{"id":28625,"date":"2018-08-14T15:08:53","date_gmt":"2018-08-14T14:08:53","guid":{"rendered":"http:\/\/www.intelligentcio.com\/me\/2018\/08\/14\/mcafee-releases-new-research-on-cyberthreat-to-medical-devices\/"},"modified":"2018-08-15T08:53:07","modified_gmt":"2018-08-15T07:53:07","slug":"mcafee-releases-new-research-on-cyberthreat-to-medical-devices","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2018\/08\/14\/mcafee-releases-new-research-on-cyberthreat-to-medical-devices\/","title":{"rendered":"McAfee releases new research on cyberthreat to medical devices"},"content":{"rendered":"<p><a href=\"http:\/\/www.mcafee.com\/\">McAfee\u2019s<\/a>\u00a0Advanced Threat Research team\u00a0has released two pieces of new research that reveal undiscovered links among major\u00a0North\u00a0Korean threat actors and malware families, as well as stunning revelations about the real cyberthreat risks to medical devices.<\/p>\n<p>The research was announced during Black Hat USA 2018, which took place between August 4 and 9.<\/p>\n<p>Douglas McKee, Senior Security Researcher for the McAfee Advanced Threat Research team, also outlined research on cyber-risks to medical devices in a blog on the cybersecurity firm\u2019s website.<\/p>\n<p>McAfee\u2019s research team discovered a weakness in one of the networking protocols used by medical devices to monitor a patient&#8217;s condition and vitals. This protocol is utilised in some of the most critical systems used in hospitals.<\/p>\n<p>The weakness discovered allows data to be modified by an attacker in real-time to provide false information to medical personnel. Lack of authentication also allows rogue devices to be placed onto the network and mimic patient monitors.<\/p>\n<p>For this attack to be viable, an attacker would need to be on the same network as the devices and have knowledge of the networking protocol. Any modifications made to patient data would need to be believable to medical professionals for there to be any impact.<\/p>\n<p>The research also outlined the general lack of security mitigations in the medical devices field, the risks they pose, and techniques to address them.<\/p>\n<p>McKee wrote: \u201cDuring our research we did not modify the patient monitor, which always showed the true data, but we have proven the impact of an attack can be meaningful. Such an attack could result in patients receiving the wrong medications, additional testing and extended hospital stays \u2013 any of which could incur unnecessary expenses.\u201d<\/p>\n<p>Both product vendors and medical facilities can take measures to drastically reduce the threat of this type of attack, he said.<\/p>\n<p>Vendors can encrypt network traffic between the devices and add authentication.These two steps would drastically increase the difficulty of this type of attack.<\/p>\n<p>Vendors also typically recommend that medical equipment is run on a completely isolated network with very strict network-access controls. If medical facilities follow these recommendations, attackers would require physical access to the network, greatly helping to reduce the attack surface.<\/p>\n<p>McKee added: \u201cOne goal of the McAfee Advanced Threat Research team is to identify and illuminate a broad spectrum of threats in today&#8217;s complex and constantly evolving landscape.<\/p>\n<p>\u201cThrough responsible disclosure we aim to assist and encourage the industry toward a more comprehensive security posture. As part of our policy, we reported this research to the vendor whose products we tested and will continue to work with other vendors to help secure their products.\u201d<\/p>\n<p><strong>U<\/strong><strong>ndiscovered links between\u00a0North\u00a0Korea\u2019s malware families<\/strong><\/p>\n<p>Meanwhile, joint research from\u00a0McAfee\u00a0and Intezer revealed undiscovered links between\u00a0North\u00a0Korea\u2019s malware families and some of the largest and most successful cyberattacks to date.<\/p>\n<p>The research was carried out in a joint effort by Jay Rosenberg, Senior Security Researcher at Intezer and Christiaan Beek, Lead Scientist and Senior Principal Engineer at McAfee.<\/p>\n<p>The researchers examined code re-use from the major threat actors believed to be tied to\u00a0North\u00a0Korea,\u00a0such as Lazarus and Hidden Cobra, malware attack campaigns including WannaCry, the Mydoom variant Brambul and recent cryptocurrency attacks. It uncovered a new connection between them.<\/p>\n<p>Four\u00a0examples of reused code in\u00a0larger-scale nationalism-motivated campaigns were discovered to only be seen in malware attributed to\u00a0North\u00a0Korea.<\/p>\n<p>In their post, the researchers said: \u201cSecurity vendors and researchers often use different names when speaking about the same malware, group or attack. This habit makes it challenging to group all the malware and campaigns.<\/p>\n<p>\u201cBy taking a scientific approach, such as looking for code reuse, we can categorise our findings.&#8221;<\/p>\n<p>For more information on the research, visit<\/p>\n<p><a href=\"https:\/\/securingtomorrow.mcafee.com\/mcafee-labs\/examining-code-reuse-reveals-undiscovered-links-among-north-koreas-malware-families\/\">https:\/\/securingtomorrow.mcafee.com\/mcafee-labs\/examining-code-reuse-reveals-undiscovered-links-among-north-koreas-malware-families\/<\/a><\/p>\n<p><a href=\"https:\/\/securingtomorrow.mcafee.com\/mcafee-labs\/80-to-0-in-under-5-seconds-falsifying-a-medical-patients-vitals\/\">https:\/\/securingtomorrow.mcafee.com\/mcafee-labs\/80-to-0-in-under-5-seconds-falsifying-a-medical-patients-vitals\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>McAfee\u2019s\u00a0Advanced Threat Research team\u00a0has released two pieces of new research that reveal undiscovered links among major\u00a0North\u00a0Korean threat actors and malware families, as well as stunning revelations about the real cyberthreat risks to medical devices. The research was announced during Black Hat USA 2018, which took place between August 4 and 9. Douglas McKee, Senior Security [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":28626,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,809,38],"tags":[6334,6335,159,1530,1641,6336,5985,6337,6338,6339,6340,104,2761,6341,6342,6301,6343],"class_list":["post-28625","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-more-news","category-networking","tag-advanced-threat-research","tag-black-hat-usa-2018","tag-cyberattacks","tag-cybersecurity","tag-cyberthreat","tag-douglas-mckee","tag-hidden-cobra","tag-intezer","tag-jay-rosenberg","tag-lazarus","tag-lead-scientist-and-senior-principal-engineer","tag-malware","tag-mcafee","tag-medical-devices","tag-north-korea","tag-senior-security-researcher","tag-senior-security-researcher-at-intezer-and-christiaan-beek"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/28625","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=28625"}],"version-history":[{"count":0,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/28625\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/28626"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=28625"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=28625"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=28625"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}