Insulin pumps, monitors vulnerable to hacking

August 4, 2011 By JORDAN ROBERTSON , AP Technology Writer in Medical research

(AP) -- Even the human bloodstream isn't safe from computer hackers.

A security researcher who is diabetic has identified flaws that could allow an attacker to remotely control insulin pumps and alter the readouts of blood-sugar monitors. As a result, diabetics could get too much or too little insulin, a hormone they need for proper metabolism.

Jay Radcliffe, a diabetic who experimented on his own equipment, shared his findings with The Associated Press before releasing them Thursday at the Black Hat in Las Vegas.

"My initial reaction was that this was really cool from a technical perspective," Radcliffe said. "The second reaction was one of maybe sheer terror, to know that there's no security around the devices which are a very active part of keeping me alive."

Increasingly, medical devices such as , operating room monitors and surgical instruments including deep-brain stimulators are being made with the ability to transmit vital health information from a patient's body to doctors and other professionals. Some devices can be remotely controlled by medical professionals.

Although there's no evidence that anyone has used Radcliffe's techniques, his findings raise fears about the safety of medical devices as they're brought into the Internet age. Serious attacks have already been demonstrated against pacemakers and defibrillators.

Medical device makers downplay the threat from such attacks. They argue that the demonstrated attacks have been performed by skilled security researchers and are unlikely to occur in the real world.

But hacking is like athletics. Showing that a far-fetched attack is possible is like cracking the 4-minute mile. Once someone does it, others often follow. Free or inexpensive programs eventually pop up online to help malicious hackers automate obscure attacks.

Though there has been a push to automate medical devices and include wireless chips, the devices are typically too small to house processors powerful enough to perform advanced encryption to scramble their communications. As a result, most devices are vulnerable.

Radcliffe wears an insulin pump that can be used with a special remote control to administer insulin. He found that the pump can be reprogrammed to respond to a stranger's remote. All he needed was a USB device that can be easily obtained from eBay or medical supply companies. Radcliffe also applied his skill for eavesdropping on computer traffic. By looking at the data being transmitted from the computer with the USB device to the insulin pump, he could instruct the USB device to tell the pump what to do.

Radcliffe, who is 33 and lives in Meridian, Idaho, tested only one brand of insulin pump - his own - but said others could be vulnerable as well.

Although an attacker would need to be within a couple hundred feet of the patient to pull this off, a stranger wandering a hospital or sitting behind a target on an airplane would be close enough.

Radcliffe also found that it was possible to tamper with a second device he wears. He found that he could intercept signals sent wirelessly from a sensor to a machine that displays blood-sugar levels. By broadcasting a signal that is stronger than the real-time, authentic readings, the monitor would be tricked into displaying old information over and over. As a result, a patient who didn't notice wouldn't adjust insulin dosage properly.

With a powerful enough antenna, Radcliffe said, an attacker could be up to half a mile away. This attack worked on two different blood-sugar monitors, Radcliffe said.

"Everybody's pushing the technology to do more and more and more, and like any technology that's pushed like that, security is an afterthought," Radcliffe said.

Radcliffe refused to identify any of the three device makers, in part out of concern for his own safety. He is concerned that the devices don't appear to have an easy way to be updated with new software to fix the problems. He said he intends to notify the manufacturers after Thursday's presentation outlining the weaknesses.

The hacking fears come on top of human errors and technical glitches tied to medical devices. The U.S. Food and Drug Administration has identified software and design errors as critical concerns in investigating hundreds of deaths potentially linked to drug pumps.

FDA officials declined to comment specifically on Radcliffe's findings, saying they hadn't seen the research. But the FDA said that any medical device with wireless communication components can fall victim to eavesdropping. It warns device makers that they are responsible for making sure they can update equipment after it's sold.

Industry officials downplay the potential threat.

"The risk to a patient with diabetes of having their monitors hacked is extraordinarily small, and there's a great health risk of not monitoring than the risk of being hacked," said Wanda Moebius, a vice president at the Advanced Medical Technology Association, an industry group.

Few public studies have been done on the susceptibility of medical devices to hacking.

One such study, which appeared in 2008 from a consortium of academics, found that a popular type of device that acted as both a pacemaker and defibrillator could be remotely reprogrammed to deliver potentially deadly shocks or run out its battery.

The problem was the way the device transmitted data unencrypted and accepted commands wirelessly from unauthorized devices. One limitation of the study was that researchers only examined an attack from a few centimeters away from the targeted device.

Yoshi Kohno, a University of Washington professor of computer science who was a co-author of that study, said that Radcliffe's new research reinforces the urgency of addressing security issues in before attacks move out of research labs.

"The threat hasn't manifested yet, so what they and we are trying to do is see what the risk could be in the future," said Kohno, who wasn't part of Radcliffe's research.

Radcliffe said the point of his research is not to alarm people. He said the issues he's discovered are important to address publicly as the medical industry moves aggressively toward more networked devices.

