Safety-Focused Security Requirements Elicitation for Medical Device Software

被引:5
|
作者
Lindvall, Mikael [1 ]
Diep, Madeline [1 ]
Klein, Michele [1 ]
Jones, Paul [2 ]
Zhang, Yi [2 ]
Vasserman, Eugene [3 ]
机构
[1] Fraunhofer CESE, College Pk, MD USA
[2] US FDA, Silver Spring, MD USA
[3] Kansas State Univ, Manhattan, KS 66506 USA
关键词
Medical device safety and security; requirements elicitation; sequence based enumeration;
D O I
10.1109/RE.2017.21
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Security attacks on medical devices have been shown to have potential safety concerns. Because of this, stakeholders (device makers, regulators, users, etc.) have increasing interest in enhancing security in medical devices. An effective means to approach this objective is to integrate systematic security requirements elicitation and analysis into the design and evaluation of medical device software. This paper extends the sequence-based enumeration approach, a systematic approach for defining the behavior of embedded software, to analyze the requirement documents of a medical device for the purpose of eliciting security requirements. As a proof of concept, we apply our approach on a concrete case study, which shows that the extended approach is useful for identifying sequences of medical device events that might be harmful to the patient, for example because the events are initiated by an active adversary trying to use the device in a malicious way. We then show how security requirements may be formulated based on the identified threats. By exploring these sequences systematically, the developers can reliably assess what, where, and how the security threats may manifest in their system, what the safety implications are, and finally they can evaluate the resulting requirements and mitigations.
引用
收藏
页码:134 / 143
页数:10
相关论文
共 50 条
  • [1] A safety-focused verification using software fault trees
    Cha, Sungdeok
    Yoo, Junbeom
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2012, 28 (08): : 1272 - 1282
  • [2] A Safety-focused Security Risk Assessment of Commercial Aircraft Avionics
    Ryon, Luke
    Rice, Greg
    2018 IEEE/AIAA 37TH DIGITAL AVIONICS SYSTEMS CONFERENCE (DASC), 2018, : 225 - 232
  • [3] Requirements for medical device software
    Pöyhönen, Ilpo
    Kylmälä, Kaarle
    Harju, Hannu
    Kemppainen-Kajola, Pia
    Kuhakoski, Kalle
    Spankie, Greig
    Ventä, Olli
    VTT Tiedotteita - Valtion Teknillinen Tutkimuskeskus, 2002, (2150): : 3 - 135
  • [4] Research on Elicitation of Safety Testing Requirements for Airborne Software
    Li Hongbing
    Bao Xiaohong
    Ji Shujuan
    3RD INTERNATIONAL SYMPOSIUM ON AIRCRAFT AIRWORTHINESS (ISAA 2013), 2014, 80 : 303 - 312
  • [5] SafeSec Tropos: Joint security and safety requirements elicitation
    Kavallieratos, Georgios
    Katsikas, Sokratis
    Gkioulos, Vasileios
    COMPUTER STANDARDS & INTERFACES, 2020, 70
  • [6] A Combined Process for Elicitation and Analysis of Safety and Security Requirements
    Raspotnig, Christian
    Karpati, Peter
    Katta, Vikash
    ENTERPRISE, BUSINESS-PROCESS AND INFORMATION SYSTEMS MODELING, BPMDS 2012, 2012, 113 : 347 - 361
  • [7] Safety-Focused Customization of Treatment Plan Documentation
    Schubert, L.
    Westerly, D.
    Stuhr, K.
    Miften, M.
    MEDICAL PHYSICS, 2012, 39 (06) : 3749 - 3749
  • [8] A Security Ontology for Security Requirements Elicitation
    Souag, Amina
    Salinesi, Camille
    Mazo, Raul
    Comyn-Wattiau, Isabelle
    ENGINEERING SECURE SOFTWARE AND SYSTEMS (ESSOS 2015), 2015, 8978 : 157 - 175
  • [9] Journey to Titratable Medications: A Patient Safety-Focused Approach
    Phan, Grace
    Ortiz, Herbert Rolito
    Carethers, Reba
    Eapen, Sini
    CRITICAL CARE NURSE, 2023, 43 (02) : E22 - E22
  • [10] Personalized Safety-focused Control by Minimizing Subjective Risk
    Bao, Naren
    Yang, Dongfang
    Carballo, Alexander
    Ozguner, Umit
    Takeda, Kazuya
    2019 IEEE INTELLIGENT TRANSPORTATION SYSTEMS CONFERENCE (ITSC), 2019, : 3853 - 3858