Attack Modeling and Mitigation Strategies for Risk-Based Analysis of Networked Medical Devices

dc.contributor.authorHodges, Bronwyn J.
dc.contributor.authorMcDonald, J. Todd
dc.contributor.authorGlisson, William Bradley
dc.contributor.authorJacobs, Michael
dc.contributor.authorVan Devender, Maureen
dc.contributor.authorPardue, J. Harold
dc.date.accessioned2021-09-15T21:40:24Z
dc.date.available2021-09-15T21:40:24Z
dc.date.issued2020-01
dc.descriptionPaper co-authored by William Glisson that was published by Proceedings of the 53rd Hawaii International Conference on System Sciences in 2020.
dc.description.abstractThe escalating integration of network-enabled medical devices raises concerns for both practitioners and academics in terms of introducing new vulnerabilities and attack vectors. This prompts the idea that combining medical device data, security vulnerability enumerations, and attack-modeling data into a single database could enable security analysts to proactively identify potential security weaknesses in medical devices and formulate appropriate mitigation and remediation plans. This study introduces a novel extension to a relational database risk assessment framework by using the open-source tool OVAL to capture device states and compare them to security advisories that warn of threats and vulnerabilities, and where threats and vulnerabilities exist provide mitigation recommendations. The contribution of this research is a proof of concept evaluation that demonstrates the integration of OVAL and CAPEC attack patterns for analysis using a database-driven risk assessment framework.
dc.identifier.citationHodges, B., Mcdonald, J., Glisson, W., Jacobs, M., Van Devender, M., & Pardue, H. (2020). Attack Modeling and Mitigation Strategies for Risk-Based Analysis of Networked Medical Devices. Proceedings of the 53rd Hawaii International Conference on System Sciences. Hawaii International Conference on System Sciences. https://doi.org/10.24251/hicss.2020.796
dc.identifier.urihttps://hdl.handle.net/20.500.11875/3198
dc.publisherProceedings of the 53rd Hawaii International Conference on System Sciences
dc.subjectMachine Learning and Cyber Threat Intelligence and Analytics
dc.subjectcyber threat
dc.subjectmedical devices
dc.subjectrisk analysis
dc.subjectthreat intelligence
dc.subjectvulnerabilities
dc.titleAttack Modeling and Mitigation Strategies for Risk-Based Analysis of Networked Medical Devices
dc.typeArticle

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Attack Modeling and Mitigation_OCR.pdf
Size:
1.26 MB
Format:
Adobe Portable Document Format
Description:
Article

License bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.63 KB
Format:
Item-specific license agreed upon to submission
Description: