Dynamic risk assessment approach for analysing cyber security events in medical IoT networks

被引:0
|
作者
Czekster, Ricardo M. [1 ]
Webber, Thais [1 ]
Furstenau, Leonardo Bertolin [2 ]
Marcon, Cesar [3 ]
机构
[1] Aston Univ, Sch Comp Sci & Digital Technol, Aston St, Birmingham B4 7ET, England
[2] Univ Fed Rio Grande do Sul, Grad Program Ind Engn, UFRGS, BR-90035190 Porto Alegre, Brazil
[3] PUCRS Univ, Grad Program Comp Sci PPGCC, Ave Ipiranga 6681, BR-90619900 Porto Alegre, RS, Brazil
关键词
Medical Internet of Things (MIoT); Cyber security; Dynamic risk assessment; Simulation models; Data integration; Threat analysis; INTERNET; THINGS; ENVIRONMENT; CHALLENGES; DEVICES; ATTACK;
D O I
10.1016/j.iot.2024.101437
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Advancements in Medical Internet of Things (MIoT) technology ease remote health monitoring and effective management of medical devices. However, these developments also expose systems to novel cyber security risks as sophisticated threat actors exploit infrastructure vulnerabilities to access sensitive data or deploy malicious software, threatening patient safety, device reliability, and trust. This paper introduces a lightweight dynamic risk assessment approach using scenario-based simulations to analyse cyber security events in MIoT infrastructures and supplement cyber security activities within organisations. The approach includes synthetic data and threat models to enrich discrete-event simulations, offering a comprehensive understanding of emerging threats and their potential impact on healthcare settings. Our simulation scenario illustrates the model's behaviour in processing data flows and capturing the characteristics of healthcare settings. Our findings demonstrate its validity by highlighting potential threats and mitigation strategies. The insights from these simulations highlight the model's flexibility, enabling adaptation to various healthcare settings and supporting continuous risk assessment to enhance MIoT system security and resilience.
引用
收藏
页数:17
相关论文
共 50 条
  • [41] Security risk assessment in IoT environments: A taxonomy and survey
    Waqdan, Mofareh
    Louafi, Habib
    Mouhoub, Malek
    COMPUTERS & SECURITY, 2025, 154
  • [42] Monitoring and Management Approach for Cyber Security Events over Complex Systems
    Hershey, Paul C.
    Silio, Charles B., Jr.
    2011 IEEE INTERNATIONAL SYSTEMS CONFERENCE (SYSCON 2011), 2011, : 38 - 45
  • [43] Development of a cyber security risk model using Bayesian networks
    Shin, Jinsoo
    Son, Hanseong
    Ur, Rahman Khalil
    Heo, Gyunyoung
    RELIABILITY ENGINEERING & SYSTEM SAFETY, 2015, 134 : 208 - 217
  • [44] IoT Security Risk Management: A Framework and Teaching Approach
    Affia, Abasi-amefon O.
    Nolte, Alexander
    Matulevicius, Raimundas
    INFORMATICS IN EDUCATION, 2023, 22 (04): : 555 - 588
  • [45] Proactive Measures to Mitigate Cyber Security Challenges in IoT based Smart Healthcare Networks
    Marshal, R.
    Gobinath, K.
    Rao, V. Venkateswara
    2021 IEEE INTERNATIONAL IOT, ELECTRONICS AND MECHATRONICS CONFERENCE (IEMTRONICS), 2021, : 982 - 985
  • [46] Cuckoo Search-Optimized Deep CNN for Enhanced Cyber Security in IoT Networks
    Gupta, Brij B.
    Gaurav, Akshat
    Arya, Varsha
    Attar, Razaz Waheeb
    Bansal, Shavi
    Alhomoud, Ahmed
    Chui, Kwok Tai
    Computers, Materials and Continua, 2024, 81 (03): : 4109 - 4124
  • [47] Application of Bayesian Network to Data-Driven Cyber-Security Risk Assessment in SCADA Networks
    Huang, Kaixing
    Zhou, Chunjie
    Tian, Yu-Chu
    Tu, Weixun
    Peng, Yuan
    2017 27TH INTERNATIONAL TELECOMMUNICATION NETWORKS AND APPLICATIONS CONFERENCE (ITNAC), 2017, : 96 - 101
  • [48] Cyber-Security Risk Assessment Framework for Critical Infrastructures
    Baig, Zubair
    Zeadally, Sherali
    INTELLIGENT AUTOMATION AND SOFT COMPUTING, 2019, 25 (01): : 121 - 129
  • [49] A review of cyber security risk assessment methods for SCADA systems
    Cherdantseva, Yulia
    Burnap, Pete
    Blyth, Andrew
    Eden, Peter
    Jones, Kevin
    Soulsby, Hugh
    Stoddart, Kristan
    COMPUTERS & SECURITY, 2016, 56 : 1 - 27
  • [50] Standardized Cyber Security Risk Assessment for Unmanned Offshore Facilities
    Teglasy, Balint Z.
    Katsika, Sokratis
    Lundteigen, Mary Ann
    3RD INTERNATIONAL WORKSHOP ON ENGINEERING AND CYBERSECURITY OF CRITICAL SYSTEMS (ENCYCRIS 2022), 2022, : 33 - 40