Vulnerability detection method for medical device security, and security system using same

The method and system generate a SBOM from medical device binaries, perform vulnerability scans and fuzzing tests, and deploy deception traps to enhance security and prevent attacks, addressing the need for improved medical device cybersecurity compliance.

WO2025263673A1PCT designated stage Publication Date: 2025-12-26COONTEC CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/009775
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-06-17
Filing Date
2024-07-09
Publication Date
2025-12-26

AI Technical Summary

Technical Problem

The increasing sophistication of cyberattacks and software supply chain attacks necessitates improved vulnerability detection and defense systems for securing medical devices, particularly in compliance with certifications like Common Criteria (CC) and FDA cybersecurity guidelines.

Method used

A method and system that includes generating a Software Bill of Materials (SBOM) from a medical device program binary, performing vulnerability scans and fuzzing tests, and deploying a deception system with traps to block unauthorized access, utilizing virtualization technology.

Benefits of technology

Enhances medical device security by detecting vulnerabilities and preventing network attacks, ensuring compliance with security standards and protecting patient information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024009775_26122025_PF_FP_ABST
    Figure KR2024009775_26122025_PF_FP_ABST
Patent Text Reader

Abstract

A vulnerability detection method for medical device security and a security system using same are disclosed. The method performed by a computing device including one or more processors and a memory for storing one or more programs executed by the one or more processors, which is disclosed according to one embodiment, comprises the steps of: acquiring a binary of a program installed in a medical device; generating a software bill of materials (SBOM) of the program by analyzing the binary of the program; scanning for vulnerabilities in the SBOM of the program and storing the scanned vulnerability; and performing a security test and / or a fuzz test on the binary of the program.
Need to check novelty before this filing date? Find Prior Art

Description

Vulnerability detection method for medical device security and security system using the same

[0001] Embodiments of the present invention relate to vulnerability detection and security technology for medical device security.

[0002] Recently, with the increasing sophistication of cyberattacks and the rise of software supply chain attacks, the security of medical facilities and medical devices is becoming increasingly important. To this end, in Korea, Common Criteria (CC) and Good Software (GS) certifications are used to assess compliance with security requirements. Internationally, compliance with FDA cybersecurity guidelines is being assessed. In line with this trend, there is a need to develop vulnerability detection technologies and defense systems to secure medical devices.

[0003] An embodiment of the present invention provides a vulnerability detection and security technique for medical device security.

[0004] A method according to one embodiment of the present disclosure is a method performed in a computing device having one or more processors and a memory storing one or more programs to be executed by the one or more processors, the method comprising: obtaining a binary of a program to be installed in a medical device; analyzing the binary of the program to generate a Software Bill of Materials (SBOM) of the program; scanning the SBOM of the program for vulnerabilities and storing the scanned vulnerabilities; and performing one or more of a security test and a fuzzing test on the binary of the program.

[0005] The above method may further include a step of analyzing vulnerabilities according to a preset cycle in the SBOM of the above program.

[0006] The method may further comprise the step of constructing a deception system comprising one or more traps in the same environment as the medical device.

[0007] A system according to one embodiment disclosed is a security system including a vulnerability detection system for securing a medical device, wherein the vulnerability detection system obtains a binary of a program installed in a medical device, analyzes the binary of the program to generate a Software Bill of Materials (SBOM) of the program, scans the SBOM of the program for vulnerabilities, stores the scanned vulnerabilities, and performs at least one of a security test and a fuzzing test on the binary of the program.

[0008] The above security system may further include a deception system having one or more traps in the same environment as the medical device through virtualization technology.

[0009] The above security system may further include an integrated monitoring system that receives and manages information from at least one of the vulnerability detection system and the deception system.

[0010] According to the disclosed embodiment, it is possible to detect vulnerabilities in programs installed in medical devices to enhance security, and to block access to network attacks through a deception system.

[0011] FIG. 1 is a diagram illustrating an overview of a vulnerability detection and defense system for securing a medical device according to one embodiment of the present invention.

[0012] FIG. 2 is a schematic diagram of a vulnerability detection system for security of a medical device according to one embodiment of the present invention.

[0013] FIG. 3 is a schematic diagram of a deception system for securing a medical device according to one embodiment of the present invention.

[0014] Figure 4 is a schematic diagram of an integrated monitoring system for security of a medical device according to one embodiment of the present invention.

[0015] FIG. 5 is a block diagram illustrating a computing environment including a computing device suitable for use in exemplary embodiments.

[0016] Hereinafter, specific embodiments of the present invention will be described with reference to the drawings. The following detailed description is provided to facilitate a comprehensive understanding of the methods, devices, and / or systems described herein. However, these are merely examples and the present invention is not limited thereto.

