Understanding and Mitigating Security Risks of Network on Medical Cyber Physical System

被引:0
|
作者
Li, Zhangtan [1 ,2 ]
Cheng, Liang [2 ]
Zhang, Yang [2 ]
Feng, Dengguo [2 ]
机构
[1] Univ Chinese Acad Sci, Beijing, Peoples R China
[2] Chinese Acad Sci, Inst Software, TCA Lab, Beijing, Peoples R China
基金
国家重点研发计划;
关键词
Medical Cyber Physical System; Publish-subscribe; Network security; Access control;
D O I
10.1007/978-3-030-86130-8_10
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Medical Cyber-Physical System (MCPS) holds the promise of reducing human errors and optimizing healthcare by integrating medical devices, applications and network. MCPS utilizes high-level supervisory and low-level communication middleware to enable medical devices to interoperate efficiently. Despite the benefits provided by MCPS, the integration of clinical information also brings new threats for the clinical data. In this paper, we performed a study on security and safety risks in MCPS's networks. We systematically analyzed different attack surfaces on MCPS's networks based on misuse and abuse of clinical data. We successfully performed end-to-end attacks based on OpenICE, a popular MCPS prototype, and demonstrated the clinical risks of these attacks and the design flaws in OpenICE. We further proposed a Topic-based access control model with Break-The-Glass feature to provide fine-grained access control for clinical data. We implemented the model in two MCPS prototypes, and evaluated its effectiveness and efficiency.
引用
收藏
页码:123 / 134
页数:12
相关论文
共 50 条
  • [41] Mitigating Security Threats through the use of Security Tactics to Design Secure Cyber-Physical Systems (CPS)
    Orellana, Cristian
    Villegas, Monica M.
    Astudillo, Hernan
    13TH EUROPEAN CONFERENCE ON SOFTWARE ARCHITECTURE (ECSA 2019), VOL 2, 2019, : 109 - 115
  • [42] An Integrated Cyber Security Risk Management Approach for a Cyber-Physical System
    Kure, Halima Ibrahim
    Islam, Shareeful
    Razzaque, Mohammad Abdur
    APPLIED SCIENCES-BASEL, 2018, 8 (06):
  • [43] Mitigating risks of perishable products in the cyber-physical systems based on the extended MRP model
    Bogataj, David
    Bogataj, Marija
    Hudoklin, Domen
    INTERNATIONAL JOURNAL OF PRODUCTION ECONOMICS, 2017, 193 : 51 - 62
  • [44] Application of Machine Learning in Cyber Security of Cyber-Physical Power System
    Peng, Sha
    Sun, Mingyang
    Zhang, Zhenyong
    Deng, Ruilong
    Cheng, Peng
    Dianli Xitong Zidonghua/Automation of Electric Power Systems, 2022, 46 (09): : 200 - 215
  • [45] A survey of the security assessment and security defense of a cyber physical power system under cyber failure threat
    Zhu B.
    Guo Y.
    Guo C.
    Jiang Z.
    Zhang X.
    Yuan X.
    Dianli Xitong Baohu yu Kongzhi/Power System Protection and Control, 2021, 49 (01): : 178 - 187
  • [46] Design of Communication Network for Cyber Physical System
    Samant, Raj
    Agrawal, Ayush
    Behera, Laxmidhar
    PROCEEDINGS OF THE 2015 39TH NATIONAL SYSTEMS CONFERENCE (NSC), 2015,
  • [47] Stabilization of a Cyber Physical System with Network issues
    El Abbadi, Reda
    Hicham, Jamouli
    2019 8TH INTERNATIONAL CONFERENCE ON SYSTEMS AND CONTROL (ICSC'19), 2019, : 508 - 512
  • [48] Mitigating Cyber Threats at the Network Edge
    Sofoluwe, Toyin
    Tso, Fung Po
    Phillips, Iain
    PROCEEDINGS OF THE 2022 22ND ACM INTERNET MEASUREMENT CONFERENCE, IMC 2022, 2022, : 776 - 777
  • [49] CYBER-SECURITY RISKS OF FEDWIRE
    Bilger, Mark J.
    JOURNAL OF DIGITAL FORENSICS SECURITY AND LAW, 2019, 14 (04)
  • [50] A Robust Approach for Mitigating Risks in Cyber Supply Chains
    Zheng, Kaiyue
    Albert, Laura A.
    RISK ANALYSIS, 2019, 39 (09) : 2076 - 2092