Kim Gunhee, Kim Dohyun, Seo Jeonghun, Lee Seyoung, Song Wonjun
Department of Convergence Security, Kangwon National University, 1 Kangwondaehak-gil, Chuncheon-si 24341, Republic of Korea.
Department of Computer and Information Engineering, Catholic University of Pusan, Busan 46252, Republic of Korea.
Sensors (Basel). 2024 Nov 22;24(23):7470. doi: 10.3390/s24237470.
In the medical domain, computer systems in digital healthcare have increased connectivity continuously and the Message Service Element (DIMSE) protocol has a critical role in exchanging biomedical imaging data among different digital healthcare systems. As the data communication technology is used to handle sensitive information such as patient information (e.g., patient's name, date of birth, and address) and medical images (e.g., ultrasound, X-ray, and MRI), it has emerged as a major target for security attacks. In this work, we study security concerns on the message exchange method used in the protocol. It is important to know which services are available on a given healthcare IT system to an adversary and we observe that the protocol can be implemented in various ways across products, with each supporting different services as well. We present , a framework for discerning services on remote medical devices. To show the effectiveness of , we evaluate our framework on multiple implementations, including commercial products and libraries, and identify the supported services of them. We demonstrate that successfully identifies medical services that are supported differently across 22 healthcare IT systems in a remote environment.
在医学领域,数字医疗中的计算机系统的连接性不断增强,消息服务元素(DIMSE)协议在不同数字医疗系统之间交换生物医学成像数据方面起着关键作用。由于数据通信技术用于处理诸如患者信息(例如患者姓名、出生日期和地址)和医学图像(例如超声、X射线和磁共振成像)等敏感信息,它已成为安全攻击的主要目标。在这项工作中,我们研究了该协议中使用的消息交换方法的安全问题。了解给定医疗信息技术系统上对手可获得哪些服务很重要,并且我们观察到该协议可以在不同产品中以各种方式实现,每个产品支持的服务也不同。我们提出了一个用于识别远程医疗设备上的服务的框架。为了展示该框架的有效性,我们在多个实现上评估我们的框架,包括商业产品和库,并确定它们支持的服务。我们证明,该框架成功识别了远程环境中22个医疗信息技术系统中支持方式不同的医疗服务。