Dynamic risk assessment approach for analysing cyber security events in medical IoT networks

被引:0
|
作者
Czekster, Ricardo M. [1 ]
Webber, Thais [1 ]
Furstenau, Leonardo Bertolin [2 ]
Marcon, Cesar [3 ]
机构
[1] Aston Univ, Sch Comp Sci & Digital Technol, Aston St, Birmingham B4 7ET, England
[2] Univ Fed Rio Grande do Sul, Grad Program Ind Engn, UFRGS, BR-90035190 Porto Alegre, Brazil
[3] PUCRS Univ, Grad Program Comp Sci PPGCC, Ave Ipiranga 6681, BR-90619900 Porto Alegre, RS, Brazil
关键词
Medical Internet of Things (MIoT); Cyber security; Dynamic risk assessment; Simulation models; Data integration; Threat analysis; INTERNET; THINGS; ENVIRONMENT; CHALLENGES; DEVICES; ATTACK;
D O I
10.1016/j.iot.2024.101437
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Advancements in Medical Internet of Things (MIoT) technology ease remote health monitoring and effective management of medical devices. However, these developments also expose systems to novel cyber security risks as sophisticated threat actors exploit infrastructure vulnerabilities to access sensitive data or deploy malicious software, threatening patient safety, device reliability, and trust. This paper introduces a lightweight dynamic risk assessment approach using scenario-based simulations to analyse cyber security events in MIoT infrastructures and supplement cyber security activities within organisations. The approach includes synthetic data and threat models to enrich discrete-event simulations, offering a comprehensive understanding of emerging threats and their potential impact on healthcare settings. Our simulation scenario illustrates the model's behaviour in processing data flows and capturing the characteristics of healthcare settings. Our findings demonstrate its validity by highlighting potential threats and mitigation strategies. The insights from these simulations highlight the model's flexibility, enabling adaptation to various healthcare settings and supporting continuous risk assessment to enhance MIoT system security and resilience.
引用
收藏
页数:17
相关论文
共 50 条
  • [1] Cyber security risk assessment for SCADA and DCS networks
    Ralston, P. A. S.
    Graham, J. H.
    Hieb, J. L.
    ISA TRANSACTIONS, 2007, 46 (04) : 583 - 594
  • [2] Cyber Security Risk Modelling and Assessment: A Quantitative Approach
    Sokri, Abderrahmane
    PROCEEDINGS OF THE 18TH EUROPEAN CONFERENCE ON CYBER WARFARE AND SECURITY (ECCWS 2019), 2019, : 466 - 474
  • [3] AI security and cyber risk in IoT systems
    Radanliev, Petar
    De Roure, David
    Maple, Carsten
    Nurse, Jason R. C.
    Nicolescu, Razvan
    Ani, Uchenna
    FRONTIERS IN BIG DATA, 2024, 7
  • [4] Stateless Security Risk Assessment for Dynamic Networks
    Hong, Jin B.
    Yusuf, Simon Enoch
    Kim, Dong Seong
    Khan, Khaled M. D.
    2018 48TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS WORKSHOPS (DSN-W), 2018, : 65 - 66
  • [5] Deep Learning Models for Cyber Security in IoT Networks
    Roopak, Monika
    Tian, Gui Yun
    Chambers, Jonathon
    2019 IEEE 9TH ANNUAL COMPUTING AND COMMUNICATION WORKSHOP AND CONFERENCE (CCWC), 2019, : 452 - 457
  • [6] Biologically Inspired Risk Assessment in Cyber Security using Neural Networks
    Mihai-Gabriel, Ionita
    Patriciu, Victor-Valeriu
    2014 10TH INTERNATIONAL CONFERENCE ON COMMUNICATIONS (COMM), 2014,
  • [7] Layered management approach to cyber security of IoT solutions
    Ozdogan, Erdal
    Das, Resul
    INTERNATIONAL JOURNAL OF GRID AND UTILITY COMPUTING, 2023, 14 (05) : 493 - 504
  • [8] Risk Assessment for Cyber Security of Manufacturing Systems: A Game Theory Approach
    Zarreha, Alireza
    Wan, HungDa
    Lee, Looneun
    Saygin, Can
    Al Janahi, Rafid
    29TH INTERNATIONAL CONFERENCE ON FLEXIBLE AUTOMATION AND INTELLIGENT MANUFACTURING (FAIM 2019): BEYOND INDUSTRY 4.0: INDUSTRIAL ADVANCES, ENGINEERING EDUCATION AND INTELLIGENT MANUFACTURING, 2019, 38 : 605 - 612
  • [9] A Model-Based Approach for Aviation Cyber Security Risk Assessment
    Kiesling, Tobias
    Niederl, Josef
    Ziegler, Juergen
    Krempel, Matias
    PROCEEDINGS OF 2016 11TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, (ARES 2016), 2016, : 517 - 525
  • [10] Asset-Driven Approach for Security Risk Assessment in IoT Systems
    Chehida, Salim
    Baouya, Abdelhakim
    Alonso, Diego Fernandez
    Brun, Paul-Emmanuel
    Massot, Guillemette
    Bozga, Marius
    Bensalem, Saddek
    RISKS AND SECURITY OF INTERNET AND SYSTEMS (CRISIS 2020), 2021, 12528 : 149 - 163