Skip to main content
QUICK REVIEW

[论文解读] A Survey on Security and Privacy Issues in Modern Healthcare Systems: Attacks and Defenses

Akm Iqridar Newaz, Amit Kumar Sikder|arXiv (Cornell University)|May 15, 2020
Wireless Body Area Networks参考文献 187被引用 62
一句话总结

本综述分析了现代医疗系统中的安全与隐私威胁,对攻击进行分类,并评估现有防御措施与未来研究方向。

ABSTRACT

The recent advancements in computing systems and wireless communications have made healthcare systems more efficient than before. Modern healthcare devices can monitor and manage different health conditions of the patients automatically without any manual intervention from medical professionals. Additionally, the use of implantable medical devices (IMDs), body area networks (BANs), and Internet of Things (IoT) technologies in healthcare systems improve the overall patient monitoring and treatment process. However, these systems are complex in software and hardware, and optimizing between security, privacy, and treatment is crucial for healthcare systems as any security or privacy violation can lead to severe effects on patients' treatments and overall health conditions. Indeed, the healthcare domain is increasingly facing security challenges and threats due to numerous design flaws and the lack of proper security measures in healthcare devices and applications. In this paper, we explore various security and privacy threats to healthcare systems and discuss the consequences of these threats. We present a detailed survey of different potential attacks and discuss their impacts. Furthermore, we review the existing security measures proposed for healthcare systems and discuss their limitations. Finally, we conclude the paper with future research directions toward securing healthcare systems against common vulnerabilities.

研究动机与目标

  • 提供对典型医疗系统及其组成部分的详细概述。
  • 识别医疗环境中的安全与隐私目标及对抗者模型。
  • 给出医疗系统攻击的分类法,并使用 CVSS 指标评估其影响。
  • 总结现有防御机制并突出局限性与未解决的挑战。
  • 提出未来的研究方向,以缓解医疗系统中的常见漏洞。

提出的方法

  • 描述具有五个组成部分的典型医疗系统架构(医疗设备、传感器、网络、数据处理和医疗提供者)。
  • 定义安全与隐私目标,包括认证、保密性、完整性、不可否认性、可用性,以及各种匿名性属性。
  • 构建正式攻击模型,对攻击者目标、能力和攻击类型进行分类(被动/主动、硬件/软件威胁、旁路、等)。
  • 对医疗设备和应用中报告的攻击进行调查和分类,并基于 CVSS 指标进行影响评估。
  • 评估为医疗系统提出的现有安全与隐私防御并讨论其局限性。
  • 概述确保医疗系统安全的开放挑战与未来方向。

实验结果

研究问题

  • RQ1现代医疗系统的主要组成部分与架构及其安全/隐私影响是什么?
  • RQ2主要的安全与隐私目标是什么,以及如何在医疗环境中实现它们?
  • RQ3针对医疗设备与网络观察到的攻击有哪些,按 CVSS 的影响程度有多严重?
  • RQ4针对这些攻击存在哪些防御,尚存那些需要解决的空白?
  • RQ5哪些未来研究方向可以填补医疗系统中识别出的安全与隐私空缺?

主要发现

  • 本文提出了三层医疗系统架构(医疗设备、个人设备、健康服务器/提供者),并讨论认证、保密性、完整性、不可否认性、可用性以及隐私要求。
  • 提供正式的攻击模型,详细描述攻击者目标(硬件修改、不可用、数据窃听/修改、信息泄露)及能力(物理/远程访问、协议知识、第三方设备)。
  • 提供攻击分类法,包括硬件木马、恶意软件、勒索软件、系统过时、伪造固件、弱认证、权限提升、旁路和欺骗威胁,并基于 CVSS 的影响评估。
  • 该综述指出当前防御的局限性,强调隐私保护通信、加密数据库,以及需要在整个医疗生态系统中实现更广泛的端到端安全解决方案。
  • 未来方向强调全面的端到端安全、标准化、持续认证,以及在设备、网络和提供者之间实现强大的隐私保护机制。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。