M. Czekster, Ricardo, Webber, Thais, Bertolin Furstenau, Leonardo and Marcon, César (2024). Dynamic risk assessment approach for analysing cyber security events in medical IoT networks. Internet of Things (Netherlands) ,
Abstract
Advancements in Medical Internet of Things (MIoT) technology ease remote health monitoring and effective management of medical devices. However, these developments also expose systems to novel cyber security risks as sophisticated threat actors exploit infrastructure vulnerabilities to access sensitive data or deploy malicious software, threatening patient safety, device reliability, and trust. This paper introduces a lightweight dynamic risk assessment approach using scenario-based simulations to analyse cyber security events in MIoT infrastructures and supplement cyber security activities within organisations. The approach includes synthetic data and threat models to enrich discrete-event simulations, offering a comprehensive understanding of emerging threats and their potential impact on healthcare settings. Our simulation scenario illustrates the model’s behaviour in processing data flows and capturing the characteristics of healthcare settings. Our findings demonstrate its validity by highlighting potential threats and mitigation strategies. The insights from these simulations highlight the model’s flexibility, enabling adaptation to various healthcare settings and supporting continuous risk assessment to enhance MIoT system security and resilience.
Publication DOI: | https://doi.org/10.1016/j.iot.2024.101437 |
---|---|
Divisions: | College of Engineering & Physical Sciences > School of Computer Science and Digital Technologies > Software Engineering & Cybersecurity |
Funding Information: | Ricardo Melo Czekster reports financial support was provided by Brazilian State Funding Agencies (FAPs), articulated by its National Council (CONFAP), and the National Council for Scientific and Technological Development (CNPq). Cesar Marcon reports finan |
Additional Information: | Copyright © 2024 The Authors. Published by Elsevier B.V. This is an open access article distributed under the terms of the Creative Commons CC-BY license (https://creativecommons.org/licenses/by/4.0/), which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited. |
Uncontrolled Keywords: | Medical Internet of Things (MIoT),Cyber security,Dynamic risk assessment,Simulation models,Data integration,Threat analysis |
Publication ISSN: | 2542-6605 |
Data Access Statement: | Data will be made available on request. |
Last Modified: | 25 Nov 2024 08:56 |
Date Deposited: | 21 Nov 2024 10:56 |
Full Text Link: | |
Related URLs: |
https://www.sci ... 3780?via%3Dihub
(Publisher URL) |
PURE Output Type: | Article |
Published Date: | 2024-11-20 |
Published Online Date: | 2024-11-20 |
Accepted Date: | 2024-11-13 |
Authors: |
M. Czekster, Ricardo
(
0000-0002-6636-4398)
Webber, Thais ( 0000-0002-8091-6021) Bertolin Furstenau, Leonardo Marcon, César |