[0017] In describing embodiments of the present invention, if a detailed description of a known technology related to the present invention is judged to unnecessarily obscure the gist of the present invention, the detailed description will be omitted. In addition, the terms described below are terms defined in consideration of their functions in the present invention, and this may vary depending on the intention or custom of the user or operator. Therefore, the definitions should be made based on the contents throughout this specification. The terminology used in the detailed description is only for the purpose of describing embodiments of the present invention and should not be limited in any way. Unless clearly used otherwise, the singular form includes the plural form. In this description, expressions such as "comprises" or "having" are intended to indicate certain features, numbers, steps, operations, elements, parts or combinations thereof, and should not be construed to exclude the presence or possibility of one or more other features, numbers, steps, operations, elements, parts or combinations thereof other than those described.

[0018] In the following description, the terms "transmission," "communication," "sending," "receiving," and other similar terms for signals or information include not only the direct transmission of signals or information from one component to another, but also transmission via another component. In particular, "transmitting" or "sending" a signal or information to one component indicates the final destination of the signal or information, and does not mean the direct destination. The same applies to "receiving" a signal or information. In addition, in this specification, the "relationship" of two or more pieces of data or information means that when one piece of data (or information) is acquired, at least a portion of the other piece of data (or information) can be acquired based on it.

[0019] Additionally, while terms such as "first" and "second" may be used to describe various components, these components should not be limited by these terms. These terms may be used to distinguish one component from another. For example, without departing from the scope of the present invention, a first component may be referred to as a "second component," and similarly, a second component may also be referred to as a "first component."

[0020] Figure 1 is a schematic diagram illustrating a vulnerability detection and defense system for securing medical devices according to one embodiment of the present invention. Referring to Figure 1, the overall system for securing medical devices may include a vulnerability detection system, a deception system, and an integrated monitoring system.

[0021] In the disclosed embodiment, vulnerabilities are identified by extracting the Software Bill of Materials (SBOM) of a program inserted into a medical device or analyzing the SBOM provided by the program supplier. Static and dynamic analysis is performed through Interactive Application Security Testing (IAST) using code and binaries, and security is ultimately verified through fuzzing testing. Furthermore, to prevent hacker intrusions into medical device networks, a deception system can be established to install vulnerable traps. This can enhance security by blocking access to IP addresses or devices that fall under the traps.

[0022] FIG. 2 is a schematic diagram of a vulnerability detection system for securing a medical device according to one embodiment of the present invention.

[0023] Referring to FIG. 2, the vulnerability detection system can obtain the program's SOURCE, BINARY, SBOM, etc. for vulnerability analysis of a program installed in a medical device. Here, the SBOM can be used for vulnerability analysis of the program. In one embodiment, if the SBOM of the program is not provided and only the binary is obtained, the binary can be analyzed to generate the SBOM of the program (SBOM extraction step). The generated SBOM can include information such as the program name, version, and open source library used. In one embodiment, the SBOM can be generated in SPDX or CycloneDX format.

[0024] Next, you can scan the program's SBOM for vulnerabilities (vulnerability scan phase). The results of the SBOM vulnerability scan can be stored in the system along with the SBOM.

[0025] Next, security testing can be performed on the program's binary (security testing phase). This step can be performed if only the program's binary was provided during the SBOM extraction phase. Alternatively, if the SOURCE is also obtained in addition to the program's binary, an integrated security test based on IAST can be performed.

[0026] Next, fuzzing tests can be performed on the program's binary (the fuzzing test phase). This step can be performed if only the program's binary was provided during the SBOM extraction phase. This step can also be performed if the program's binary is a network program. During the fuzzing test phase, fuzzing techniques can be used to perform random data transmission attacks. Afterwards, the results of each test and the SBOM can be stored in a vulnerability detection system.

[0027] FIG. 3 is a schematic diagram of a deception system for securing a medical device according to one embodiment of the present invention.

[0028] Referring to Figure 3, a deception system identical to a medical device or medical system can be created using virtualization technology. Based on this deception system, network-based attacks and theft of patient information can be detected and blocked. Specifically, if an attacker infiltrates a trap built into the deception system (①), the trap detects the attack and intrusion and alerts the deception system (②). The deception system can then use the provided information to issue a notification and block access to the attack (③).

[0029] FIG. 4 is a schematic diagram of an integrated monitoring system for security of a medical device according to one embodiment of the present invention.

