Black Hat USA 2018 - Understanding and Exploiting Implanted Medical Devices @HackersOnBoard
Black Hat USA 2018 - Understanding and Exploiting Implanted Medical Devices  @HackersOnBoard
Uploaded October 2019 | Updated September 2026, 2 hours ago
There has been significant attention recently surrounding the risks associated with cyber vulnerabilities in critical medical devices. Understandably, people are concerned that an attacker may exploit a vulnerability to modify the delivery of patient therapy, such as altering the dosage of medicine, delivering insulin therapy, or administering a shock via a pacemaker. These concerns raise several questions, such as: How do these devices work? What does the typical attack surface for implanted medical device look like? What do exploits against these systems look like? How do manufacturers respond to potentially life-threatening security issues? This presentation will address all these questions.

This presentation is the culmination of an 18-month independent case study in implanted medical devices. The presenters will provide detailed technical findings on remote exploitation of a pacemaker systems, pacemaker infrastructure, and a neurostimulator system. Exploitation of these vulnerabilities allow for the disruption of therapy as well as the ability to execute shocks to a patient.

The researchers followed coordinated disclosure policies in an attempt to help mitigate the security concerns. What followed was an 18-month roller coaster of unresponsiveness, technical inefficiencies and misleading reactions. The researchers will walk the audience through the details of disclosure and discuss the responses from the manufacturer and coordination associated with DHS ICS-CERT and the FDA. How did the manufacturer initially respond? What tactics did the manufacturer use to attempt to dismiss the independent researchers? Was the response by the manufacturer adequate from a patient responsibility standpoint? Has the actual technical vulnerability even been addressed?
Black Hat USA 2018 - Understanding and Exploiting Implanted Medical DevicesDEF CON 27 - Panel - Hacking Congress The Enemy Of My Enemy Is My FriendDEF CON 27 - Ali Islam - Weaponizing Hypervisors to Fight and Beat Car and Medical Devices AttacksAttacks on the Curl-P Hash Function Leading to Signature Forgeries in the IOTA Signature SchemeDEF CON 27 - Elie Bursztein - How Deep Learning Is Revolutionizing Side-Channel CryptanalysisBlack Hat USA 2018 - Breaking the IIoT Hacking industrial Control GatewaysDEF CON 27 - Contests and Events - Contests Awards CeremonyDEF CON 27 - Ariel Herbert-Voss - Dont Red-Team AI Like a ChumpDEF CON 27 - How To Improve Coverage-Guided Fuzzing and Find New 0days in Tough TargetsMoney-rity Report Using Intelligence to Predict the Next Payment Card Fraud VictimsNone of My Pixel is Your Business Active Watermarking Cancellation Against Video Streaming ServiceBlack Hat USA 2018 - GOD MODE UNLOCKED - Hardware Backdoors in x86 CPUs
HackersOnBoard |

Black Hat USA 2018 - Understanding and Exploiting Implanted Medical Devices

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER