{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/132606"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/132606","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"A demonstration of holes in the unified security in the internet of medical things","abstract":"The internet of medical things (IoMT) is a subset of the internet of things focused on medical devices. Its ecosystem is comprised of everything from disposable wearable devices that cost tens or hundreds of USD to hospital equipment worth thousands of USD. As with virtually every facet of the modern world, these devices are becoming increasingly networked. With this growth comes an expanded attack surface: rather than needing to access a physician’s office or a hospital room to steal a patient’s medical information or change the settings on an infusion pump, an adversary can now take advantage of remote access capabilities to launch an attack from anywhere with internet access. While IoMT devices inherit the intrinsic vulnerabilities of their more generic IoT brethren, also they have their unique concerns, including the sensitivity of medical data, and potential health impact of device exploitation, making it crucial to ensure the security of each device and its communications. Because of their limited size and compute capacity, in situ analysis is often difficult or impossible. Many of these devices are designed for short lifespans, making firmware updates unnecessary. Without channels intended for software delivery, simply obtaining copies of the firmware for external analysis can be a challenge in its own right. This thesis examines the threats to IoMT devices and investigates tools and tactics to analyze both device and data security. To achieve this, we develop a taxonomy of cybersecurity threats, examine a swatch of available reconnaissance tools, explore both simulation and emulation options, and analyze devices from opposite ends of the IoMT spectrum.","abstract_html":"The internet of medical things (IoMT) is a subset of the internet of things focused on medical devices. Its ecosystem is comprised of everything from disposable wearable devices that cost tens or hundreds of USD to hospital equipment worth thousands of USD. As with virtually every facet of the modern world, these devices are becoming increasingly networked. With this growth comes an expanded attack surface: rather than needing to access a physician’s office or a hospital room to steal a patient’s medical information or change the settings on an infusion pump, an adversary can now take advantage of remote access capabilities to launch an attack from anywhere with internet access. While IoMT devices inherit the intrinsic vulnerabilities of their more generic IoT brethren, also they have their unique concerns, including the sensitivity of medical data, and potential health impact of device exploitation, making it crucial to ensure the security of each device and its communications. Because of their limited size and compute capacity, in situ analysis is often difficult or impossible. Many of these devices are designed for short lifespans, making firmware updates unnecessary. Without channels intended for software delivery, simply obtaining copies of the firmware for external analysis can be a challenge in its own right. This thesis examines the threats to IoMT devices and investigates tools and tactics to analyze both device and data security. To achieve this, we develop a taxonomy of cybersecurity threats, examine a swatch of available reconnaissance tools, explore both simulation and emulation options, and analyze devices from opposite ends of the IoMT spectrum.","abstract_has_math":false,"creators":["Battista, Jude"],"institution":"University of Illinois Urbana-Champaign","degree_name":"M.S.","degree_level":"Thesis","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["Nahrstedt, Klara"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2025,"date_issued":"2025-12","date_published":"2025-12","updated_at":"2026-07-22T22:25:07Z","subjects":["Internet of Medical Things","Security","Privacy"],"languages":["en"],"rights":["Copyright 2025 Jude Battista"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/2142/132606","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Nahrstedt, Klara"]},{"key":"dc:creator","label":"Author","values":["Battista, Jude"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2025-12","2025-12-12"]},{"key":"dc:type","label":"Dc Type","values":["text","Thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.S."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Internet of Medical Things","Security","Privacy"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2025 Jude Battista"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://hdl.handle.net/2142/132606"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["The internet of medical things (IoMT) is a subset of the internet of things focused on medical devices. Its ecosystem is comprised of everything from disposable wearable devices that cost tens or hundreds of USD to hospital equipment worth thousands of USD. As with virtually every facet of the modern world, these devices are becoming increasingly networked. With this growth comes an expanded attack surface: rather than needing to access a physician’s office or a hospital room to steal a patient’s medical information or change the settings on an infusion pump, an adversary can now take advantage of remote access capabilities to launch an attack from anywhere with internet access. While IoMT devices inherit the intrinsic vulnerabilities of their more generic IoT brethren, also they have their unique concerns, including the sensitivity of medical data, and potential health impact of device exploitation, making it crucial to ensure the security of each device and its communications. Because of their limited size and compute capacity, in situ analysis is often difficult or impossible. Many of these devices are designed for short lifespans, making firmware updates unnecessary. Without channels intended for software delivery, simply obtaining copies of the firmware for external analysis can be a challenge in its own right. This thesis examines the threats to IoMT devices and investigates tools and tactics to analyze both device and data security. To achieve this, we develop a taxonomy of cybersecurity threats, examine a swatch of available reconnaissance tools, explore both simulation and emulation options, and analyze devices from opposite ends of the IoMT spectrum.","Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2026-02-19 without embargo terms","The student, Jude Battista, accepted the attached license on 2025-12-12 at 09:20.","The student, Jude Battista, submitted this Thesis for approval on 2025-12-12 at 09:26.","This Thesis was approved for publication on 2025-12-12 at 09:34.","DSpace SAF Submission Ingestion Package generated from Vireo submission #23145 on 2026-02-19 at 18:30:36"]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["A demonstration of holes in the unified security in the internet of medical things"]}]}],"canonical_facts":{"dc:contributor":["Nahrstedt, Klara"],"dc:creator":["Battista, Jude"],"dc:date":["2025-12","2025-12-12"],"dc:description":["The internet of medical things (IoMT) is a subset of the internet of things focused on medical devices. Its ecosystem is comprised of everything from disposable wearable devices that cost tens or hundreds of USD to hospital equipment worth thousands of USD. As with virtually every facet of the modern world, these devices are becoming increasingly networked. With this growth comes an expanded attack surface: rather than needing to access a physician’s office or a hospital room to steal a patient’s medical information or change the settings on an infusion pump, an adversary can now take advantage of remote access capabilities to launch an attack from anywhere with internet access. While IoMT devices inherit the intrinsic vulnerabilities of their more generic IoT brethren, also they have their unique concerns, including the sensitivity of medical data, and potential health impact of device exploitation, making it crucial to ensure the security of each device and its communications. Because of their limited size and compute capacity, in situ analysis is often difficult or impossible. Many of these devices are designed for short lifespans, making firmware updates unnecessary. Without channels intended for software delivery, simply obtaining copies of the firmware for external analysis can be a challenge in its own right. This thesis examines the threats to IoMT devices and investigates tools and tactics to analyze both device and data security. To achieve this, we develop a taxonomy of cybersecurity threats, examine a swatch of available reconnaissance tools, explore both simulation and emulation options, and analyze devices from opposite ends of the IoMT spectrum.","Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2026-02-19 without embargo terms","The student, Jude Battista, accepted the attached license on 2025-12-12 at 09:20.","The student, Jude Battista, submitted this Thesis for approval on 2025-12-12 at 09:26.","This Thesis was approved for publication on 2025-12-12 at 09:34.","DSpace SAF Submission Ingestion Package generated from Vireo submission #23145 on 2026-02-19 at 18:30:36"],"dc:format":["application/pdf"],"dc:identifier":["https://hdl.handle.net/2142/132606"],"dc:language":["en"],"dc:rights":["Copyright 2025 Jude Battista"],"dc:subject":["Internet of Medical Things","Security","Privacy"],"dc:title":["A demonstration of holes in the unified security in the internet of medical things"],"dc:type":["text","Thesis"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.S."],"thesis:institution_name":["University of Illinois Urbana-Champaign"]},"updated_at":"2026-07-22T22:25:07Z"}