IoT Medical Devices: Our Scariest Security Threat Yet

IoT medical devices may be our scariest security threat yet. Implanted devices such as pacemakers draw big headlines for security threats. However, there are 36,000 other health-care related devices in the United States that are discoverable on the connected device search engine Shodan – which doesn’t even take into account the global level of unprotected devices (source: Wired).

In fact, U.S. hospitals have an average of ten to 15 connected IoT medical devices per bed with some hospitals registering 5,000 beds (or 50,000 connected devices). Therefore, the magnitude of the risks associated with these medical IoT devices is a gripping proposition.

Most hacks will not be a life or death situation, although a few exposed vulnerabilities could be potentially fatal, such as with Johnson & Johnson’s insulin pumps, which could potentially administer a fatal dose of insulin, or the Animas OneTouch Ping with a vulnerable wireless controller. The most common hack is for medical records, which can be sold on a Dark Web aftermarket with a value of $500 per Medicare or Medicaid record [2] . As The Hill reports, tens of millions of electronic health records have been compromised over the last few years, whereas there has not been a single implant device death or documented patient harm, according to Zach Rothstein, associated vice president of the Advanced Medical Technology Association. In 2015 over 113 million personal health records were compromised, up 9x from 2014, according to the Department of Health and Human Services (DHS).

While medical record theft and device hacks are well documented, there are many reasons hackers target the vast array of medical devices on the market. Ransomware is the practice of taking over a mobile app until a ransom is paid. A similar exploit can be performed on hospitals by entering a weak point, such as unsecured wireless connections, to access the system and take it over for a ransom. For instance, the Los Angeles Hollywood Medical Center had to pay hackers $17,000 to regain control of critical computer systems [3] . A similar attack also occurred in Mount Pleasant, Texas, where a hospital had its core electronic medical system knocked offline until a ransom was paid. According to those in the security industry, while ransomware attacks are prevalent, they are rarely made public for a variety of reasons.

Other reasons hacks that can occur include changing medical records for allergies or diagnoses. There is at least one case where medical devices were hacked to disseminate information and change stock prices, such as with Muddy Waters, a short selling firm that hired a boutique cybersecurity firm to conduct test attacks on a St. Jude’s pacemaker from 10 feet (3 meters) away, but up to 100 feet with an antenna and software defined radio, according to Reuters.

Medical devices extend beyond healthcare facilities and now overlap with mobile apps, as well. Last year, the Medicines and Healthcare products Regulatory Agency (MHRA) has issued updated guidance today to help identify health apps that are medical devices – and how to secure these mobile vulnerabilities. The apps that are of concern gather data from either the person or a diagnostic device, collecting information such as heartbeat or blood glucose levels, and then interpret the data to make a diagnosis, or to recommend treatment4 . As the MRHA director of medical devices says, “We live in an increasingly digital world, both healthcare professionals, patients and the public use software and stand-alone apps to aid diagnosis and monitor health.” There are also many apps connected to medical devices, providing another entry point for hackers.

“Mobile apps are unleashing amazing creativity,” Bakul Patel said from the FDA’s Center for Devices and Radiological Health. “At the same time, we have set risk-based priorities and are focusing FDA’s oversight on mobile apps that are devices for which safety and effectiveness are critical.”

This article first appeared on Intertrust.comIntertrust.com

To learn more on how to protect IoT Medical Devices and how Intertrust drives advancements in healthcare with secure data collaborations, data privacy and security, contact sales@whitecryption.com Intertrust drives advancements in healthcare with secure data collaborations, data privacy and security, contact sales@whitecryption.com 

SOURCES:

