• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

医疗器械采购的国家卫生服务的网络安全漏洞分析。

Cybersecurity vulnerability analysis of medical devices purchased by national health services.

机构信息

Department of Electronic Engineering, University of Rome Tor Vergata, Rome, Italy.

CNIT, National Inter-University Consortium for Telecommunication, Parma, Italy.

出版信息

Sci Rep. 2023 Nov 9;13(1):19509. doi: 10.1038/s41598-023-45927-1.

DOI:10.1038/s41598-023-45927-1
PMID:37945583
原文链接:https://pmc.ncbi.nlm.nih.gov/articles/PMC10636100/
Abstract

The growing integration of software within medical devices introduces the potential for cybersecurity threats. How significant is this risk, and to what extent are citizens currently exposed? In this study, we adopt a new data-gathering methodology using datasets provided in Open Contracting Data Standard (OCDS). This allowed us to perform an extensive analysis across over 36 countries within a 12-year range, searching 92 million public administration purchase records for potentially vulnerable medical devices. The findings reveal a concerning landscape wherein numerous medical devices purchased by national health services possessed or still possess 661 distinct vulnerabilities-more than half of which are deemed critical or high-severity. These vulnerabilities enable relatively simple attacks to impact data confidentiality, integrity, and accessibility severely. Even if patches were applied immediately upon discovery, these vulnerabilities would still result in roughly 3.2 years of system exposure from the time a device is purchased until a software vulnerability is announced, with all classes of devices affected, including high-risk IIB and III devices which accounts for 74% of instances. While a full analysis requires interactivity, this noninvasive methodology enables a large-scale study, emphasizing the need to move faster from the safety to the security of medical devices.

摘要

软件在医疗器械中的日益融合带来了网络安全威胁的可能性。这种风险有多大,公民目前受到多大程度的影响?在这项研究中,我们采用了一种新的数据收集方法,使用开放合同数据标准(OCDS)提供的数据集。这使我们能够在 12 年的时间跨度内对 36 个以上的国家进行广泛分析,在 9200 万条公共行政采购记录中搜索可能存在漏洞的医疗器械。研究结果显示出令人担忧的局面,许多国家卫生服务机构购买的医疗器械存在或仍然存在 661 个不同的漏洞——其中一半以上被认为是严重或高严重程度的漏洞。这些漏洞使得相对简单的攻击能够严重影响数据的保密性、完整性和可访问性。即使在发现后立即应用补丁,这些漏洞仍将导致设备从购买到宣布软件漏洞期间系统暴露约 3.2 年,所有类别的设备都受到影响,包括占 74%的高风险 IIB 和 III 类设备。虽然全面分析需要交互性,但这种非侵入性方法可以进行大规模研究,强调需要更快地从医疗器械的安全性转向安全性。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1588/10636100/66bfded4982f/41598_2023_45927_Fig5_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1588/10636100/ba242c8f1117/41598_2023_45927_Fig4_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1588/10636100/66bfded4982f/41598_2023_45927_Fig5_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1588/10636100/ba242c8f1117/41598_2023_45927_Fig4_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/1588/10636100/66bfded4982f/41598_2023_45927_Fig5_HTML.jpg

相似文献

1
Cybersecurity vulnerability analysis of medical devices purchased by national health services.医疗器械采购的国家卫生服务的网络安全漏洞分析。
Sci Rep. 2023 Nov 9;13(1):19509. doi: 10.1038/s41598-023-45927-1.
2
Security vulnerabilities in healthcare: an analysis of medical devices and software.医疗保健中的安全漏洞:医疗设备和软件分析。
Med Biol Eng Comput. 2024 Jan;62(1):257-273. doi: 10.1007/s11517-023-02912-0. Epub 2023 Oct 4.
3
Cardiac implantable electronic devices and cybersecurity.心脏植入式电子设备与网络信息安全。
Expert Rev Med Devices. 2021 Dec;18(sup1):69-77. doi: 10.1080/17434440.2021.2007075. Epub 2021 Nov 22.
4
Cybersecurity features of digital medical devices: an analysis of FDA product summaries.数字医疗设备的网络安全特性:对 FDA 产品摘要的分析。
BMJ Open. 2019 Jun 28;9(6):e025374. doi: 10.1136/bmjopen-2018-025374.
5
Influence of Human Factors on Cyber Security within Healthcare Organisations: A Systematic Review.人为因素对医疗机构网络安全的影响:系统综述。
Sensors (Basel). 2021 Jul 28;21(15):5119. doi: 10.3390/s21155119.
6
Cybersecurity for Connected Diabetes Devices.联网糖尿病设备的网络安全
J Diabetes Sci Technol. 2015 Apr 16;9(5):1143-7. doi: 10.1177/1932296815583334.
7
Cybersecurity in Science and Medicine: Threats and Challenges.科学与医学中的网络安全:威胁与挑战。
Trends Biotechnol. 2020 Aug;38(8):825-828. doi: 10.1016/j.tibtech.2020.02.010. Epub 2020 Mar 18.
8
Cybersecurity in healthcare: A narrative review of trends, threats and ways forward.医疗保健中的网络安全:趋势、威胁及未来发展方向的叙述性综述。
Maturitas. 2018 Jul;113:48-52. doi: 10.1016/j.maturitas.2018.04.008. Epub 2018 Apr 22.
9
A Data Taxonomy for Adaptive Multifactor Authentication in the Internet of Health Care Things.面向医疗物联网自适应多因素认证的数据分类法。
J Med Internet Res. 2023 Aug 29;25:e44114. doi: 10.2196/44114.
10
Cybersecurity Awareness and Training (CAT) Framework for Remote Working Employees.远程工作员工的网络安全意识和培训 (CAT) 框架。
Sensors (Basel). 2022 Nov 9;22(22):8663. doi: 10.3390/s22228663.

