv (Cornell University)|2020. 02. 17.
Healthcare Technology and Patient Monitoring참고 문헌 34인용 수 9
한 줄 요약

이 논문은 의료 기기의 정보 보안 위험 평가를 위한 새로운 방법론인 TLDR를 제안한다. 이 방법론은 사이버 공격을 CAPEC 온톨로지에 매핑하고, 전문가 패anel을 통해 확률을 추정하며, CAPEC 기반의 확률와 전문가가 평가한 심각도를 통합하여 복합 위험 점수를 산출한다. 방법론은 CAPEC 기반의 확률 추정과 직접적인 전문가 확률 추정 간에 강한 상관관계(Spearman의 rho > 0.8)를 보이고, t-검정 결과가 유의미하지 않아 신뢰성과 효율성이 전통적 방법에 비해 뛰어나다는 것을 입증한다.

ABSTRACT

As technology advances towards more connected and digital environments, medical devices are becoming increasingly connected to hospital networks and to the Internet, which exposes them, and thus the patients using them, to new cybersecurity threats. Currently, there is a lack of a methodology dedicated to information security risk assessment for medical devices. In this study, we present the Threat identification, ontology-based Likelihood, severity Decomposition, and Risk integration (TLDR) methodology for information security risk assessment for medical devices. The TLDR methodology uses the following steps: (1) identifying the potentially vulnerable components of medical devices, in this case, four different medical imaging devices (MIDs); (2) identifying the potential attacks, in this case, 23 potential attacks on MIDs; (3) mapping the discovered attacks into a known attack ontology - in this case, the Common Attack Pattern Enumeration and Classifications (CAPECs); (4) estimating the likelihood of the mapped CAPECs in the medical domain with the assistance of a panel of senior healthcare Information Security Experts (ISEs); (5) computing the CAPEC-based likelihood estimates of each attack; (6) decomposing each attack into several severity aspects and assigning them weights; (7) assessing the magnitude of the impact of each of the severity aspects for each attack with the assistance of a panel of senior Medical Experts (MEs); (8) computing the composite severity assessments for each attack; and finally, (9) integrating the likelihood and severity of each attack into its risk, and thus prioritizing it. The details of steps six to eight are beyond the scope of the current study; in the current study, we had replaced them by a single step that included asking the panel of MEs [in this case, radiologists], to assess the overall severity for each attack and use it as its severity...

연구 동기 및 목표

  • 점점 더 연결된 의료 환경에서 의료 기기 전용 정보 보안 위험 평가 방법론의 부족을 해결하기 위해.
  • 의료 기기의 사이버 위험에 특화된 체계적이고 반복 가능하며 확장 가능한 방법론을 개발하기 위해.
  • CAPEC 기반의 확률 추정과 직접적인 전문가 평가를 비교하여 방법론의 정확성을 검증하기 위해.
  • 의료 전문가들이 검증된 데이터 기반의 위험 점수에 기반해 보안 노력을 우선순위 정리할 수 있도록 하기 위해.
  • 표준화된 공격 패턴 매핑을 통해 다양한 의료 기기 생태계에서의 위험 평가를 촉진하기 위해.

제안 방법

  • 의료 기기의 취약한 구성 요소를 식별하고, 중간급 의료 영상 장치 4종을 중심으로 분석한다.
  • 이러한 장치를 대상으로 하는 23개의 잠재적 사이버 공격를 목록화한다.
  • 각 공격를 CAPEC(Common Attack Pattern Enumeration and Classification) 온톨로지에 매핑하여 표준화된 분류를 수행한다.
  • CAPEC 기반 템플릿을 활용하여 고위험 의료 정보 보안 전문가(ISEs) 패널을 통해 공격 발생 가능성을 추정한다.
  • CAPEC 기반의 확률 추정과 고위험 의료 전문가(MEs) 패널이 평가한 심각도를 통합하여 복합 위험 점수를 산출한다.
  • 통합된 확률-심각도 점수에 기반해 위험을 우선순위 정리함으로써 실질적인 위험 관리가 가능하게 한다.

실험 결과

연구 질문

  • RQ1CAPEC 기반의 방법론은 의료 기기 사이버 공격에 대해 직접적인 전문가 평가와 동일한 유효성을 가진 확률 추정을 제공할 수 있는가?
  • RQ2CAPEC 기반의 확률 추정은 의료 정보 보안 전문가(ISEs)가 제공한 직접적인 확률 추정과 얼마나 높은 상관관계를 보이는가?
  • RQ3CAPEC 기반의 확률 추정과 직접적인 전문가 확률 추정 간에 통계적으로 유의미한 차이가 존재하는가?
  • RQ4TLDR 방법론은 의료 기기 보안 분야에서 위험 평가의 효율성과 일관성을 향상시킬 수 있는가?
  • RQ5공격를 CAPEC에 매핑함으로써 의료 기기 위험 평가의 확장성과 표준화는 어느 정도 향상되는가?

주요 결과

  • TLDR 방법론은 CAPEC 기반의 확률 추정과 직접적인 전문가 평가 간에 높은 스피어먼 순위 상관관계(rho > 0.8)를 달성하여 강력한 일관성을 보였다.
  • CAPEC 기반 추정과 직접적인 전문가 추정 간의 대응 t-검정에서 귀무가설을 기각하지 않았다(p > 0.05), 통계적으로 유의미한 차이가 없음을 확인했다.
  • CAPEC 기반 접근법은 직접적인 전문가 평가와 동일한 유효성을 가졌지만, 훨씬 적은 노력과 시간이 소요되었다.
  • 이 방법론은 의료 정보 보안 전문가들이 공격 발생 가능성을 공감대를 형성하면서도 위험 점수의 절대적 유효성을 유지할 수 있도록 했다.
  • 공격를 CAPEC에 매핑함으로써 여러 의료 기기와 생태계에 걸쳐 효율적이고 표준화되고 확장 가능한 위험 평가가 가능해졌다.
  • 심각도 평가를 전문가 패널이 수행하고, CAPEC 기반의 확률을 통합함으로써 신뢰할 수 있는 복합 위험 점수를 도출할 수 있었으며, 이는 우선순위 설정에 적합하였다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.