"It would only take one person to do this to kill someone and then you have a catastrophe," he said.

©2011 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

not rated yet  

Filter


Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

antialias_physorg
Aug 04, 2011

Rank: 1 / 5 (1)
The risk to a patient with diabetes of having their monitors hacked is extraordinarily small, and there's a great health risk of not monitoring than the risk of being hacked

This is a false dichotomy if ever I saw one. The alternative not being hacked is not to forego monitoring. It is to increase security.

Since the data passed between monitor and insulin pump is not much over the lifetime of the devices and they only need to transmit stuff in 'clear' when interfacing with special hospital hardware it's perfectly simple to upload both with a set of random numbers for completely unhackable one-time-pad functionality.
antonima
Aug 04, 2011

Rank: not rated yet
I agree that its important to increase security, but frankly, if it wasn't for this one researcher and his publicist, NO ONE WOULD KNOW ABOUT IT. And now, hundreds of thousands if not millions of tech interested persons have the information. Good going, assholes! I'm sure you'll get a grant now!
antialias_physorg
Aug 04, 2011

Rank: 1 / 5 (1)
NO ONE WOULD KNOW ABOUT IT

Not true. Just yesterday my coworkers and I were discussing this very problem over lunch (I work for a company that develops hardware/software for the medical industry - albeit not such vital/security sensitive stuff).
The lack of security in such devices is known to anyone working in that area.

What you advocate is called 'security by obscurity' which is widely derided as the worst form of security possible.
Rank not rated yet
Related Stories
Relevant PhysicsForums posts
  • A question about drug tolerance
    createdMay 23, 2012
  • Poor nutrition leading to overeating?
    createdMay 23, 2012
  • Math and dyslexia?
    createdMay 21, 2012
  • portable metabolism meter?
    createdMay 21, 2012
  • Rare medical conditions on 20/20 tonight
    createdMay 18, 2012
  • "Good" Cholesterol in Doubt
    createdMay 17, 2012
  • More from Physics Forums - Medical Sciences

More news stories

Implantable pain disk may help those with cancer

An estimated 3.5 million cancer patients around the globe are in severe pain from their disease, but many get no relief.

Medical research created 12 hours ago | popularity not rated yet | comments 0 | with audio podcast

Energy levels link sleep control mechanisms

Sleep, or lack of it, can determine level of cognitive performance which is linked with accidents as well as increased risk of serious health problems. Links between cell energy levels, gene transcription ...

Medical research created 14 hours ago | popularity not rated yet | comments 0

Researchers identify key brain cell in antidepressant action

(Medical Xpress) -- Antidepressant medications such as Prozac have helped improve mood and lessen anxiety in millions of people with major depression. But scientists know surprisingly little about how these drugs work.

Medical research created 14 hours ago | popularity 4 / 5 (1) | comments 0 | with audio podcast

Rockefeller scientists pioneer new method to determine mechanisms of drug action

(Medical Xpress) -- Knowing that a drug works is great. Knowing how it works is a luxury. And until now, determining a drug’s mechanism of action has been a tedious and difficult process for scientists.

Medical research created 14 hours ago | popularity not rated yet | comments 0 | with audio podcast

Like curry? New biological role identified for compound used in ancient medicine

Scientists have just identified a new reason why some curry dishes, made with spices humans have used for thousands of years, might be good for you.

Medical research created 22 hours ago | popularity 4.3 / 5 (9) | comments 2 | with audio podcast


Of mice and mental models: Neuroscientific implications of risk-optimized behavior in the mouse

(Medical Xpress) -- Regardless of an organism’s biological complexity, every encephalized animal continuously makes under-informed behavioral choices that can have serious consequences. Despite its ubiquity, ...

Tongue analysis software uses ancient Chinese medicine to warn of disease

For 5,000 years, the Chinese have used a system of medicine based on the flow and balance of positive and negative energies in the body. In this system, the appearance of the tongue is one of the measures used to classify ...

Cancer may require simpler genetic mutations than previously thought

Chromosomal deletions in DNA often involve just one of two gene copies inherited from either parent. But scientists haven't known how a deletion in one gene from one parent, called a "hemizygous" deletion, can contribute ...

Inherited DNA change explains overactive leukemia gene

A small inherited change in DNA is largely responsible for overactivating a gene linked to poor treatment response in people with acute leukemia.

Skp2 activates cancer-promoting, glucose-processing Akt

HER2 and its epidermal growth factor receptor cousins mobilize a specialized protein to activate a major player in cancer development and sugar metabolism, scientists report in the May 25 issue of Cell.

Early physical therapist treatment associated with reduced risk of healthcare utilization and reduced overall healthcare

A new study published in Spine shows that early treatment by a physical therapist for low back pain (LBP), as compared to delayed treatment, was associated with reduced risk of subsequent healthcare utilization and lower ...