Attack Detection for Medical Cyber-Physical Systems - A Systematic Literature Review

The threat situation due to cyber attacks in hospitals is emerging and patient life is at risk. One significant source of potential vulnerabilities is medical cyber-physical systems (MCPS). Detecting intrusions in this environment faces challenges different from other domains, mainly due to the hete...

Full description

Bibliographic Details
Main Authors: Pilgermann, M. (Author), Schrader, T. (Author), Stein, S. (Author), Weber, S. (Author)
Format: Article
Language:English
Published: Institute of Electrical and Electronics Engineers Inc. 2023
Subjects:
IDS
Online Access:View Fulltext in Publisher
View in Scopus
LEADER 03233nam a2200397Ia 4500
001 10.1109-ACCESS.2023.3270225
008 230529s2023 CNT 000 0 und d
020 |a 21693536 (ISSN) 
245 1 0 |a Attack Detection for Medical Cyber-Physical Systems - A Systematic Literature Review 
260 0 |b Institute of Electrical and Electronics Engineers Inc.  |c 2023 
300 |a 1 
856 |z View Fulltext in Publisher  |u https://doi.org/10.1109/ACCESS.2023.3270225 
856 |z View in Scopus  |u https://www.scopus.com/inward/record.uri?eid=2-s2.0-85159709641&doi=10.1109%2fACCESS.2023.3270225&partnerID=40&md5=5473af6dc32fff350d729b3b4e47289c 
520 3 |a The threat situation due to cyber attacks in hospitals is emerging and patient life is at risk. One significant source of potential vulnerabilities is medical cyber-physical systems (MCPS). Detecting intrusions in this environment faces challenges different from other domains, mainly due to the heterogeneity of devices, the diversity of connectivity types, and the variety of terminology. To summarize existing results, we conducted a structured literature review (SLR) following the guidelines of Kitchenham et al. for SLRs in software engineering. We developed six research questions regarding detection approach, detection location, included features, adversarial focus, utilized datasets, and intrusion prevention. We identified that most researchers focused on an anomaly-based detection approach at the network layer. The primary focus was on the detection of malicious insiders. While several researchers used publicly available datasets for training and testing their algorithms, the lack of suitable datasets resulted in the development of testbeds consisting of various medical devices. Based on the results, we formulated five future research topics. First, the special conditions of hospital networks, the MCPS deployed within them, and the contrasts to other IT and OT environments should be examined. Thereupon, MCPS-specific datasets should be created that allow researchers to address the health domain’s unique requirements and possibilities. At the same time, endeavors aimed at standardization in this area should be supported and expanded. Moreover, the use of medical context for attack detection should be further explored. Last but not least, efforts for MCPS-tailored intrusion prevention should be intensified. This way, the emerging threat landscape can be addressed, IT security in hospitals can be improved, and patient health can be protected. Author 
650 0 4 |a Biomedical imaging 
650 0 4 |a Connected Health 
650 0 4 |a Detection 
650 0 4 |a Healthcare 4.0 
650 0 4 |a Hospitals 
650 0 4 |a IDS 
650 0 4 |a Internet of Health Things 
650 0 4 |a Intrusion detection 
650 0 4 |a Intrusion Prevention 
650 0 4 |a IoMT 
650 0 4 |a Medical CPS 
650 0 4 |a Medical Cyber-Physical Systems 
650 0 4 |a Medical devices 
650 0 4 |a Medical IoT 
650 0 4 |a Medical services 
650 0 4 |a Security 
650 0 4 |a Wireless sensor networks 
700 1 0 |a Pilgermann, M.  |e author 
700 1 0 |a Schrader, T.  |e author 
700 1 0 |a Stein, S.  |e author 
700 1 0 |a Weber, S.  |e author 
773 |t IEEE Access