4.6 Article

Synthesizing Pareto-Optimal Signal-Injection Attacks on ICDs

期刊

IEEE ACCESS
卷 11, 期 -, 页码 4992-5003

出版社

IEEE-INST ELECTRICAL ELECTRONICS ENGINEERS INC
DOI: 10.1109/ACCESS.2022.3233010

关键词

Medical treatment; Heart; Electric shock; Threat modeling; Medical devices; Optimization; Defibrillation; Cardiology; Medical device security; signal-injection attacks; Pareto-optimal attacks

向作者/读者索取更多资源

Implantable Cardioverter Defibrillators (ICDs) are vulnerable to signal-injection attacks, which induce morphological changes in measured electrograms (EGMs) and disrupt the normal behavior of the ICD control software. This paper introduces InjectICD, a model-based framework that systematically constructs stealthy attack templates for ICDs by synthesizing attack signals as multi-objective optimizations. The evaluation shows that InjectICD can construct attack templates for various heart conditions and adversary capabilities, highlighting the need for ICD manufacturers to incorporate defenses against signal-injection attacks.
Implantable Cardioverter Defibrillators (ICDs) are medical cyber-physical systems that monitor cardiac activity and administer therapy shocks in response to sensed irregular electrograms (EGMs) to prevent cardiac arrest. Prior work has shown that the analog sensors used in these systems are vulnerable to signal-injection attacks. Such attacks induce morphological changes in EGM measurements that disrupt the normal behavior of the ICD's control software and cause the device to administer incorrect therapy. Existing work has primarily focused on the feasibility of such attacks and has not examined how they can be systematically devised. In this paper, we introduce InjectICD, a model-based framework for the systematic construction of stealthy signal-injection attacks that can thwart ICD control software. InjectICD solves the problem of synthesizing attack signals as one of multi-objective optimization, thereby allowing it to identify Pareto-optimal signal-injection templates that maximize the probability of attack success while simultaneously applying minimal modifications to the original EGM. We evaluate InjectICD on an ICD algorithm currently implemented in devices from a major ICD manufacturer. We show that InjectICD can construct such attack templates for various heart conditions and under different adversary capabilities, while also demonstrating that our approach generalizes to unseen EGM signals. Our results highlight the urgent need for ICD manufacturers to incorporate defenses against signal-injection attacks.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.6
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据