A few months ago, the FDA released a set of recommendations for managing cybersecurity in healthcare devices. While it doesn't exactly seem to contain a lot of groundbreaking cybersecurity principles (it discusses risk management, patching, identifying exploits, threats, and vulnerabilities, etc. etc.), it is significant that even big cogs of the federal government are finally turning to address Internet of Things security.
Since the government thinks medical devices deserve cybersecurity, let's look at some examples of healthcare IoT insecurity, shall we?
- Perhaps the most well-known example of insecure healthcare IoT is pacemakers. Last year, a research firm released a report detailing how St. Jude pacemakers can be "easily compromised". These findings were apparently replicated by another security firm, and it was discovered that St. Jude had been aware of these vulnerabilities for a few years but did little to address them. Although St. Jude's pacemakers were shown to be flawed, there has been a larger trend in the pacemaker market in general to be shown insecure to remote attackers. One security researcher stated he could wirelessly connect to a pacemaker with a laptop and make the pacemaker deliver an 830 volt shock. Even Dick Cheny's pacemaker was potentially at risk from hackers, and his doctor recommended disabling its wireless to prevent a hacker from causing damage to the VP.
- Drug infusion pumps are also vulnerable. One security researcher's analysis discovered that at least one pump model included checks that prevented dangerously high levels of drugs to be administered, but that these checks could be easily bypassed and manipulated. It also included a hardcoded, plaintext password for a database and hardcoded crypto keys.
- Other machines include CT machines and blood refrigeration units. Some blood refrigeration units allow remote monitoring and adjusting of temperatures, and alerts about serious changes in temperature can be sent over the network to hospital staff. However, security researchers discovered this system was protected by a hardcoded password and that the refrigeration units' alert functionality could be disabled and the temperatures adjusted to hazardous levels. A set of researchers also discovered that CT machines' configuration files could be remotely adjusted and the amount of radiation given to a patient could be modified. For obvious reasons, manipulating the temperature of stored blood as well as adjusting radiation levels are cybersecurity risks that need to be addressed.
Considering the insecurities discovered in healthcare IoT, it seems that the FDA did the right thing in stepping up and implementing security controls. The problems facing healthcare are much the same as normal IoT (which has been examined in previous posts). In short, people design pacemakers to do the job of a pacemaker, and the digital aspects are just a 'necessary evil' included to make it work. We struggle to keep standard, dedicated computers secured today; why should we expect anything different from IoT? However, a line needs to be drawn with more critical IoT devices--like those in health care. If Windows is hacked, it's highly unlikely its user will die; this is not true if a CT machine or pacemaker is the target of the hacker.
No comments:
Post a Comment