Seyed Masoud Hosseini · Overview · Study log · Weekly summaries · Ideas · Search · Transcript · RSS feed

Computer Security · Lecture 14 of 22 · 1:15:31

Lecture 15: Medical Device Security

15. Medical Software on YouTube

Study guide

What this lecture covers

This guest lecture, by Kevin Fu of the University of Michigan, shifts the course from technical security mechanisms to what happens when those mechanisms meet a high-consequence domain: implantable and hospital medical devices. It asks why the medical industry has been slow to adopt a security mindset, and what happens in practice when software controls devices like pacemakers, infusion pumps, and ventilators.

The lecture sits later in the course, after students have studied core security mechanisms, and applies that background to a concrete industry. After watching, you should be able to explain why medical device security differs from conventional software security, describe real documented failures (accidental and adversarial), and understand emerging defenses such as physiological plausibility checks and power-side-channel malware detection.

Key ideas

  • Design-in, not bolt-on: the FDA now expects manufacturers to consider security during design, before any code is written, because retrofitting security onto deployed medical devices is extremely difficult.
  • Culture gap: much of the medical device industry reasons about risk statistically from past incidents, unlike security practitioners who assume absence of evidence is not evidence of absence.
  • Resource-constrained implants: implanted devices run on tiny batteries, are hermetically sealed, and cannot be easily patched, which limits what security controls are practical.
  • Command shock vulnerability: researchers used a software radio to record and replay an unauthenticated wireless command that made a defibrillator deliver a large, unprompted shock.
  • Sensor integrity over confidentiality: the lecture argues that trusting what a sensor reports is often a bigger risk than an attacker breaking in, since malware or interference can quietly corrupt readings a device relies on.
  • Electromagnetic interference as an attack path: carefully tuned interference can "unintentionally demodulate" onto a device's internal wiring, bypassing analog filters and reaching the microprocessor as if it were a real signal.
  • Availability over confidentiality: widescale outages, such as malware disabling thousands of infusion pumps or a hospital's cath lab, are described as a more pressing risk than headline-grabbing device hacks.
  • Legacy software lifecycles: many medical devices run outdated, unpatched operating systems (including Windows XP or older) because hospital and manufacturer update cycles lag far behind consumer software.

Walkthrough

Regulatory shift and the culture problem (2:01)

The lecture opens with the FDA's then-recent guidance requiring manufacturers to address cybersecurity during device design rather than after the fact. Fu draws a parallel to 19th-century resistance to handwashing in medicine, arguing that medical device security faces a similar cultural resistance today: manufacturers are only beginning to accept that security has to be part of the process, not an afterthought.

Real device failures without an attacker (8:05)

Before discussing adversaries, the lecture covers documented failures from the FDA's public malfunction database, including a fatal buffer overflow in an infusion pump and a fatal dosing error caused by a missing units label on a pump interface. These cases show that ordinary software bugs and human-factors failures already cause serious harm, independent of any attacker.

Software management and legacy systems (12:06)

The lecture turns to how medical devices are updated in practice, describing an antivirus update that misclassified a critical Windows file and disabled hospital admissions systems, and the widespread use of outdated, unsupported operating systems such as Windows XP on devices with multi-decade deployment lifespans. It contrasts this with the FDA's expectation that manufacturers keep software current.

Attacking an implanted defibrillator (17:11)

Fu describes how his research group used a software-defined radio to eavesdrop on unencrypted wireless communication with a defibrillator, then recorded and replayed the device's built-in "command shock" test signal without authentication, causing it to deliver a large shock. The lecture explains this was possible because early devices had no cryptographic protection on their control channel, and notes that manufacturers have since patched this class of issue.

Hospital malware and supply-chain infection (23:13)

The lecture covers malware inside hospitals, including hundreds of unpatched Windows XP machines at one facility, a vendor's USB drive accidentally spreading malware while updating equipment, and a manufacturer's own firmware-update website flagged as distributing malware. These examples illustrate that medical device infections are often accidental rather than targeted, and that vendors themselves can be an infection vector.

Spoofing sensors with electromagnetic interference (36:25)

This section explains, with a Bluetooth headset demonstration, how intentional electromagnetic interference tuned to a wire's resonant frequency can be "unintentionally demodulated" past analog filters and appear to a microprocessor as a legitimate signal. The lecture extends this to a synthetic cadaver test on a pacemaker, showing that interference could trick a device into believing the heart was beating on its own, though the effect only worked at close range and not through real tissue.