[1] WIRED, Medical Devices Next Security Nightmare

[2] NextGov, This Is the Real Threat Posed by Hacked Medical Devices at VA

[3] NYTimes,  Los Angeles Hackers Pay $17,000 After Attack

Cybersecurity in Connected Vehicles Becomes Safety Feature for New Cars

New car firms such as Tesla are promoting increasingly high-tech features that require a connection to the internet, which has propelled cybersecurity in connected vehicles forward as a major safety feature. Last year, Chinese security researchers from Keen Security Lab successfully managed to hack a Tesla Model S from 12 miles away. By focusing on Tesla’s on-board software, the hack targeted the car’s controller area network, or CAN bus, which connects the chips found inside the cars. In this hack, the Model S P85 and Model 75D were targeted. Tesla continued to make news in 2015 for safety concerns in cybersecurity of connected vehicles. In November 2016, security personnel from the Norwegian company Promon were able to use the Tesla’s Android app as an entry point to successfully hack the vehicle. What’s more, using the features in the app, the hackers were able to locate the vehicle, unlock it and drive away unhindered.

As GM CEO Mary Barra said in a keynote speech, “A cyber incident is a problem for every automaker in the world. It is a matter of public safety.” As Tesla, GM and many others continue to release connected vehicles, the dangers of cybersecurity are very real. In fact, more than half of the vehicles sold today are connected and vulnerable. This threat will only grow as manufacturers begin to release autonomous vehicles.

Cybersecurity in Connected Vehicles and Mobile Applications

While gaining access to, and being able to control or steal, a vehicle such as a Tesla is disturbing enough, it raises several concerns about not only cybersecurity in connected cars, but also the mobile applications that extend the features of these vehicles and others. In fact, mobile apps are quickly becoming the main target for malicious behavior. Over the last four years, there has been a 188 percent increase in the number of Android vulnerabilities and a 262 percent increase in the number of iOS vulnerabilities. In addition, according to Gartner, 75 percent of mobile apps would fail basic security tests.

Digging deeper, Veracode found that four out of five applications written in PHP, Classic ASP and ColdFusion failed at least one of the OWASP Top 10, implying that many web-based applications and websites contain security vulnerabilities. More than 80 percent of mobile apps on both the Android and iOS platform revealed cryptographic implementation issues. This attempt to protect and then doing it poorly highlights the importance of updated training and tools to aid these feature developers as they target secure and protected applications.

Recently, Android malware has become more stealth. Last year, in 2015, malware began to obfuscate code to bypass signature-based security software. Despite Google’s response to critical vulnerabilities and patches of critical issues in the Android OS, end users are still dependent on device manufacturers for these updates.

Tesla and other automobiles today can have the computing power of 20 personal computers and feature 100 million lines of programming code. While features such as web browsing, Wi-Fi access points and remote-start mobile phone apps, help to enhance the enjoyment of the vehicle, they also add more opportunities for advanced attacks. In real life, thieves are hacking keyless entry systems in the UK to steal cars, meanwhile, software recalls have doubled within the past year, and soon they will match mechanical recalls.

The mobile application industry is pushing forward a new level of interoperability that will require heightened security and privacy measures. App developers are in a position where they can reduce the number of vulnerabilities before the app ships. Auto manufacturers are also prioritizing cybersecurity in connected vehicles as a major safety feature to compete with features requiring connectivity.

This article originally appeared on Intertrust.com Intertrust.com 

Read more about how Intertrust’s suite of products helps automobile manufacturers address privacy and security in the age of the connected car. connected car

Hot Startups in IoT

The Internet of Things (IoT) has enjoyed a lot of attention from analysts and researchers who expect the number of IoT connections to surpass the human population this year. It’s no surprise there are quite a few startups in IoT. But how many of these products will actually be used? And does IoT simplify life or only add more gadgets in an already gadget-frenzied world?

An open-source analysis of IoT user behavior conducted by Harvard Business Review collected from 1,000 IoT technology platforms and 279,000 early adopters found that the most heavily used IoT programs made home life easier. The top 3 most preferred systems extended security, quantified the self, such as measuring body mass index (BMI) or sleeping patterns), and optimized machines to automate functions such as turning off lights when someone leaves the house.

