AI 中文总结
研究针对医学成像系统网络攻击问题,提出DICOMHawk网络欺骗框架,通过逼真交互等模拟相关服务,经多阶段测试,该框架吸引更多有效会话,避免被检测,捕获多次攻击,提升了对威胁的可见性。
AI 中文摘要
针对暴露的医疗基础设施的网络攻击威胁着敏感患者数据和临床操作,然而现有的基于DICOM的医学成像系统防御工具交互有限且易被识别。我们引入了DICOMHawk,一个使用逼真交互、动态填充病历和嵌入式蜜罐令牌来模拟DICOM和PACS服务的网络欺骗框架。在86天的比较和347天的多网络部署中,DICOMHawk吸引了比Dicompot更多的有效会话,避免了蜜罐检测,并捕获了49次医疗相关攻击。结果表明,逼真、长期、多地点的欺骗提高了对针对医学成像系统的威胁的可见性。
英文摘要
Cyber-attacks against exposed healthcare infrastructure threaten sensitive patient data and clinical operations, yet existing defensive tools for DICOM-based medical imaging systems provide limited interaction and are easily fingerprinted. We introduce DICOMHawk, a cyber-deception framework that emulates DICOM and PACS services using realistic interactions, dynamically populated medical records, and embedded honeytokens. In an 86-day comparison and a 424-day deployment across multiple networks, DICOMHawk attracted more valid sessions than Dicompot, avoided honeypot detection, and captured 67 medical-related attacks from 15 unique IPs. The results show that realistic, long-term, multi-location deception improves visibility into threats targeting medical imaging systems.
Comments18 pages, 3 figures