Understanding and Mitigating Security Risks of Network on Medical Cyber Physical System

被引:0
|
作者
Li, Zhangtan [1 ,2 ]
Cheng, Liang [2 ]
Zhang, Yang [2 ]
Feng, Dengguo [2 ]
机构
[1] Univ Chinese Acad Sci, Beijing, Peoples R China
[2] Chinese Acad Sci, Inst Software, TCA Lab, Beijing, Peoples R China
基金
国家重点研发计划;
关键词
Medical Cyber Physical System; Publish-subscribe; Network security; Access control;
D O I
10.1007/978-3-030-86130-8_10
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Medical Cyber-Physical System (MCPS) holds the promise of reducing human errors and optimizing healthcare by integrating medical devices, applications and network. MCPS utilizes high-level supervisory and low-level communication middleware to enable medical devices to interoperate efficiently. Despite the benefits provided by MCPS, the integration of clinical information also brings new threats for the clinical data. In this paper, we performed a study on security and safety risks in MCPS's networks. We systematically analyzed different attack surfaces on MCPS's networks based on misuse and abuse of clinical data. We successfully performed end-to-end attacks based on OpenICE, a popular MCPS prototype, and demonstrated the clinical risks of these attacks and the design flaws in OpenICE. We further proposed a Topic-based access control model with Break-The-Glass feature to provide fine-grained access control for clinical data. We implemented the model in two MCPS prototypes, and evaluated its effectiveness and efficiency.
引用
收藏
页码:123 / 134
页数:12
相关论文
共 50 条
  • [21] Security Challenges & Controls in Cyber Physical System
    Rathi, Rajat
    Sharma, Nikhil
    Manchanda, Chinkit
    Bhushan, Bharat
    Grover, Moksh
    2020 IEEE 9TH INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS AND NETWORK TECHNOLOGIES (CSNT 2020), 2020, : 242 - 247
  • [22] Cyber, Physical, and System Security for Smart Grid
    Ren, Kui
    Li, Zuyi
    Qiu, Robert Caiming
    IEEE TRANSACTIONS ON SMART GRID, 2011, 2 (04) : 643 - 644
  • [23] Boosting Cyber-Physical System Security
    Kutzler, Tobias
    Wolter, Alexandra
    Kenner, Andy
    Dassow, Stephan
    IFAC PAPERSONLINE, 2021, 54 (01): : 976 - 981
  • [24] Security Analysis of Cyber-Physical System
    Li, Bo
    Zhang, Lichen
    MATERIALS SCIENCE, ENERGY TECHNOLOGY, AND POWER ENGINEERING I, 2017, 1839
  • [25] An approach to risks in cyber physical systems based on information security psychology
    Fukuzawa, Yasuko
    Samejima, Masaki
    IEEJ Transactions on Electronics, Information and Systems, 2014, 134 (06) : 756 - 759
  • [26] Security risks in cyber physical systems-A systematic mapping study
    Zahid, Maryam
    Inayat, Irum
    Daneva, Maya
    Mehmood, Zahid
    JOURNAL OF SOFTWARE-EVOLUTION AND PROCESS, 2021, 33 (09)
  • [27] The Application of Computer Intelligence in the Cyber-Physical Business System Integration in Network Security
    Lin, Shi
    Yang, Ma
    Lu, Yan
    Chen, Liquan
    COMPUTATIONAL INTELLIGENCE AND NEUROSCIENCE, 2022, 2022
  • [28] Evaluation of a Cyber Security System for Hospital Network
    Faysel, Mohammad A.
    MEDINFO 2015: EHEALTH-ENABLED HEALTH, 2015, 216 : 915 - 915
  • [30] Towards Diagnosing and Mitigating Behavioral Cyber Risks
    Pugnetti, Carlo
    Bjorck, Albena
    Schonauer, Reto
    Casian, Carlos
    RISKS, 2024, 12 (07)