A Brief Chronology of Medical Device Security

作者:Burns A J*; Johnson M Eric; Honeyman Peter
来源:Communications of the ACM, 2016, 59(10): 66-72.
DOI:10.1145/2890488

摘要

THE CAPABILITIES OF modern medical devices continue to radically transform the treatment of acute conditions as well as the management of chronic long-term disease. As these technologies evolve, so also do the threats to the security and reliability of these devices. Over the past decade, there has been no shortage of headlines warning of pacemaker turned peacemaker, or insulin assassinations. Although these taglines are fictional (but not unimaginable), they capture the tenor of much of the medical device security reportage. While we strongly affirm the necessity of public awareness of these issues, we believe that hyperbole and/or mischaracterizations may lead to panic, desensitization, or perhaps worse, exploitation. Today, attention is turning to the dangers posed by the omnipresent cyber threat, as signaled with the long- awaited release on Oct. 2, 2014 of Food and Drug Administration (FDA) guidance on the management of cybersecurity in medical devices, 7 and the more recent draft guidance of Postmarket Management of Cybersecurity in Medical Devices. 8 Therefore, as the human body joins the illustrious Internet of Things, it is constructive to take pause and see how we got here. We hope this brief chronology of medical device and health IT security helps provide context for the current state of medical device security.

  • 出版日期2016-10