Digital networking is already widespread in many areas of life. In the
healthcare industry, a clear trend towards networked devices is noticeable, so
that the number of high-tech medical devices in hospitals is steadily
increasing.
In this blog post, we want to elucidate a vulnerability we identified during the
security assessment of a patient monitor. The device sends HL7 v2.x messages,
such as observation results to HL7 v2.x capable electronic medical record (EMR)
systems. A user with malicious intent can tamper these messages. As HL7 v2.x is
a common medical communication standard, we also want to present how this kind
of vulnerability may be mitigated. The assessment was part of the BSI project
ManiMed, which we would like to present in the following section.
This year’s MRMCD16 had a topic that immediately
let me submit a talk about medical device security: “diagnosis:critical”. Or to
quote the official website:
Security issues in soft- and hardware have a low chance of healing, especially
in medical IT.
Despite years of therapy using code reviews and programming guidelines, we still
face huge amounts of vulnerable software that probably is in need of palliative
treatment.
Security vulnerabilities caused by the invasion of IT in the medical sector are
becoming real threats. From insulin pumps over analgesic pumps through to pace
makers, more and more medical devices have been hacked already. This year’s
motto “mrmcd2016 - diagnosis:critical” stands summarizing for the current state
of the whole IT sector.
TL;DR: Marie Moe talked about security issues of medical devices, especially
implantable devices like pacemakers, but not in overwhelming technological
depth. She wanted to point out the necessity of intensified security research in
the field of medical devices as vendors and medical personnel seem to be lacking
necessary awareness of security of devices, interfaces, services, and even data
privacy.”Get involved, join the cavalry” was
her core message.
Lub-Dub-Lub-Dub-Lub-Dub
Marie started her talk with the sound of a repeating heartbeat. First she
introduced how she came up with the topic of her talk: Marie relies on a
pacemaker herself andsince she got it implanted she was curious how secure this
little device might be. A minimum education of the auditorium followed including
an explanation how a human heart works and what a pacemaker does.
Kevin Fu is an Associate Professor at the University of Michigan where he
directs the Archimedes Center for Medical Device Security and cofounded Virta
Labs. At Troopers 16 he held a talk in the field of his research:
medical device security.
He started his talk with a brief introduction how he got started with medical
device security and how it has changed since he started. Round about ten years
ago he started dumpster diving for medical devices to investigate how they are
protected and maintained. In 2006 he held his first talk about medical device
security at the FDA. In 2008 he presented a wireless replay attack against a
pacemaker. In 2013 concerns about medical device security became more and more
mainstream when the television series homeland featured an episode where the
pacemaker of the American vice president was attacked resulting in his death.
Now, instead of dumpster diving for medical devices, he works together with
clinicians and has a lab for testing devices. The communication with clinicians
is very important for his work, so he visits hospitals with his student so that
they can learn how the process works on the inside.
That was the opener for my presentation on the Security in Medical Devices at
CodeBlue 2015 last week in Tokyo, Japan. A
Code Blue
often describes a patient in a critical condition, mostly needing resuscitation.
That just seemed to be a perfect match, also in the sense that the condition of
some medical devices out there are still pretty critical concerning security. If
you follow our current research on this you know what I am talking about. I hope
that we are not talking about this topic anymore three years from now. That
would mean that we have made the world a safer place, although it took some time
… 😉
On October 1st and 2nd Flo and I were presenting at
hardwear.io in The Hague, NL. My topic was
“Living in a fool’s wireless-secured paradise”
and Flo was presenting his current research
on medical device security. It was the first talk at an international
security conference for me and I am still quite excited!
I was speaking about the (in)security of wireless consumer alarm
systems, which you can buy just in every consumer electronics store
around the corner for about $10 – $250. I analyzed the systems on
different levels, e.g. looking at UART and JTAG and the wireless domain
with Software Defined Radio (SDR). I gave an overview of my current
research and the tools I usually use for hardware hacking, especially my
favorite thing to play with: SDR.
Last week I gave a short interview for Süddeutsche Zeitung on the security of
medical devices. You can find it
here.
Unfortunately it is in German so I decided to sum up some of my key points that
made it into the article and some that didn’t in this blog post.
The medical devices that we have been looking into include patient monitors,
syringe pumps, EEGs, home monitoring devices and an MRI. All of these devices
had major flaws that look like they came straight out of the 90s. Sometimes, we
were able to crash the machines by simply doing a port scan, sometimes we could
get around access controls protecting PIN codes of devices, and in most cases we
were able to render the machine unusable. All these attacks were performed over
the network and no physical access to the device was needed.
I had the pleasure to participate in this year’s
Power of Community
and was invited to talk about the insecurity of medical devices. The conference
is based in Seoul, Korea and started in 2006. It has a strong technical focus
and it is a community driven event. For me it was great to participate as mostly
hackers from Asia were there and I got the chance to talk to a lot of nice folks
that I wouldn’t be able to meet otherwise. This is especially true for the host,
vangelis.
One of our guiding principles at ERNW is “Make the World a Safer Place”. There
could not be a topic that matches this principle more than the security or
insecurity of medical devices. This is why we started a research project that is
looking at how vulnerable those devices are that might be deployed in hospitals
around the world. Recently the U.S. Food and Drug Administration (FDA) has put
out
a recommendation concerning
the security of medical devices. It recommends that “manufacturers and health
care facilities take steps to assure that appropriate safeguards are in place to
reduce the risk of failure due to cyberattack, which could be initiated by the
introduction of malware into the medical equipment or unauthorized access to
configuration settings in medical devices and hospital networks”. We thought
that we should take a look at how manufacturers deal with security for these
devices.