Detecting anomalies and reusing devices (52:35)

The lecture presents two defenses: sending test pacing pulses to check physiological plausibility of sensor readings, and using machine learning on a device's power consumption pattern to detect malware without modifying the device itself. It closes with a humanitarian project that sterilizes and reimplants donated pacemakers in developing countries, and a broader discussion of why availability and sensor integrity matter more than headline hacking incidents, plus the tension between security controls and clinical workflow.

Before you watch

  • Familiarity with the course's earlier material on buffer overflows and authentication will help, since both come up as concrete examples.
  • No specialized medical knowledge is assumed; sensor and cardiac physiology concepts are explained as they arise.
  • A basic sense of radio/RF concepts (frequency, filtering) helps with the electromagnetic interference sections, though the lecture explains these from first principles.

Check your understanding

  1. Why did the researchers succeed in triggering an unauthenticated defibrillator shock, and what specific vulnerability did the device lack?
  2. What is the difference between "unintentional demodulation" and simply overpowering a sensor with a strong signal, and why does it matter for bypassing analog filters?
  3. Why does the lecture argue that sensor integrity and device availability are bigger risks than targeted hacking, given the evidence presented?
  4. What made the infusion pump buffer overflow case fatal even though the software's error handling worked as designed?
  5. How does the "audit-based access control" model used in many hospitals differ from requiring passwords, and what tradeoff does it reflect?

Vocabulary

implantable device (noun)
A medical device placed permanently inside a patient's body.
Pacemakers are common implantable devices.
high-consequence domain (noun)
A field where mistakes can cause very serious harm, such as injury or death.
Medical devices are a high-consequence domain for software bugs.
retrofit (verb)
To add a new feature to something that already exists and was not designed for it.
It is hard to retrofit security onto deployed medical devices.
bolt-on (adjective)
Added afterward as an extra, rather than built in from the start.
Security should not be a bolt-on feature added after design.
statistically (adverb)
Based on numbers and patterns from past data.
The industry reasons about risk statistically from past incidents.
absence of evidence (phrase)
The lack of proof that something happened, which does not mean it never will.
Security experts assume absence of evidence is not evidence of absence.
resource-constrained (adjective)
Limited in available power, memory, or processing ability.
Resource-constrained implants run on tiny batteries.
hermetically sealed (adjective)
Completely sealed so nothing can get in or out.
Implants are hermetically sealed and hard to update.
patch (verb) (verb)
To update software to fix a bug or vulnerability.
Implanted devices are difficult to patch after implantation.
unauthenticated (adjective)
Not verified or checked for identity or permission.
The command shock was triggered by an unauthenticated wireless signal.
eavesdrop (verb)
To secretly listen to or intercept communication.
Researchers used a radio to eavesdrop on the defibrillator's signal.
replay (verb)
To record a signal and send it again later to trick a system.
They recorded and replayed the shock command.
integrity (of data) (noun)
The correctness and trustworthiness of data, showing it hasn't been changed.
Sensor integrity matters more than keeping data secret.
corrupt (verb)
To damage or wrongly alter data so it becomes unreliable.
Malware can quietly corrupt sensor readings.
electromagnetic interference (noun)
Unwanted electrical signals that disturb the normal operation of a device.
Electromagnetic interference can trick a device's internal circuits.
demodulate (verb)
To extract a signal from a carrier wave, often unintentionally.
Interference can unintentionally demodulate onto the device's wiring.
resonant frequency (noun)
The specific frequency at which an object vibrates most easily.
The interference was tuned to the wire's resonant frequency.
microprocessor (noun)
The main chip in a device that processes instructions and data.
The fake signal reached the microprocessor as if it were real.
availability (noun)
The property of a system being usable and working when needed.
Widescale outages threaten availability more than isolated hacks.
legacy software (noun)
Old software that is still used even though newer versions exist.
Many devices still run legacy software like Windows XP.
plausibility check (noun)
A test that checks whether a value makes reasonable sense given the context.
A physiological plausibility check can flag a fake sensor reading.
power side-channel (noun)
A way of detecting behavior by observing a device's electricity usage pattern.
Power side-channel analysis can detect malware without touching the device.
workflow (clinical) (noun)
The sequence of steps medical staff follow to do their work.
Strong security controls can conflict with clinical workflow.

Chapters

From the YouTube description

MIT 6.858 Computer Systems Security, Fall 2014
View the complete course: http://ocw.mit.edu/6-858F14
Instructor: Kevin Fu

In this lecture, Kevin Fu from the University of Michigan delivers a guest lecture on medical software.

License: Creative Commons BY-NC-SA
More information at http://ocw.mit.edu/terms
More courses at http://ocw.mit.edu

← Lecture 14: SSL and HTTPS · Lecture 16: Side-Channel Attacks →