Abstract
Most medical devices in the healthcare system are not built-in security concepts. Hence, these devices' built-in vulnerabilities prone them to various cyber-attacks when connected to a hospital network or cloud. Attackers can penetrate devices, tamper, and disrupt services in hospitals and clinics, which results in threatening patients' health and life. A specialist can Manage Cyber-attacks risks by reducing the system's attack surface. Attack surface analysis, either as a potential source for exploiting a potential vulnerability by attackers or as a medium to reduce cyber-attacks play a significant role in mitigating risks. Furthermore, it is necessitated to perform attack surface analysis in the design phase. This research proposes a framework that integrates attack surface concepts into the design and development of medical devices. Devices are classified as high-risk, medium-risk, and low-risk. After risk assessment, the employed classification algorithm detects and analyzes the attack surfaces. Accordingly, the relevant adapted security controls will be prompted to hinder the attack. The simulation and evaluation of the framework is the subject of further research.
Original language | English |
---|---|
Pages (from-to) | 1289-1298 |
Number of pages | 10 |
Journal | International Journal of Computing and Digital Systems |
Volume | 11 |
Issue number | 1 |
Early online date | 25 Jul 2021 |
DOIs | |
Publication status | Published - 15 Apr 2022 |
Keywords
- Attack surface
- Networked medial device
- Risk assessment
- Internet of Things
- Cyber-attack