School of IT, Deakin University, Melbourne, VIC 3125, Australia.
BGD e-GOV CIRT, Bangladesh National CERT, ICT Division, Ministry of Post, Telecom and IT, Dhaka 1212, Bangladesh.
Sensors (Basel). 2024 Aug 15;24(16):5282. doi: 10.3390/s24165282.
This paper presents a comprehensive and evidence-based cyber-risk assessment approach specifically designed for Medical Cyber Physical Systems (MCPS)- and Internet-of-Medical Devices (IoMT)-based collaborative digital healthcare systems, which leverage Federated Identity Management (FIM) solutions to manage user identities within this complex environment. While these systems offer advantages like easy data collection and improved collaboration, they also introduce new security challenges due to the interconnected nature of devices and data, as well as vulnerabilities within the FIM and the lack of robust security in IoMT devices. To proactively safeguard the digital healthcare system from cyber attacks with potentially life-threatening consequences, a comprehensive and evidence-based cyber-risk assessment is crucial for mitigating these risks. To this end, this paper proposes a novel cyber-risk assessment approach that leverages a three-dimensional attack landscape analysis, encompassing existing IT infrastructure, medical devices, and Federated Identity Management protocols. By considering their interconnected vulnerabilities, the approach recommends tailored security controls to prioritize and mitigate critical risks, ultimately enhancing system resilience. The proposed approach combines established industry standards like Cyber Resilience Review (CRR) asset management and NIST SP 800-30 for a comprehensive assessment. We have validated our approach using threat modeling with attack trees and detailed attack sequence diagrams on a diverse range of IoMT and MCPS devices from various vendors. The resulting evidence-based cyber-risk assessments and corresponding security control recommendations will significantly support healthcare professionals and providers in improving both patient and medical device safety management within the FIM-enabled healthcare ecosystem.
本文提出了一种全面的、基于证据的网络风险评估方法,专门针对基于医疗网络物理系统(MCPS)和医疗物联网(IoMT)的协作数字医疗系统,这些系统利用联合身份管理(FIM)解决方案在复杂环境中管理用户身份。虽然这些系统具有易于数据收集和改进协作等优势,但由于设备和数据的互联性质,以及 FIM 中的漏洞和 IoMT 设备中缺乏强大的安全性,它们也带来了新的安全挑战。为了主动防范可能危及生命的网络攻击,必须对数字医疗系统进行全面的、基于证据的网络风险评估,以减轻这些风险。为此,本文提出了一种新的网络风险评估方法,该方法利用三维攻击场景分析,涵盖现有的 IT 基础设施、医疗设备和联合身份管理协议。通过考虑它们的互联漏洞,该方法建议采用量身定制的安全控制措施来优先考虑和减轻关键风险,最终提高系统的弹性。该方法结合了 Cyber Resilience Review(CRR)资产管理等成熟的行业标准和 NIST SP 800-30 进行全面评估。我们已经使用威胁建模和攻击树对来自不同供应商的各种 IoMT 和 MCPS 设备进行了详细的攻击序列图,验证了我们的方法。基于证据的网络风险评估和相应的安全控制建议将极大地支持医疗保健专业人员和提供者,提高 FIM 支持的医疗生态系统中患者和医疗设备的安全管理。