How STRIDE Framework Can Be Applied to Secure ECG Medical Devices
A structured threat modelling exercise demonstrates how the STRIDE framework can be used to identify cybersecurity risks in electrocardiogram (ECG) devices used in clinical settings. The model breaks down an ECG system into key components — from electrodes and signal processors to network interfaces and electronic health record systems — and maps trust boundaries across each layer. Six threat categories are examined: spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege, each carrying distinct risks to patient data integrity and care delivery. For example, tampering with ECG signals could lead to false diagnoses, while denial-of-service attacks could disrupt real-time cardiac monitoring. Mitigations are aligned with established frameworks including OWASP Threat Modeling guidelines, NIST SP 800-53 Rev. 5, and ISO/IEC 27001, making the model a practical educational resource for medical device security professionals.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in