CardiWall: A Trusted Firewall for the Detection of Malicious Clinical Programming of Cardiac Implantable Electronic Devices

Today, cardiac implantable electronic devices (CIEDs), such as pacemakers and implantable cardioverter defibrillators (ICDs), play an increasingly important role in healthcare ecosystems as patient life support devices. Physicians control, program and configure CIEDs on a regular basis using a dedic...

Full description

Bibliographic Details
Main Authors: Matan Kintzlinger, Aviad Cohen, Nir Nissim, Moshe Rav-Acha, Vladimir Khalameizer, Yuval Elovici, Yuval Shahar, Amos Katz
Format: Article
Language:English
Published: IEEE 2020-01-01
Series:IEEE Access
Subjects:
Online Access:https://ieeexplore.ieee.org/document/9025056/
_version_ 1818735558870958080
author Matan Kintzlinger
Aviad Cohen
Nir Nissim
Moshe Rav-Acha
Vladimir Khalameizer
Yuval Elovici
Yuval Shahar
Amos Katz
author_facet Matan Kintzlinger
Aviad Cohen
Nir Nissim
Moshe Rav-Acha
Vladimir Khalameizer
Yuval Elovici
Yuval Shahar
Amos Katz
author_sort Matan Kintzlinger
collection DOAJ
description Today, cardiac implantable electronic devices (CIEDs), such as pacemakers and implantable cardioverter defibrillators (ICDs), play an increasingly important role in healthcare ecosystems as patient life support devices. Physicians control, program and configure CIEDs on a regular basis using a dedicated programmer device. The programmer device is open to external connections (e.g., USB, Bluetooth, etc.), and thus it is exposed to a variety of cyber-attacks by which an attacker can manipulate the programmer device's operations and consequently harm the patient. In this paper, we present CardiWall, a novel detection and prevention system designed to protect ICDs from cyber-attacks aimed at the programmer device. Our system has six different layers of protection, leveraging medical experts' knowledge, statistical methods, and machine learning algorithms. We evaluated the CardiWall system extensively in two comprehensive experiments. For the evaluation, we gathered data for a period of four years and used 775 benign clinical commands that are related to hundreds of different patients (obtained from different programmer devices located at Barzilai University Medical center) and 28 malicious clinical commands (created by two cardiology experts from different hospitals). The evaluation results show that only two out of the six layers proposed in CardiWall system provided a high detection capability associated with high rates of true positive, and low rates of false positive. With the configuration that provided the best harmonic mean of sensitivity and specificity (HMSS), CardiWall achieved a high true positive rate (TPR) of 91.4% and a very low false positive rate (FPR) of 1%, with an AUC of 94.7%.
first_indexed 2024-12-18T00:23:10Z
format Article
id doaj.art-79852d96a2d74f18a6cc5032e4cec764
institution Directory Open Access Journal
issn 2169-3536
language English
last_indexed 2024-12-18T00:23:10Z
publishDate 2020-01-01
publisher IEEE
record_format Article
series IEEE Access
spelling doaj.art-79852d96a2d74f18a6cc5032e4cec7642022-12-21T21:27:18ZengIEEEIEEE Access2169-35362020-01-018481234814010.1109/ACCESS.2020.29786319025056CardiWall: A Trusted Firewall for the Detection of Malicious Clinical Programming of Cardiac Implantable Electronic DevicesMatan Kintzlinger0https://orcid.org/0000-0002-2771-8157Aviad Cohen1https://orcid.org/0000-0001-9976-0525Nir Nissim2https://orcid.org/0000-0003-0652-8861Moshe Rav-Acha3https://orcid.org/0000-0002-5365-9947Vladimir Khalameizer4https://orcid.org/0000-0002-3102-2726Yuval Elovici5https://orcid.org/0000-0002-9641-128XYuval Shahar6https://orcid.org/0000-0003-0328-2333Amos Katz7https://orcid.org/0000-0003-0422-934XMalware Lab, Ben-Gurion University of the Negev (BGU), Beer-Sheva, IsraelMalware Lab, Ben-Gurion University of the Negev (BGU), Beer-Sheva, IsraelMalware Lab, Ben-Gurion University of the Negev (BGU), Beer-Sheva, IsraelCardiology Department, Shaare Zedek Medical Center, Hebrew University, Jerusalem, IsraelFaculty of Health Sciences, Ben-Gurion University of the Negev, Beer-Sheva, IsraelDepartment of Software and Information Systems Engineering, Ben-Gurion University of the