4/17 (四) 10:15 - 10:45 7F 701H

Protecting Medical Data: The Risk of DICOM File Attacks on PACS Servers

Picture Archiving and Communication System (PACS) servers are crucial for managing patient imaging data in medical institutions. This presentation explores the essential functions of PACS servers and the structure of DICOM (Digital Imaging and Communications in Medicine) files, emphasizing the importance of unique identifiers.

We discuss the processing and transmission of DICOM files using various protocols and uncover significant privacy and security risks associated with exposed PACS servers and DICOM files on the internet.

Our research has identified multiple vulnerabilities in PACS servers, including use-after-free, stack-based buffer overflow, and path traversal, which could disrupt medical operations or result in the deletion of patient data.

The goal of this presentation is to raise security awareness and provide practical mitigation strategies for medical staff and server developers to protect sensitive medical data.

Chizuru Toyama
講者
TXOne Networks Inc.
Senior Threat Researcher, Threat Research
Canaan Kao
講者
TXOne Networks Inc.
Threat Research Director, Threat Research

TOPIC / TRACK
Cyber-Physical System Security 論壇

LOCATION
臺北南港展覽二館
7F 701H

LEVEL
中階 中級議程聚焦在資安架構、工具與實務應用等,適合已經具備資安基礎的資安與資訊人員。

SESSION TYPE
Breakout Session

LANGUAGE
英文

SUBTOPIC
Healthcare Security
Cyber-Physical System Security
Vulnerability Research