[0030] Referring to Figure 4, the integrated monitoring system may be a system that receives, integrates, and manages information from both the vulnerability detection system and the deception system. In other words, the deception system can be managed through the integrated monitoring system. Furthermore, the integrated monitoring system can manage the software supply chain delivered by the vulnerability detection system. Furthermore, the integrated monitoring system can perform periodic SBOM inspections to detect and respond to newly discovered vulnerabilities.

[0031] FIG. 5 is a block diagram illustrating a computing environment (10) including a computing device suitable for use in exemplary embodiments. In the illustrated embodiment, each component may have different functions and capabilities other than those described below, and may include additional components other than those described below.

[0032] The illustrated computing environment (10) includes a computing device (12). In one embodiment, the computing device (12) may be a device for implementing the vulnerability detection system of the disclosed embodiment. Furthermore, the computing device (12) may be a device for implementing the deception system of the disclosed embodiment. Furthermore, the computing device (12) may be a device for implementing the integrated monitoring system of the disclosed embodiment.

[0033] A computing device (12) includes at least one processor (14), a computer-readable storage medium (16), and a communication bus (18). The processor (14) may cause the computing device (12) to operate according to the exemplary embodiments mentioned above. For example, the processor (14) may execute one or more programs stored in the computer-readable storage medium (16). The one or more programs may include one or more computer-executable instructions, which, when executed by the processor (14), may be configured to cause the computing device (12) to perform operations according to the exemplary embodiments.

[0034] A computer-readable storage medium (16) is configured to store computer-executable instructions or program code, program data, and / or other suitable forms of information. A program (20) stored in the computer-readable storage medium (16) includes a set of instructions executable by the processor (14). In one embodiment, the computer-readable storage medium (16) may be a memory (volatile memory such as random access memory, non-volatile memory, or a suitable combination thereof), one or more magnetic disk storage devices, optical disk storage devices, flash memory devices, any other form of storage medium that can be accessed by the computing device (12) and store desired information, or a suitable combination thereof.

[0035] A communication bus (18) interconnects various other components of the computing device (12), including the processor (14) and computer-readable storage media (16).

[0036] The computing device (12) may also include one or more input / output interfaces (22) that provide interfaces for one or more input / output devices (24) and one or more network communication interfaces (26). The input / output interfaces (22) and the network communication interfaces (26) are connected to the communication bus (18). The input / output devices (24) may be connected to other components of the computing device (12) via the input / output interfaces (22). Exemplary input / output devices (24) may include input devices such as pointing devices (such as a mouse or a trackpad), a keyboard, a touch input device (such as a touchpad or a touchscreen), a voice or sound input device, various types of sensor devices and / or photographing devices, and / or output devices such as display devices, printers, speakers and / or network cards. The exemplary input / output devices (24) may be included within the computing device (12) as a component constituting the computing device (12), or may be connected to the computing device (12) as a separate device distinct from the computing device (12).

[0037] While representative embodiments of the present invention have been described in detail above, those skilled in the art will appreciate that various modifications to the above-described embodiments are possible without departing from the scope of the present invention. Therefore, the scope of the present invention should not be limited to the described embodiments, but should be defined not only by the claims set forth below but also by equivalents thereof.

Claims

1. One or more processors, and A method performed on a computing device having a memory storing one or more programs executed by one or more processors, Step of obtaining the binary of the program to be installed on the medical device; A step of analyzing the binary of the above program to generate a Software Bill of Materials (SBOM) of the above program; A step of scanning vulnerabilities in the SBOM of the above program and storing the scanned vulnerabilities; and A method comprising the step of performing at least one of a security test and a fuzzing test on a binary of the above program.

2. In claim 1, The above method, A method further comprising a step of analyzing vulnerabilities according to a preset cycle in the SBOM of the above program.

3. In claim 1, The above method, A method further comprising the step of constructing a deception system comprising one or more traps in the same environment as the medical device.

4. A security system including a vulnerability detection system for the security of medical devices, The above vulnerability detection system, A security system that obtains a binary of a program installed in a medical device, analyzes the binary of the program to generate a Software Bill of Materials (SBOM) of the program, scans the SBOM of the program for vulnerabilities, stores the scanned vulnerabilities, and performs at least one of a security test and a fuzzing test on the binary of the program.

5. In claim 4, The above security system, A security system further comprising a deception system having one or more traps in the same environment as the medical device through virtualization technology.

6. In claim 5, The above security system, A security system further comprising an integrated monitoring system that receives and manages information from at least one of the vulnerability detection system and the deception system.

Citation Information

Patent Citations

  • Method for integrating software bill of material (SBOM) to assembly line

    CN117892267A

  • Risk assessment based on augmented software bill of materials

    US20230359992A1

  • Control flow prevention using software bill of materials analysis

    US20240031394A1