Composite Risk Modeling For Automated Threat Mitigation In Medical Devices

  • Aakarsh Rao (Speaker)
  • Jerzy W. Rozenblit (Speaker)
  • Sametinger, J. (Speaker)

Activity: Talk or presentationContributed talkscience-to-science

Description

Medical device security is a growing concern with the increasing incorporation of complex software and hardware. Security threats exploiting vulnerabilities in medical devices may directly impact patient safety. Medical devices in particular, provide a high-risk attack surface due to their resource-constraint nature, off-the-shelf software, human-in-the-loop use case, interconnectivity and persistent maintenance of essential functionality. Standardization and federal organizations are actively involved in setting up new paradigms for guidance and regulation of medical device security management throughout their lifecycle. To protect medical devices against security attacks a risk-based framework that continually manages and assesses security risks along with their proactive addressing is highly recommended. In this paper, we model a multi-modal design approach for risk assessment in a medical device and propose an adaptive remediation scheme to mitigate security threats. Our multi-modal approach is integrated into the hardware-software design development of medical device with a middleware for interaction between the modes. This provides an effective premarket risk management while the adaptive remediation scheme pro-actively mitigate risk during postmarket deployment. We model our approaches in detail and demonstrate them in a pacemaker design model and deployment scenario.
Period25 Apr 2017
Event titleMSM 2017 - Modeling and Simulation in Medicine, in SpringSim'17 Spring Simulation Multi-Conference, Virginia Beach, Virginia, USA, April 23 –26, 2017
Event typeConference
LocationUnited StatesShow on map

Fields of science

  • 202017 Embedded systems
  • 102006 Computer supported cooperative work (CSCW)
  • 202005 Computer architecture
  • 102027 Web engineering
  • 102 Computer Sciences
  • 202022 Information technology
  • 502032 Quality management
  • 502050 Business informatics
  • 207409 Navigation systems
  • 102020 Medical informatics
  • 102011 Formal languages
  • 102022 Software development
  • 102002 Augmented reality
  • 201305 Traffic engineering
  • 102015 Information systems
  • 102040 Quantum computing 
  • 509026 Digitalisation research
  • 211928 Systems engineering
  • 102034 Cyber-physical systems
  • 102016 IT security
  • 503015 Subject didactics of technical sciences

JKU Focus areas

  • Management and Innovation
  • Computation in Informatics and Mathematics
  • Digital Transformation