Abstract
Healthcare systems are increasingly based on IoT architecture given their advantages it brings to the field, such as real-time monitoring of the patient's health status. However, the complexity of the IoT has increased the number of attack surfaces, jeopardising the security of confidential medical data. Some studies have highlighted the issues of security in IoT environments, but few have detailed the threats associated with the healthcare sector based on frameworks. This paper fills this gap by providing a comprehensive study in Internet of Medical Things (IoMT) using the MITRE ATT&CK matrix to identify and anticipate the techniques and tactics exploited by attackers against vulnerabilities in IoMT besides presenting a use case illustrating how attackers can endanger a patient's life by compromising a remote cardiac monitoring system following the Cyber Kill Chain. The study further highlights under-documented attack paths specific to healthcare IoT and proposes tailored technical and organizational mitigations. The novelty of this work lies in its integrated use of MITRE ATT&CK and the Cyber Kill Chain to put into perspective mapping of IoMT threats and a structured mitigation framework. This contribution provides a reference for security professionals to identify attack paths and build a model of security measures against cyber risk in IoMT.
Author supplied keywords
Cite
CITATION STYLE
Nadifi, Z., Ouaissa, M., Ouaissa, M., & Kartit, A. (2025). An Integrated Threat Modeling and Mitigation Framework for IoT Healthcare Using MITRE ATT&CK and Cyber Kill Chain Models. Ingenierie Des Systemes d’Information, 30(12), 3131–3141. https://doi.org/10.18280/isi.301205
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.