引用本文的文献

1
Cybersecurity requirements for medical devices in the EU and US - A comparison and gap analysis of the MDCG 2019-16 and FDA premarket cybersecurity guidance.欧盟和美国医疗设备的网络安全要求——MDCG 2019-16与美国食品药品监督管理局上市前网络安全指南的比较及差距分析
Comput Struct Biotechnol J. 2025 Jul 15;28:259-266. doi: 10.1016/j.csbj.2025.07.024. eCollection 2025.
2
Recent Optical Coherence Tomography (OCT) Innovations for Increased Accessibility and Remote Surveillance.近期用于提高可及性和远程监测的光学相干断层扫描(OCT)创新技术。
Bioengineering (Basel). 2025 Apr 23;12(5):441. doi: 10.3390/bioengineering12050441.
3

本文引用的文献

1
ANSI/AAMI SW96: Raising the Bar for Medical Device Security Risk Management.美国国家标准学会/美国医疗器械促进协会SW96:提升医疗设备安全风险管理标准
Biomed Instrum Technol. 2023;57(2):40-43. doi: 10.2345/0899-8205-57.2.40. Epub 2023 May 2.
2
Bluetooth Wireless Technology Cybersecurity and Diabetes Technology Devices.蓝牙无线技术的网络安全和糖尿病技术设备。
J Diabetes Sci Technol. 2020 Nov;14(6):1111-1115. doi: 10.1177/1932296819864416. Epub 2019 Jul 18.
3
Cybersecurity features of digital medical devices: an analysis of FDA product summaries.
Consideration of Cybersecurity Risks in the Benefit-Risk Analysis of Medical Devices: Scoping Review.
医疗设备获益-风险分析中的网络安全风险考量:范围综述
J Med Internet Res. 2024 Dec 24;26:e65528. doi: 10.2196/65528.
4
Uptake of Digital Health Interventions for Cardiometabolic Disease in British South Asian Individuals: Think Aloud Study.英国南亚个体对心血管代谢疾病数字健康干预措施的接受度:出声思维研究。
JMIR Hum Factors. 2024 Oct 24;11:e57338. doi: 10.2196/57338.
5
Transformative Frontiers: A Comprehensive Review of Emerging Technologies in Modern Healthcare.变革性前沿:现代医疗保健中新兴技术的全面综述
Cureus. 2024 Mar 20;16(3):e56538. doi: 10.7759/cureus.56538. eCollection 2024 Mar.
数字医疗设备的网络安全特性:对 FDA 产品摘要的分析。
BMJ Open. 2019 Jun 28;9(6):e025374. doi: 10.1136/bmjopen-2018-025374.
4
Standards for Medical Device Cybersecurity in 2018.2018年医疗设备网络安全标准。
J Diabetes Sci Technol. 2018 Jul;12(4):743-746. doi: 10.1177/1932296818763634. Epub 2018 Mar 24.
5
The Evolving State of Medical Device Cybersecurity.医疗设备网络安全的发展现状
Biomed Instrum Technol. 2018 Mar/Apr;52(2):103-111. doi: 10.2345/0899-8205-52.2.103.
6
Cybersecurity vulnerabilities in medical devices: a complex environment and multifaceted problem.医疗设备中的网络安全漏洞:一个复杂的环境和多方面的问题。
Med Devices (Auckl). 2015 Jul 20;8:305-16. doi: 10.2147/MDER.S50048. eCollection 2015.
7
Controlling for cybersecurity risks of medical device software.控制医疗设备软件的网络安全风险。
Biomed Instrum Technol. 2014 Spring;Suppl:38-41. doi: 10.2345/0899-8205-48.s1.38.