在互联网规模上测量医疗数据泄露和安全漏洞
Measuring Healthcare Data Leaks and Security Flaws at Internet Scale
浏览论文内容
中文总结 AI 辅助
研究医疗数据处理系统安全,通过运行低交互honeypot及大规模互联网扫描,覆盖三大医疗协议,发现认证缺陷致数据泄露、TLS配置及软件漏洞问题,揭示安全现状并讨论对策。
中文摘要 AI 辅助
处理医疗数据的系统应严密保护。医疗环境中网络服务常未实施基本安全措施,如网络分割缺陷致DICOM系统泄露大量患者记录。我们运行医疗协议低交互蜜罐9个月,发现DICOM常被扫描而HL7和FHIR未被扫描。本文对HL7和FHIR服务进行首次大规模研究并扩展DICOM相关工作,通过扫描发现诸多安全问题并揭示医疗部署中网络安全的警示状态,还讨论了潜在原因、对策及协调披露活动。
英文摘要
Systems that process medical data should be meticulously secured. Yet, network services in healthcare environments often fail to implement basic security measures. For example, previous studies showed that network segmentation flaws led to DICOM systems leaking millions of patient records. In addition to DICOM, healthcare facilities rely heavily on the HL7 and FHIR protocols to transmit data. For nine months, we operated a low-interaction honeypot for medical protocols. We found it was regularly scanned for DICOM but never for HL7 or FHIR, indicating that despite their widespread use and importance for patient data security, the security of these services remains underexplored. In this paper, we present the first large-scale study on HL7 and FHIR services and expand previous work on DICOM. Our large-scale Internet scans, covering the three major healthcare protocols across IPv4 and IPv6 address spaces, identify healthcare systems and uncover data leaks due to authentication flaws. Additionally, we scanned for deficiencies in TLS configurations of these services and known insecure healthcare software. In total, we found 2,841 healthcare services with authentication flaws. 94.4% of all exposed systems do not support transport encryption, and 1,373 systems have known software vulnerabilities, including those with potential for system takeover and CVSS scores up to 9.8. Overall, our study reveals an alarming state of cybersecurity in healthcare deployments, for which we discuss potential reasons and countermeasures. Finally, we report on the coordinated disclosure campaign we initiated to improve the security of patient data.