Cyber-attacks Risk Analysis of a Connected Pulse Oximeter Device: A Threat Modeling Using STRIDE and DREAD Models
DOI:
https://doi.org/10.59992/IJSR.2024.v3n5p10Keywords:
Threat modeling, Cyber-security Threats, Connected Medical Device, STRIDE, DREADAbstract
The term "Internet of Things (IoT)" has gained significant traction in recent years due to its wide-ranging applications across various industries, including the healthcare sector. These medical devices, known as connected medical devices, offer immense benefits to patients with chronic diseases and others. However, despite their advantages, regulatory bodies responsible for issuing medical device sales and usage permits currently lack a standardized method for evaluating the security and cybersecurity resilience of these devices before granting approval.
The proposed threat modeling approach is an engineering tool that utilizes the STRIDE model to identify and categorize potential threats to connected devices, determine the mitigation techniques employed, and generate a comprehensive report. Additionally, the DREAD model is employed to assess the severity of potential threats throughout the development life cycle of the connected medical device.
This paper aims to validate the accuracy and realism of the outcomes derived from this tool and assess the ease of implementation of the proposed methodology by medical device designers and biomedical engineers who lack cybersecurity expertise.
The results of applying the proposed threat modeling approach using the STRIDE and DREAD models to an open-source connected pulse oximeter revealed a low average severity score for the connected medical device against potential cyber threats. Our approach was also compared to other threat modeling methods in terms of the number of steps, implementation complexity, and result realism. The findings demonstrat that our threat modeling approach requires the fewest steps, does not necessitate cybersecurity expertise for implementation, and produces more realistic and stable results.
Consequently, we propose that the FDA adopt and implement our proposed approach to expedite the approval process for the sale and use of these medical devices, enabling healthcare providers to leverage connected medical devices on a wider scale to combat diseases and epidemics, ultimately delivering higher quality and more effective healthcare.
References
[1] M. N. Alam , B. Kaur and M. S. Kabir, "Tracing the Historical Progression and Analyzing the Broader Implications of IoT: Opportunities and Challenges with Two Case Studies," INTERNATIONAL JOURNAL OF ENGINEERING RESEARCH & TECHNOLOGY (IJERT), vol. 12, no. 04, April 2023.
[2] T. TSENG, T. C. Wu and F. Lai, "Threat analysis for wearable health devices and environment monitoring internet of things integration system," IEEE Access, vol. 7, p. 144983–144994, 2019.
[3] V. Vakhter, B. Soysal, P. Schaumont and U. Guler , "Security for Emerging Miniaturized Wireless Biomedical Devices: Threat modeling with Applications to Case Studies," IEEE 63rd International Midwest Symposium on Circuits and Systems (MWSCAS, 2020.
[4] M. Ghazal, "Piracy of wearable and implanted medical devices," International Arab Journal of Information, vol. 5, no. 9, 2017.
[5] M. Muthuppalaniappan and K. Stevenson, "Healthcare cyber-attacks and the COVID-19 pandemic: an urgent threat to global health," International Journal for Quality in Health Care, vol. 133, no. 1, 2020.
[6] S. Anderson and T. Williams, "Cybersecurity and medical devices: Are the ISO/IEC 80001-2-2 technical controls up to the challenge?," Computer Standards & Interfaces, vol. 56, pp. 134-143, February 2018.
[7] M. Siddiqi and A. Tsintzira, "Adding Security to Implantable Medical Devices: Can We Afford It," Association for Computing Machinery, 28 April 2021.
[8] Lechner, N. Hrgarek, Z. Stapić and V. Strahonja, "Threat modeling methods in the medical device industry: An integrative literature review," Central European Conference on Information and Intelligent Systems. Faculty of Organization and Informatics Varazdin, 2022.
[9] M. Cagnazzo, M. Hertlein, T. Holz and N. Pohlmann, "Threat modeling for Mobile Health Systems," IEEE Wireless Communications and Networking Conference Workshops (WCNCW), 2018.
[10] A. Omotosho, B. A. Haruna and O. M. Olaniyi , "Threat Modeling of Internet of Things Health Devices," Journal of Applied Security Research., 2019.
[11] D.-w. Kim, J.-y. Choi and K.-h. Han2, "Medical Device Safety Management Using Cybersecurity Risk Analysis," IEEE Access, 2022.
[12] "Saudi Food and Drug Administration," 2019. [Online]. Available: https://www.sfda.gov.sa/sites/default/files/2020-03/MDS-G36.pdf.
[13] P. Williams and A. Woodward, "Cybersecurity vulnerabilities in medical devices: a complex environment and multifaceted problem," Medical Devices: Evidence and Research, 2015.
[14] D. Revar, H. Nayak and D. Jhalac, "Design and Implementation of Pulse oximeter to monitor and predict Patient’s health," Compliance Engineering Journal, p. 18, 2020.
[15] A. Onubeze, "Developing a Wireless Heart Rate Monitor with MAX30100 and nRF51822," theseus, p. 42, 2016.
[16] Y. S. Parihar, "Internet of Things and Nodemcu: A review of use of Nodemcu ESP8266 in IoT products," Journal of Emerging Technologies and Innovative Research, p. 4, 2019.
[17] "Blynk Platform Security," Blynk, [Online]. Available: https://docs.blynk.io/en/blynk.cloud/security.
[18] S. Sarkar, A. Ghosh, M. Chakraborty and A. Mondal, "Design, Hardware Implementation of a Domestic Pulse Oximeter Using IOT for COVID – 19 Patient," International Journal of Microsystems and IoT, p. 8, 2023.
[19] A. Shostack, "Experiences Threat Modeling at Microsoft," p. 11.