DICOMHawk: A Cyber Deception Framework for Medical Imaging Infrastructure

📅 2026-07-17
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This work addresses the vulnerability of medical imaging infrastructures to targeted attacks and the limitations of existing defensive tools, which often exhibit low interactivity and are easily identifiable. To overcome these challenges, the authors propose a high-fidelity network deception framework that emulates highly interactive DICOM/PACS services, dynamically generates realistic medical imaging data, and embeds stealthy honeypots. The framework supports coordinated, long-term deployment across multiple nodes while effectively evading fingerprinting techniques. During a real-world deployment spanning 347 days, the system captured 49 targeted attacks against medical infrastructure, attracted numerous legitimate-looking sessions, and significantly outperformed Dicompot in both engagement and stealth—remaining undetected as a honeypot throughout the evaluation period. This approach substantially enhances the capability to lure, capture, and analyze sophisticated adversarial activities targeting healthcare systems.
📝 Abstract
Cyber-attacks against exposed healthcare infrastructure threaten sensitive patient data and clinical operations, yet existing defensive tools for DICOM-based medical imaging systems provide limited interaction and are easily fingerprinted. We introduce DICOMHawk, a cyber-deception framework that emulates DICOM and PACS services using realistic interactions, dynamically populated medical records, and embedded honeytokens. In an 86-day comparison and a 347-day deployment across multiple networks, DICOMHawk attracted more valid sessions than Dicompot, avoided honeypot detection, and captured 49 medical-related attacks. The results show that realistic, long-term, multi-location deception improves visibility into threats targeting medical imaging systems.
Problem

Research questions and friction points this paper is trying to address.

cyber-attacks
DICOM
medical imaging infrastructure
honeypot detection
healthcare security
Innovation

Methods, ideas, or system contributions that make the work stand out.

cyber deception
DICOM
honeypot
PACS
honeytokens
🔎 Similar Papers
No similar papers found.
K
Karina Elzer
Technical University of Denmark
A
Alberto Mongardini
Technical University of Denmark
R
Ricardo Yaben
Technical University of Denmark
G
Georgios Theodoridis
CSIS
A
Alexandra Babanuta
Technical University of Denmark
N
Nawras Mouala
Technical University of Denmark
Emmanouil Vasilomanolakis
Emmanouil Vasilomanolakis
Associate Professor, Technical University of Denmark (DTU)
intrusion detectionhoneypotsbotnetsdeception