Securing the Internet of Medical Things (IoMT): Real-World Attack Taxonomy and Practical Security Measures

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Deb, Suman, Lupu, Emil, Drakakis, Emm Mic, Bharath, Anil Anthony, Leung, Zhen Kit, Ma, Guang Rui, Chattopadhyay, Anupam
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908468232847360
author Deb, Suman
Lupu, Emil
Drakakis, Emm Mic
Bharath, Anil Anthony
Leung, Zhen Kit
Ma, Guang Rui
Chattopadhyay, Anupam
author_facet Deb, Suman
Lupu, Emil
Drakakis, Emm Mic
Bharath, Anil Anthony
Leung, Zhen Kit
Ma, Guang Rui
Chattopadhyay, Anupam
contents The Internet of Medical Things (IoMT) has the potential to radically improve healthcare by enabling real-time monitoring, remote diagnostics, and AI-driven decision making. However, the connectivity, embedded intelligence, and inclusion of a wide variety of novel sensors expose medical devices to severe cybersecurity threats, compromising patient safety and data privacy. In addition, many devices also have direct capacity - individually or in conjunction with other IoMT devices - to perform actions on the patient, such as delivering an electrical stimulus, administering a drug, or activating a motor, which can potentially be life-threatening. We provide a taxonomy of potential attacks targeting IoMT, presenting attack surfaces, vulnerabilities, and mitigation strategies across all layers of the IoMT architecture. It answers key questions such as: What makes IoMT security different from traditional IT security? What are the cybersecurity threats to medical devices? How can engineers design secure IoMT systems and protect hospital networks from cyberattacks? By analyzing historical cyber incidents, we highlight critical security gaps and propose practical security guidelines for medical device engineers and security professionals. This work bridges the gap between research and implementation, equipping healthcare stakeholders with actionable insights to build resilient and privacy-preserving IoMT ecosystems. Finally, we present the latest standardization and compliance frameworks, that IoMT security designers should be aware of.
format Preprint
id arxiv_https___arxiv_org_abs_2507_19609
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Securing the Internet of Medical Things (IoMT): Real-World Attack Taxonomy and Practical Security Measures
Deb, Suman
Lupu, Emil
Drakakis, Emm Mic
Bharath, Anil Anthony
Leung, Zhen Kit
Ma, Guang Rui
Chattopadhyay, Anupam
Cryptography and Security
The Internet of Medical Things (IoMT) has the potential to radically improve healthcare by enabling real-time monitoring, remote diagnostics, and AI-driven decision making. However, the connectivity, embedded intelligence, and inclusion of a wide variety of novel sensors expose medical devices to severe cybersecurity threats, compromising patient safety and data privacy. In addition, many devices also have direct capacity - individually or in conjunction with other IoMT devices - to perform actions on the patient, such as delivering an electrical stimulus, administering a drug, or activating a motor, which can potentially be life-threatening. We provide a taxonomy of potential attacks targeting IoMT, presenting attack surfaces, vulnerabilities, and mitigation strategies across all layers of the IoMT architecture. It answers key questions such as: What makes IoMT security different from traditional IT security? What are the cybersecurity threats to medical devices? How can engineers design secure IoMT systems and protect hospital networks from cyberattacks? By analyzing historical cyber incidents, we highlight critical security gaps and propose practical security guidelines for medical device engineers and security professionals. This work bridges the gap between research and implementation, equipping healthcare stakeholders with actionable insights to build resilient and privacy-preserving IoMT ecosystems. Finally, we present the latest standardization and compliance frameworks, that IoMT security designers should be aware of.
title Securing the Internet of Medical Things (IoMT): Real-World Attack Taxonomy and Practical Security Measures
topic Cryptography and Security
url https://arxiv.org/abs/2507.19609