AI 中文总结
研究在存在欺骗情况下互联网上暴露的DICOM服务,结合主动扫描与被动蜜罐部署,用噪声感知方法识别并过滤欺骗工件,降低暴露率,揭示大量DICOM部署漏洞及风险,指出现有欺骗系统不足以捕获这些风险。
AI 中文摘要
DICOM是用于交换医学图像的主要协议,但许多面向互联网的部署缺乏基本安全控制,将敏感患者数据暴露于未经授权的访问。准确测量这种暴露因蜜罐、网络望远镜和其他测量工件而变得复杂,这些会夸大公布的估计值。本文提出了一项针对面向互联网的DICOM服务的噪声感知研究,将主动的IPv4全范围扫描与被动蜜罐部署相结合。我们使用仅限于关联协商和C-ECHO的符合道德约束的探测器扫描常见的DICOM端口。然后,我们引入了一种可重复的误报过滤方法,该方法可识别蜜罐、望远镜、格式错误的响应者和其他欺骗工件,将明显的暴露率降低39%。过滤后,我们识别出3979个易受攻击的DICOM部署,所有这些部署都缺乏加密并接受未经认证的连接;1782个运行过时或弃用的软件,1551个存在已知的可远程利用的漏洞。后续扫描显示,大约50%的暴露服务在5个月的观察期内没有维护迹象,并且负责任的披露仅导致适度的短期补救。在被动测量中,我们部署了Dicompot,发现由于通用TCP噪声被错误记录为DICOM会话,其原始会话日志将活动高估了83%。过滤后,我们观察到一个侦察差距:大多数发出C-ECHO探测的行为者从未升级到数据窃取,这与复杂行为者对蜜罐进行指纹识别并在继续之前脱离的情况一致。我们的结果表明,DICOM暴露测量可能会因欺骗和日志工件而被严重扭曲,但一旦纠正,就会揭示对患者隐私和医疗安全的广泛风险,而现有的欺骗系统不足以捕获这些风险。
英文摘要
DICOM is the dominant protocol for exchanging medical images, yet many Internet-facing deployments lack basic security controls, exposing sensitive patient data to unauthorized access. Accurately measuring this exposure is complicated by honeypots, network telescopes, and other measurement artifacts that inflate published estimates. This paper presents a noise-aware study of Internet-facing DICOM services, combining active IPv4-wide scanning with passive honeypot deployments. We scan common DICOM ports using an ethics-constrained probe limited to association negotiation and C-ECHO. Then, we introduce a reproducible false-positive filtering method that identifies honeypots, telescopes, malformed responders, and other deception artifacts, reducing apparent exposure by 39%. After filtering, we identify 3,979 vulnerable DICOM deployments, all of which lack encryption and accept unauthenticated connections; 1,782 run outdated or deprecated software, and 1,551 carry known remotely exploitable vulnerabilities. Follow-up scans reveal that approximately 50% of exposed services show no evidence of maintenance over 5 months of observation, and that responsible disclosure led to only modest, short-term remediation. On the passive measurement, we deploy Dicompot and find that its raw session logs overstate activity by up to 83% due to generic TCP noise being incorrectly logged as DICOM sessions. After filtering, we observe a reconnaissance gap: Most actors issuing C-ECHO probes never escalate to data exfiltration, consistent with sophisticated actors fingerprinting the honeypot and disengaging before proceeding. Our results show that DICOM exposure measurements can be significantly distorted by deception and logging artifacts, but once corrected, reveal widespread risks to patient privacy and healthcare security that existing deception systems are insufficient to capture.