Content area

Abstract

The rapid growth and anticipated future expansion of medical devices in healthcare bring with it an increase in cyber security risks. Current cyber security risk assessment methods use frameworks that are not frequently updated and are not specific to the healthcare sector. This study explored the feasibility of using MITRE ATT&CK in conjunction with the Manufacturer Disclosure Statement for Medical Device Security (MDS2) to evaluate the cyber risks of medical devices. MDS2 provides information about the security status of medical devices. Vulnerabilities identified by using MDS2 data were compared with the vulnerabilities identified by interrogating the CVE database. The threat intelligence information that can be generated via the use of MITRE ATT&CK can be customized to the field of healthcare. Relevant threats identified by the use of ATT&CK were compared with general threats identified via the STRIDE model. CVSS was used to calculate vulnerability severity scores. Patient safety was addressed by the using the optional safety metric in CVSS 4.0. Lastly, risk scores were generated. The results of this research showed that this new method is an improvement over the previously published approaches. This new methodology has built-in mechanisms to keep it up to date when new cyber threat intelligence and new device security information is published. The incorporation of the safety metric highlighted vulnerabilities that would be of higher priority in a healthcare enterprise. This methodology will, therefore, help healthcare security teams meet the need to identify threats to the healthcare organization and to the organization’s patients.

Details

1010268
Title
Risk Assessment of Medical Devices: Leveraging MITRE ATT&CK® and Manufacturer Disclosure Statement for Medical Device Security
Author
Number of pages
217
Publication year
2025
Degree date
2025
School code
2210
Source
DAI-B 86/10(E), Dissertation Abstracts International
ISBN
9798310392694
Committee member
Liu, Michelle; Cintas-Canto, Alvaro; Sangurima, Omar
University/institution
Marymount University
Department
School of Technology and Innovation
University location
United States -- Virginia, US
Degree
D.Sc.
Source type
Dissertation or Thesis
Language
English
Document type
Dissertation/Thesis
Dissertation/thesis number
31937547
ProQuest document ID
3192026795
Document URL
https://www.proquest.com/dissertations-theses/risk-assessment-medical-devices-leveraging-mitre/docview/3192026795/se-2?accountid=208611
Copyright
Database copyright ProQuest LLC; ProQuest does not claim copyright in the individual underlying works.
Database
ProQuest One Academic