• DocumentCode
    40044
  • Title

    Behavior Rule Specification-Based Intrusion Detection for Safety Critical Medical Cyber Physical Systems

  • Author

    Mitchell, Robert ; Chen, Ing-Ray

  • Author_Institution
    Dept. of Comput. Sci., Virginia Polytech. Inst. & State Univ., Falls Church, VA, USA
  • Volume
    12
  • Issue
    1
  • fYear
    2015
  • fDate
    Jan.-Feb. 1 2015
  • Firstpage
    16
  • Lastpage
    30
  • Abstract
    We propose and analyze a behavior-rule specification-based technique for intrusion detection of medical devices embedded in a medical cyber physical system (MCPS) in which the patient´s safety is of the utmost importance. We propose a methodology to transform behavior rules to a state machine, so that a device that is being monitored for its behavior can easily be checked against the transformed state machine for deviation from its behavior specification. Using vital sign monitor medical devices as an example, we demonstrate that our intrusion detection technique can effectively trade false positives off for a high detection probability to cope with more sophisticated and hidden attackers to support ultra safe and secure MCPS applications. Moreover, through a comparative analysis, we demonstrate that our behavior-rule specification-based IDS technique outperforms two existing anomaly-based techniques for detecting abnormal patient behaviors in pervasive healthcare applications.
  • Keywords
    health care; medical computing; safety-critical software; security of data; IDS technique; MCPS; abnormal patient behavior detection; anomaly-based technique; behavior rule specification-based intrusion detection; medical devices; patient safety; pervasive healthcare application; safety critical medical cyber physical systems; state machine; Behavioral science; Biomedical monitoring; Intrusion detection; Monitoring; Peer-to-peer computing; Principal component analysis; Temperature measurement; Temperature sensors; Intrusion detection; healthcare; medical cyber physical systems; safety; security; sensor actuator networks;
  • fLanguage
    English
  • Journal_Title
    Dependable and Secure Computing, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1545-5971
  • Type

    jour

  • DOI
    10.1109/TDSC.2014.2312327
  • Filename
    6774867