Poster-Medical Protocol Security: DICOM Vulnerability Mining Based on Fuzzing Technology

被引:4
作者
Wang, Zhiqiang [1 ,2 ,3 ]
Li, Quanqi [1 ]
Wang, Yazhe [1 ]
Liu, Biao [1 ]
Zhang, Jianyi [1 ]
Liu, Qixu [4 ]
机构
[1] Beijing Eletron Sci & Technol Inst, Beijing, Peoples R China
[2] State Key Lab Cryptol, Beijing, Peoples R China
[3] State Informat Ctr, Beijing, Peoples R China
[4] Chinese Acad Sci, Key Lab Network Assessment Technol, Inst Informat Engn, Beijing, Peoples R China
来源
PROCEEDINGS OF THE 2019 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'19) | 2019年
关键词
DICOM; Fuzzing; PACS; Medical information security;
D O I
10.1145/3319535.3363253
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
DICOM is an international standard for medical images and related information, and is a medical image format that can be used for data exchange. The agreement is widely used in medical fields such as radiology and cardiovascular imaging. However, since DICOM libraries have less security considerations in protocol implementation, they have a large number of security risks. Aiming at the security issue of DICOM libraries, the paper conducts research on vulnerability mining technology for DICOM open source libraries, proposes a vulnerability mining framework based on Fuzzing technology, and implements a prototype system named DICOM-Fuzzer, which includes initialization, test case generation, automatic test, exception monitoring and other modules. Finally, the open source library DCMTK was selected for testing, and it was found that data overflow would occur when the content of the received file was greater than 7080 lines. Found that there is a vulnerability that causes the PACS system to refuse service. In conclusion, the DICOM protocol does have risks, and its information security needs to be further improved.
引用
收藏
页码:2549 / 2551
页数:3
相关论文
共 7 条
[1]  
Aizatsky Mike, 2016, Continuous fuzzing for open source software
[2]   A systematic review of fuzzing techniques [J].
Chen, Chen ;
Cui, Baojiang ;
Ma, Jinxin ;
Wu, Runpu ;
Guo, Jianchao ;
Liu, Wenqian .
COMPUTERS & SECURITY, 2018, 75 :118-137
[3]  
Duggal A, 2017, 8 ANN HITB SEC C
[4]  
Eichelberg M, 2011, DIGITAL IMAGING COMM
[5]   The Information Security Needs in Radiological Information Systems-an Insight on State Hospitals of Iran, 2012 [J].
Farhadi, Akram ;
Ahmadi, Maryam .
JOURNAL OF DIGITAL IMAGING, 2013, 26 (06) :1040-1044
[6]  
Food US and Administration Drug, 2013, CONT PREM SUBM MAN C, V1, P2014
[7]   CollAFL: Path Sensitive Fuzzing [J].
Gan, Shuitao ;
Zhang, Chao ;
Qin, Xiaojun ;
Tu, Xuwen ;
Li, Kang ;
Pei, Zhongyu ;
Chen, Zuoning .
2018 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2018, :679-696