Security News Fatal flaws in ten pacemakers make for Denial of Life attacks

frogboy

In memoriam 1961-2018
Thread author
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
Brit/Belgian research team decipher signals and devise wounding wireless attacks

A global research team has hacked 10 different types of implantable medical devices and pacemakers finding exploits that could allow wireless remote attackers to kill victims.

Eduard Marin and Dave Singelée, researchers with KU Leuven University, Belgium, began examining the pacemakers under black box testing conditions in which they had no prior knowledge or special access to the devices, and used commercial off-the-shelf equipment to break the proprietary communications protocols.

From the position of blind attackers the pair managed to hack pacemakers from up to five metres away gaining the ability to deliver fatal shocks and turn off life-saving treatment.

The wireless attacks could also breach patient privacy, reading device information disclosing location history, treatments, and current state of health.

Singelée told The Register the pair has probed implantable medical device and pacemakers, along with insulin pumps and neurostimulators in a bid to improve security understanding and develop lightweight countermeasures.

"So we wanted to see if these wireless attacks would be possible on these newer types of pacemakers, as this would show that there are still security problems almost 10 years after the initial security flaws have been discovered, and because the impact of breaking the long-range wireless communication channel would be much larger as adversaries can be further away from their victim," Singelée says.

"We deliberately followed a black-box approach mimicking a less-skilled adversary that has no prior knowledge about the specification of the system.

"Using this black-box approach we just listened to the wireless communication channel and reverse-engineered the proprietary communication protocol. And once we knew all the zeros and ones in the message and their meaning, we could impersonate genuine readers and perform replay attacks etcetera."

YLC6n7V.jpg

Their work is detailed in the On the (in)security of the Latest Generation Implantable Cardiac Defibrillators and How to Secure Them [PDF] authored by Marin and Singelée, KU Leven colleague Bart Preneel, Flavio D. Garcia and Tom Chothia of the University of Birmingham, and cardiologist Rik Willems of University Hospital Gasthuisberg.

The team describes in limited detail to protect patients how the wireless communications used to maintain the implantable medical devices can be breached.

"Adversaries may eavesdrop the wireless channel to learn sensitive patient information, or even worse, send malicious messages to the implantable medical devices. The consequences of these attacks can be fatal for patients as these messages can contain commands to deliver a shock or to disable a therapy." No physical access to the devices is required to pull off the attacks

Full Article. Fatal flaws in ten pacemakers make for Denial of Life attacks
 

Axelrod Sven

Level 3
Verified
Well-known
Feb 11, 2016
132
We're seeing Ransomware on computers. How long before we see messages on mobiles.. "Attention, your pacemaker is compromised, we will prove it by .." or some messages, and forcing patients to pay up? A pretty straightforward process by either hacking Hospital or Healthcare technology companies, both of whom are pathetically unaware of Strong Security... and leaves the vulnerable customer to pay for his life - literally. It's too dark to think about.
 

DardiM

Level 26
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
May 14, 2016
1,597
Thanks for the share :)

In the TV show 24 (I don't remember the season), there is an episode where they hack a pacemaker.

(I can't even imagine when cars will be completely autonomous ... or if one day body parts of human are changed to "improve" him :D)
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top