A few months back, Santa Clara hosted the IoT World conference, which is known as the largest IoT conference in the world with 400 speakers, 250 sponsors and exhibitors, and an attendance of over 11,000 people. I attended this conference and found the following startups in IoT to be on the mark for both innovation and also answering demand for consumer needs:

 

Hot Startups in IoT:

1. Owlet:

Owlet has created a smart sock to track a baby's heart rate and oxygen levels while they sleep

In 2015, there were about 3,700 sudden unexpected infant deaths (SUID) in the United States with 1,600 confirmed from SIDS. These deaths occur in infants less than 1-year-old and have no immediate obvious cause, creating stress for parents of newborn babies. Owlet has created a smart sock to track a baby’s heart rate and oxygen levels while they sleep. The gadget features a sensor within the sock that connects to a smartphone to log and track the data collected. The technology is called “pulse oximetry” that works like the red light used in hospitals placed on the index finger to measure heart rate and oxygen. If the baby’s oxygen levels or heart rate exceeds the acceptable range, the monitor sounds the alarm. Owlet is still in the process of FDA approval and cannot yet claim to prevent SIDS, however, some parents already claim to be sleeping better.

 

2. Swarm Technology

Swarm Intelligence was introduced in 1989 by Jing Wang as a collective behavior of decentralized, self-organized systems and was employed for artificial intelligence, especially in regards to cellular robotic systems. The inspiration for “intelligent” global behavior comes from nature, such as ant colonies, bird flocks, animal herding and bacterial growth. The company, Swarm Technology, takes this concept and applies it to distributed processing, heterogeneous processing, machine learning and multi-agent artificial intelligence. Alfonso Inguez, the electrical engineer who developed the idea, explains the CPU broadcasts ‘this is what I need’ and the other computers or hardware that are interconnected and part of the internet of things lends to the fulfillment of what is being broadcast. Iniquz explains the key concept is “that the co-processors are not sitting idle waiting to be told what to do; they’re actively looking for work.”

Swarm Intelligence was introduced in 1989 by Jing Wang as a collective behavior of decentralized, self-organized systems and was employed for artificial intelligence, especially in regards to cellular robotic systems.

 

3. Grid Connect

The smart home market continues to be plagued by high device prices, limited value and hard to install devices as pointed out in my article in VentureBeat.  Centralization may be necessary for the connected home to work, but where should we limit this? If the benefits we’re looking for are interoperability and efficiency, then the connected home should limit centralization to only this, allowing the rest of the appliances and electronics to be decentralized. GridConnect helps facilitate this balance with the Connect Sense Smart Outlet. Released in 2015, the company announced the addition of power monitoring to the Smart Outlet and ConnectSense app in late 2016. With the ConnectSense app, users can integrate scenes and rules for the Smart Outlet and other home automation devices regardless of manufacturer. The power monitoring also helps to give insight into the power consumption of the devices plugged into the Smart Outlet. The ConnectSense app also gives the ability to create rules based on power usage.

4. Mynt

Smart trackers are becoming increasingly sophisticated and Mynt is not only reasonably priced but offers a full set of features such as accurate position tracking, playing music, taking a picture, recording video and sharing location, to name a few. By attaching Mynt to your valuables, your smartphone will alert you if you leave your keys or wallet behind, or if your pet is lost. Mynt is also a bi-directional tracker that has a built-in buzzer if you leave your phone. You can also locate your car by saving your parking location or take a selfie with Mynt by using it as a remote control for your cell phone camera. Although not the only Bluetooth tracker on the market, Mynt is extremely thin and reasonably priced at $19.99.

Please note: The I/O Fund conducts research and draws conclusions for the Fund’s positions. We then share that information with our readers. This is not a guarantee of a stock’s performance. Please consult your personal financial advisor before buying any stock in the companies mentioned in this analysis.