Negev, Beer-Sheva, IsraelDepartment of Software and Information Systems Engineering, Ben-Gurion University of the Negev, Beer-Sheva, IsraelFaculty of Health Sciences, Ben-Gurion University of the Negev, Beer-Sheva, IsraelToday, cardiac implantable electronic devices (CIEDs), such as pacemakers and implantable cardioverter defibrillators (ICDs), play an increasingly important role in healthcare ecosystems as patient life support devices. Physicians control, program and configure CIEDs on a regular basis using a dedicated programmer device. The programmer device is open to external connections (e.g., USB, Bluetooth, etc.), and thus it is exposed to a variety of cyber-attacks by which an attacker can manipulate the programmer device's operations and consequently harm the patient. In this paper, we present CardiWall, a novel detection and prevention system designed to protect ICDs from cyber-attacks aimed at the programmer device. Our system has six different layers of protection, leveraging medical experts' knowledge, statistical methods, and machine learning algorithms. We evaluated the CardiWall system extensively in two comprehensive experiments. For the evaluation, we gathered data for a period of four years and used 775 benign clinical commands that are related to hundreds of different patients (obtained from different programmer devices located at Barzilai University Medical center) and 28 malicious clinical commands (created by two cardiology experts from different hospitals). The evaluation results show that only two out of the six layers proposed in CardiWall system provided a high detection capability associated with high rates of true positive, and low rates of false positive. With the configuration that provided the best harmonic mean of sensitivity and specificity (HMSS), CardiWall achieved a high true positive rate (TPR) of 91.4% and a very low false positive rate (FPR) of 1%, with an AUC of 94.7%.https://ieeexplore.ieee.org/document/9025056/ICDmachine learningmalwaredetectionsecurity
spellingShingle Matan Kintzlinger
Aviad Cohen
Nir Nissim
Moshe Rav-Acha
Vladimir Khalameizer
Yuval Elovici
Yuval Shahar
Amos Katz
CardiWall: A Trusted Firewall for the Detection of Malicious Clinical Programming of Cardiac Implantable Electronic Devices
IEEE Access
ICD
machine learning
malware
detection
security
title CardiWall: A Trusted Firewall for the Detection of Malicious Clinical Programming of Cardiac Implantable Electronic Devices
title_full CardiWall: A Trusted Firewall for the Detection of Malicious Clinical Programming of Cardiac Implantable Electronic Devices
title_fullStr CardiWall: A Trusted Firewall for the Detection of Malicious Clinical Programming of Cardiac Implantable Electronic Devices
title_full_unstemmed CardiWall: A Trusted Firewall for the Detection of Malicious Clinical Programming of Cardiac Implantable Electronic Devices
title_short CardiWall: A Trusted Firewall for the Detection of Malicious Clinical Programming of Cardiac Implantable Electronic Devices
title_sort cardiwall a trusted firewall for the detection of malicious clinical programming of cardiac implantable electronic devices
topic ICD
machine learning
malware
detection
security
url https://ieeexplore.ieee.org/document/9025056/
work_keys_str_mv AT matankintzlinger cardiwallatrustedfirewallforthedetectionofmaliciousclinicalprogrammingofcardiacimplantableelectronicdevices
AT aviadcohen cardiwallatrustedfirewallforthedetectionofmaliciousclinicalprogrammingofcardiacimplantableelectronicdevices
AT nirnissim cardiwallatrustedfirewallforthedetectionofmaliciousclinicalprogrammingofcardiacimplantableelectronicdevices
AT mosheravacha cardiwallatrustedfirewallforthedetectionofmaliciousclinicalprogrammingofcardiacimplantableelectronicdevices
AT vladimirkhalameizer cardiwallatrustedfirewallforthedetectionofmaliciousclinicalprogrammingofcardiacimplantableelectronicdevices
AT yuvalelovici cardiwallatrustedfirewallforthedetectionofmaliciousclinicalprogrammingofcardiacimplantableelectronicdevices
AT yuvalshahar cardiwallatrustedfirewallforthedetectionofmaliciousclinicalprogrammingofcardiacimplantableelectronicdevices
AT amoskatz cardiwallatrustedfirewallforthedetectionofmaliciousclinicalprogrammingofcardiacimplantableelectronicdevices