Breaking

Medical Device Security: HL7v2 Injections in Patient Monitors

Digital networking is already widespread in many areas of life. In the healthcare industry, a clear trend towards networked devices is noticeable, so that the number of high-tech medical devices in hospitals is steadily increasing.

In this blog post, we want to elucidate a vulnerability we identified during the security assessment of a patient monitor. The device sends HL7 v2.x messages, such as observation results to HL7 v2.x capable electronic medical record (EMR) systems. A user with malicious intent can tamper these messages. As HL7 v2.x is a common medical communication standard, we also want to present how this kind of vulnerability may be mitigated. The assessment was part of the BSI project ManiMed, which we would like to present in the following section.

Continue reading
Events

MRMCD16 – diagnosis:critical

This year’s MRMCD16 had a topic that immediately let me submit a talk about medical device security: “diagnosis:critical”. Or to quote the official website:

Security issues in soft- and hardware have a low chance of healing, especially in medical IT.

Despite years of therapy using code reviews and programming guidelines, we still face huge amounts of vulnerable software that probably is in need of palliative treatment.

Security vulnerabilities caused by the invasion of IT in the medical sector are becoming real threats. From insulin pumps over analgesic pumps through to pace makers, more and more medical devices have been hacked already. This year’s motto “mrmcd2016 - diagnosis:critical” stands summarizing for the current state of the whole IT sector.

Continue reading
Events

Unpatchable – Living with a vulnerable implanted device

TL;DR: Marie Moe talked about security issues of medical devices, especially implantable devices like pacemakers, but not in overwhelming technological depth. She wanted to point out the necessity of intensified security research in the field of medical devices as vendors and medical personnel seem to be lacking necessary awareness of security of devices, interfaces, services, and even data privacy.”Get involved, join the cavalry” was her core message.

Lub-Dub-Lub-Dub-Lub-Dub
Marie started her talk with the sound of a repeating heartbeat. First she introduced how she came up with the topic of her talk: Marie relies on a pacemaker herself andsince she got it implanted she was curious how secure this little device might be. A minimum education of the auditorium followed including an explanation how a human heart works and what a pacemaker does.

Continue reading
Events

Medical Device Security: Hack or Hype

Kevin Fu is an Associate Professor at the University of Michigan where he directs the Archimedes Center for Medical Device Security and cofounded Virta Labs. At Troopers 16 he held a talk in the field of his research: medical device security.

He started his talk with a brief introduction how he got started with medical device security and how it has changed since he started. Round about ten years ago he started dumpster diving for medical devices to investigate how they are protected and maintained. In 2006 he held his first talk about medical device security at the FDA. In 2008 he presented a wireless replay attack against a pacemaker. In 2013 concerns about medical device security became more and more mainstream when the television series homeland featured an episode where the pacemaker of the American vice president was attacked resulting in his death. Now, instead of dumpster diving for medical devices, he works together with clinicians and has a lab for testing devices. The communication with clinicians is very important for his work, so he visits hospitals with his student so that they can learn how the process works on the inside.

Continue reading
Events

“We have a Code Blue right here!”

That was the opener for my presentation on the Security in Medical Devices at CodeBlue 2015 last week in Tokyo, Japan. A Code Blue often describes a patient in a critical condition, mostly needing resuscitation. That just seemed to be a perfect match, also in the sense that the condition of some medical devices out there are still pretty critical concerning security. If you follow our current research on this you know what I am talking about. I hope that we are not talking about this topic anymore three years from now. That would mean that we have made the world a safer place, although it took some time … 😉

Continue reading
Events

ERNW speaking @ hardwear.io

Hardwarebug

On October 1st and 2nd Flo and I were presenting at
hardwear.io in The Hague, NL. My topic was “Living in a fool’s
wireless-secured paradise” and Flo was presenting his current research
on medical device security. It was the first talk at an international
security conference for me and I am still quite excited!

I was speaking about the (in)security of wireless consumer alarm
systems, which you can buy just in every consumer electronics store
around the corner for about $10 – $250. I analyzed the systems on
different levels, e.g. looking at UART and JTAG and the wireless domain
with Software Defined Radio (SDR). I gave an overview of my current
research and the tools I usually use for hardware hacking, especially my
favorite thing to play with: SDR.

Continue reading
Breaking

The patient’s last words: I am not a target!

Last week I gave a short interview for Süddeutsche Zeitung on the security of medical devices. You can find it here. Unfortunately it is in German so I decided to sum up some of my key points that made it into the article and some that didn’t in this blog post.

The medical devices that we have been looking into include patient monitors, syringe pumps, EEGs, home monitoring devices and an MRI. All of these devices had major flaws that look like they came straight out of the 90s. Sometimes, we were able to crash the machines by simply doing a port scan, sometimes we could get around access controls protecting PIN codes of devices, and in most cases we were able to render the machine unusable. All these attacks were performed over the network and no physical access to the device was needed.

Continue reading
Events

Power of Community 2014

I had the pleasure to participate in this year’s Power of Community and was invited to talk about the insecurity of medical devices. The conference is based in Seoul, Korea and started in 2006. It has a strong technical focus and it is a community driven event. For me it was great to participate as mostly hackers from Asia were there and I got the chance to talk to a lot of nice folks that I wouldn’t be able to meet otherwise. This is especially true for the host, vangelis.

Continue reading
Breaking

Medical Device Security

One of our guiding principles at ERNW is “Make the World a Safer Place”. There could not be a topic that matches this principle more than the security or insecurity of medical devices. This is why we started a research project that is looking at how vulnerable those devices are that might be deployed in hospitals around the world. Recently the U.S. Food and Drug Administration (FDA) has put out a recommendation concerning the security of medical devices. It recommends that “manufacturers and health care facilities take steps to assure that appropriate safeguards are in place to reduce the risk of failure due to cyberattack, which could be initiated by the introduction of malware into the medical equipment or unauthorized access to configuration settings in medical devices and hospital networks”. We thought that we should take a look at how manufacturers deal with security for these devices.

Continue reading