Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device...

29
Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF

Transcript of Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device...

Page 1: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF

UnpatchableLivingwithavulnerableimplanteddevice

@MarieGMoe@SINTEF_Infosec

MarieMoe,PhD,ResearchScientistatSINTEF

Page 2: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF

Hacktosavelives!

Page 3: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF

Howtheheartworks

3https://www.youtube.com/watch?v=d6RbN5lPqIU

Page 4: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF

Electricalsystemoftheheart

4

Page 5: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF

Pacemaker

5https://www.youtube.com/watch?v=-f2FKmMneXY

Page 6: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF

Leadless pacemaker

Page 7: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF

Thefuture?

Page 8: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF

TheInternetofMedical”Things”isreal,andmyheartiswiredintoit…

Page 9: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF

Pacemaker/ICDProgrammer

Homemonitoringunit

CellularorTelephoneNetwork Webportal

InductivenearfieldcommunicationMICS/

ISM

POTS/SMS

Remotemonitoring

Page 10: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF

Withconnectivitycomesvulnerability…

10

Page 11: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF

PotentialthreatsDeviceisvulnerable?

Accesspointisvulnerable?

Mobilenetworkiscompromised?

Serveratvendoriscompromised?

Websitethatdoctorlogsintoisvulnerable?

Page 12: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF
Page 13: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF

PersonalInfrastructureYourrelianceonaninfrastructureisinverselyproportionaltohowinvisibleitistoyou.

Weallrelyonoxygen,ourlungs,andourhearts,buthowoftentowethinkaboutthem?

Howoftendowedomaintenanceordebugthem?

Page 14: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF

“Techisnotneutralnorvalue-free.”

BenZevenbergen, Troopers16

Page 15: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF

Thestairs that almost killed me

Page 16: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF

Debuggingme

Page 17: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF

”We need tobeable toverify the software thatcontrols our lives”

BruceSchneier on“VolkswagenandCheatingSoftware”

Page 18: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF

Reflections on trusting machines

Page 19: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF

Whentrustisbroken

http://www.startribune.com/guidant-to-pay-a-fine-of-296m/113367264/

Page 20: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF

Previouswork• KevinFuetal:

– Pacemakersandimplantablecardiacdefibrillators:Softwareradioattacksandzero-powerdefenses (2008)

– MitigatingEMIsignalinjectionattacksagainstanalogsensors(2013)

• BarnabyJack• Hardcodedcredentials• Medicaldevicehoneypots• Druginfusionpumps

20

Page 21: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF

Hackingcansavelives!

21http://www.fda.gov/MedicalDevices/Safety/AlertsandNotices/ucm456815.htm

Page 22: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF

WTFare you doing with mydata?

22

Page 23: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF
Page 24: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF
Page 25: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF

25

Page 26: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF

Researchneeded• Opensourcemedicaldevices• Medicaldevicecryptography• Personalareanetworkmonitoring• Jammingprotection• Forensicsevidencecapture

Page 27: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF

Thebenefitoutweighstherisk

Page 28: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF

CreditsÉireann Leverett (@blackswanburst)

TonyNaggs (@xa329)GunnarAlendal (@gradoisageek)

HugoCampos(@HugoOC)ScottErven (@scotterven)

Alexandre Dulaunoy (@adulau)ClausCramonHoumann (@ClausHoumann)

JoshuaCorman (@joshcorman)BeauWoods (@beauwoods)SuzanneSchwartz(USFDA)

Family&Friends

Page 29: Living with a vulnerable implanted device · Unpatchable Living with a vulnerable implanted device @MarieGMoe @SINTEF_Infosec Marie Moe, PhD, Research Scientist at SINTEF

Thankyou!marie.moe@sintef.nowww.infosec.sintef.nowww.iamthecavalry.org

@MarieGMoe@SINTEF_Infosec