HACKED IoT FEAR - USENIX · HACKED IoT MEDICAL DEVICES Sara Rampazzi - srampazz@umich.edu -...

Preview:

Citation preview

MEDICAL DEVICES

FEARHACKED IoT

THE

Sara RampazziUniversity of MichiganSPQR Lab

The apocalypse is already happening, and no one noticed?

FEAR THEHACKED IoTMEDICAL DEVICES

Sara Rampazzi - srampazz@umich.edu - spqr.eecs.umich.eduSPQR Lab

FEAR THEHACKED IoTMEDICAL DEVICES

Sara Rampazzi - srampazz@umich.edu - spqr.eecs.umich.eduSPQR Lab

PACEMAKER

INFUSION PUMP

IMAGING SYSTEM

MONITORING SYSTEM

EHR SYSTEM

NURSECALL

SYSTEMNEUROSTIMULATOR

MEDICALDEVICE

GATEWAYICD

FEAR THEHACKED IoTMEDICAL DEVICES

Sara Rampazzi - srampazz@umich.edu - spqr.eecs.umich.eduSPQR Lab

41.22 billion

158.07 billion

2017 2022

IoT healthcaremarket MarketsandMarkets™

FEAR THEHACKED IoTMEDICAL DEVICES

Sara Rampazzi - srampazz@umich.edu - spqr.eecs.umich.eduSPQR Lab

Security requirements not homogenous

Different devices, different protection

FEAR THEHACKED IoTMEDICAL DEVICES

Sara Rampazzi - srampazz@umich.edu - spqr.eecs.umich.eduSPQR Lab

FEAR THEHACKED IoTMEDICAL DEVICES

Sara Rampazzi - srampazz@umich.edu - spqr.eecs.umich.eduSPQR Lab

Trustworthy chain for health devicesELECTRONICHARDWARE

DESIGN

SW DESIGN AND

DEVELOPMENT

MECHANICAL DESIGN

NETWORK DATABASES

PRODUCT REGULATORY COMPLIANT

VERIFICATION AND

VALIDATION

PRODUCT LIFECYCLE

MANAGEMENT

INTERFACES DESIGN

MANUFACTURERS

PHYSICIANSINSTITUTIONS

ACADEMICS

FEAR THEHACKED IoTMEDICAL DEVICES

Sara Rampazzi - srampazz@umich.edu - spqr.eecs.umich.eduSPQR Lab

Build the trustworthy chain for health devices● Security-based HW/SW

Co-design● Risk-based approach● Centralized health data

management● Authorized third-party

consortiums● International shared

regulation and standard● ...

www.secure-medicine.orgthaw.orgspqr.eecs.umich.edu

Recommended