[论文解读] Know Your Enemy: Characteristics of Cyber-Attacks on Medical Imaging Devices
本研究利用CIA(机密性、完整性、可用性)框架,识别出针对医学影像设备(尤其是CT扫描仪)的关键网络攻击向量。通过与一家主要医疗组织合作开展的风险分析调查,作者发现由于CT设备在急症护理中的关键作用,其面临最高风险,攻击面包括协议参数操纵、机械干扰、信号干扰以及拒绝服务攻击。
Purpose: Used extensively in the diagnosis, treatment, and prevention of disease, Medical Imaging Devices (MIDs), such as Magnetic Resonance Imaging (MRI) or Computed Tomography (CT) machines, play an important role in medicine today. MIDs are increasingly connected to hospital networks, making them vulnerable to sophisticated cyber-attacks targeting the devices' infrastructure and components, which can disrupt digital patient records, and potentially jeopardize patients' health. Attacks on MIDs are likely to increase, as attackers' skills improve and the number of unpatched devices with known vulnerabilities that can be easily exploited grows. Attackers may also block access to MIDs or disable them, as part of ransomware attacks, which have been shown to be successful against hospitals. Method and Materials: We conducted a comprehensive risk analysis survey at the Malware-Lab, based on the Confidentiality, Integrity, and Availability (CIA) model, in collaboration with our country's largest health maintenance organization, to define the characteristics of cyber-attacks on MIDs. The survey includes a range of vulnerabilities and potential attacks aimed at MIDs, medical and imaging information systems, and medical protocols and standards such as DICOM and HL7. Results: Based on our survey, we found that CT devices face the greatest risk of cyber-attack, due to their pivotal role in acute care imaging. Thus, we identified several possible attack vectors that target the infrastructure and functionality of CT devices, which can cause: 1. Disruption of the parameters' values used in the scanning protocols within the CT devices (e.g., tampering with the radiation exposure levels); 2. Mechanical disruption of the CT device (e.g., changing the pitch); 3. Disruption of the tomography scan signals constructing the digital images; and 4. Denial-of-Service attacks against the CT device.
研究动机与目标
- 评估医院网络中针对医学影像设备(MIDs)的日益增长的网络威胁态势。
- 识别破坏CT和MRI系统机密性、完整性和可用性的具体攻击向量。
- 评估广泛使用的医学影像协议(如DICOM和HL7)中未修补漏洞所造成的现实世界风险。
- 为医疗保健提供方和网络安全专业人员提供关于保护医学影像基础设施的可操作见解。
- 提高对勒索软件和功能破坏性攻击可能对关键影像系统造成影响的认识。
提出的方法
- 使用CIA三元组模型对医学影像设备的网络威胁进行全面风险分析。
- 与以色列最大的医疗保障组织合作,评估临床影像环境中实际存在的漏洞。
- 将医学影像协议(DICOM、HL7)和设备固件中的已知漏洞映射到潜在攻击场景。
- 模拟并分析针对CT设备配置、机械参数和图像信号完整性的攻击向量。
- 评估对CT系统发起拒绝服务(DoS)攻击的可行性及其对患者护理的潜在影响。
- 根据对患者安全、数据完整性和系统可用性的影响,对攻击类型进行分类。
实验结果
研究问题
- RQ1针对医学影像设备(尤其是CT扫描仪)的主要网络攻击向量是什么?
- RQ2DICOM和HL7协议中的漏洞如何增加影像系统遭受网络攻击的风险?
- RQ3由于其临床角色和网络暴露程度,哪些影像设备类型面临最高被利用风险?
- RQ4操纵扫描参数(如辐射剂量)对患者安全和图像质量可能产生何种影响?
- RQ5拒绝服务或信号干扰攻击在多大程度上可使CT系统失效并扰乱急诊护理?
主要发现
- 由于CT设备在急症护理影像中的关键作用及其高网络连通性,其面临最高的网络攻击风险。
- 攻击者可操纵扫描协议参数(如辐射暴露水平),导致潜在患者伤害。
- CT扫描仪中的机械参数(如螺距)可被篡改,影响图像质量和诊断准确性。
- 断层扫描信号的干扰可导致数字图像损坏,引发误诊或治疗延迟。
- 对CT设备的拒绝服务攻击可阻断影像服务访问,其行为类似于勒索软件,扰乱急诊护理。
- 大量医学影像设备仍处于未修补状态,增加了已知可利用漏洞的攻击面。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。