🤖 AI Summary
This work addresses the vulnerability of medical imaging infrastructures to targeted attacks and the limitations of existing defensive tools, which often exhibit low interactivity and are easily identifiable. To overcome these challenges, the authors propose a high-fidelity network deception framework that emulates highly interactive DICOM/PACS services, dynamically generates realistic medical imaging data, and embeds stealthy honeypots. The framework supports coordinated, long-term deployment across multiple nodes while effectively evading fingerprinting techniques. During a real-world deployment spanning 347 days, the system captured 49 targeted attacks against medical infrastructure, attracted numerous legitimate-looking sessions, and significantly outperformed Dicompot in both engagement and stealth—remaining undetected as a honeypot throughout the evaluation period. This approach substantially enhances the capability to lure, capture, and analyze sophisticated adversarial activities targeting healthcare systems.
📝 Abstract
Cyber-attacks against exposed healthcare infrastructure threaten sensitive patient data and clinical operations, yet existing defensive tools for DICOM-based medical imaging systems provide limited interaction and are easily fingerprinted. We introduce DICOMHawk, a cyber-deception framework that emulates DICOM and PACS services using realistic interactions, dynamically populated medical records, and embedded honeytokens. In an 86-day comparison and a 347-day deployment across multiple networks, DICOMHawk attracted more valid sessions than Dicompot, avoided honeypot detection, and captured 49 medical-related attacks. The results show that realistic, long-term, multi-location deception improves visibility into threats targeting medical imaging systems.