arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.00901cs.CR

医疗网络威胁十年:实证分析、循证优先级排序与AI威胁模型

A Decade of Healthcare Cyber Threats: Empirical Analysis, Evidence-Based Prioritisation, and AI Threat Model

Sadia Mehrin Rahi, Ayesha Siddika, Istiyak Hasan Maruf, Adrita Rahman Tory, Muhammad Aminur Rahaman, Khondokar Fida Hasan

AI总结:

本文通过分析2017-2024年的1214条医疗网络威胁记录,揭示攻击者行为转向隐匿战术,发现现有检测指南与攻击者精力错位,确定42项高优先级技术对应AI集成临床系统新兴威胁。

AI中文摘要:

医疗系统面临持续且不断演变的网络威胁,但对抗战术与技术随时间的变化尚未通过实证多源数据进行系统刻画。本文分析了来自三个权威来源的1214条威胁记录:MITRE ATT&CK行为框架、CISA已知被利用漏洞目录及NIST漏洞数据库,涵盖2017至2024年间44个经验证的针对医疗领域的威胁实体。研究显示,攻击者行为已明显转向以隐匿为导向的战术:防御逃避在整个观测期内始终是主导战术,2017至2024年间其在观测到的技术使用中占比稳定在15%-20%,而持久化从11.2%降至0,初始访问从9.0%降至0。研究进一步表明,现有检测指南与攻击者精力集中的领域存在结构性错位,覆盖最少的技术却受到最多的对抗关注。收敛分析将679个已确认被利用的漏洞与单一主导行为技术关联,在漏洞与行为层面识别出一个共同的可解决 choke point( choke point 译为“ choke point”,即关键节点)。最后,研究确定了42项高优先级技术,代表了即时检测机会,并表明该技术集直接对应针对AI集成临床系统的新兴威胁。

英文摘要:

Healthcare systems face persistent and evolving cyber threats, yet how adversarial tactics and techniques have shifted over time has not been systematically characterised using empirical, multi-source data. This paper analyses 1,214 threat records drawn from three authoritative sources: the MITRE ATT&CK behavioural framework, the CISA Known Exploited Vulnerabilities catalogue, and the NIST vulnerability database, covering 44 validated healthcare-targeting threat entities from 2017 to 2024. We show that attacker behaviour has shifted measurably toward stealth-oriented tactics: defense evasion remained the dominant tactic throughout the observation period, consistently accounting for 15-20% of observed technique use from 2017 to 2024, while persistence declined from 11.2% to zero and initial access from 9.0% to zero over the same period. We further demonstrate that existing detection guidance is structurally misaligned with where attacker effort is concentrated, with the least-covered techniques receiving the most adversarial attention. A convergence analysis links 679 confirmed exploited vulnerabilities to a single dominant behavioural technique, identifying a common addressable chokepoint across the vulnerability and behavioural surfaces. Finally, we identify 42 high-priority techniques representing immediate detection opportunities and show that this set of techniques maps directly to emerging threats against AI-integrated clinical systems.

补充信息

↑