Suppr超能文献

医学影像 PACS 的网络安全挑战

Cybersecurity Challenges for PACS and Medical Imaging.

机构信息

OFFIS-Institute for Information Technology, R&D Department Health, Escherweg 2, Oldenburg 26121, Germany.

VISUS Health IT GmbH, Bochum, Germany.

出版信息

Acad Radiol. 2020 Aug;27(8):1126-1139. doi: 10.1016/j.acra.2020.03.026. Epub 2020 May 15.

Abstract

Cybersecurity issues have been on the rise for years, increasingly affecting the healthcare sector. In 2019, several attacks have been published that specifically aim at medical network protocols and file formats, in particular digital imaging and communications in medicine. This article describes five attack scenarios on picture archiving and communications systems (PACS) and medical imaging networks: the import of patient data from storage media containing malware, a compromise of the hospital network, malware embedded in digital imaging and communications in medicine images or reports, a malicious manipulation of medical images and a network infiltration of malicious health level seven messages. Prevention and mitigation measures for each of these attacks exist, some of which can be implemented by the system user (e.g., hospital), while others require implementation in the PACS and medical imaging devices by the vendors. In practice, however, many of these are not in common use. What is missing today are PACS network security guidelines for practitioners that support users in keeping their network secure. Furthermore, integrating the healthcare enterprise integration profiles and test tools might be needed to address the deployment of public key infrastructure and digital signatures in the PACS environment.

摘要

网络安全问题多年来一直呈上升趋势,越来越多地影响到医疗保健行业。2019 年,已经公布了一些特别针对医疗网络协议和文件格式的攻击,特别是医学数字成像和通信。本文描述了对影像归档和通信系统(PACS)和医学成像网络的五种攻击场景:从存储有恶意软件的存储介质中导入患者数据、医院网络被攻陷、数字成像和通信中的恶意软件嵌入图像或报告、恶意操纵医疗图像以及网络渗透恶意健康级别 7 消息。针对每种攻击都存在预防和缓解措施,其中一些可以由系统用户(例如医院)实施,而其他措施则需要供应商在 PACS 和医学成像设备中实施。然而,在实践中,这些措施并未得到广泛应用。目前缺少的是供从业者使用的 PACS 网络安全指南,以帮助用户确保网络安全。此外,可能需要集成医疗保健企业集成配置文件和测试工具,以解决在 PACS 环境中部署公钥基础设施和数字签名的问题。

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验