Back to results

University of Illinois Urbana-Champaign

A demonstration of holes in the unified security in the internet of medical things

Abstract

dc:description

The internet of medical things (IoMT) is a subset of the internet of things focused on medical devices. Its ecosystem is comprised of everything from disposable wearable devices that cost tens or hundreds of USD to hospital equipment worth thousands of USD. As with virtually every facet of the modern world, these devices are becoming increasingly networked. With this growth comes an expanded attack surface: rather than needing to access a physician’s office or a hospital room to steal a patient’s medical information or change the settings on an infusion pump, an adversary can now take advantage of remote access capabilities to launch an attack from anywhere with internet access. While IoMT devices inherit the intrinsic vulnerabilities of their more generic IoT brethren, also they have their unique concerns, including the sensitivity of medical data, and potential health impact of device exploitation, making it crucial to ensure the security of each device and its communications. Because of their limited size and compute capacity, in situ analysis is often difficult or impossible. Many of these devices are designed for short lifespans, making firmware updates unnecessary. Without channels intended for software delivery, simply obtaining copies of the firmware for external analysis can be a challenge in its own right. This thesis examines the threats to IoMT devices and investigates tools and tactics to analyze both device and data security. To achieve this, we develop a taxonomy of cybersecurity threats, examine a swatch of available reconnaissance tools, explore both simulation and emulation options, and analyze devices from opposite ends of the IoMT spectrum.

Degree

thesis:*
Name thesis:degree_name
M.S.
Level thesis:degree_level
Thesis
Discipline thesis:degree_discipline
Computer Science
Grantor
University of Illinois Urbana-Champaign
Year dc:date
2025

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Battista, Jude
Contributors dc:contributor
  • Nahrstedt, Klara

Subjects

dc:subject × 3

Rights

dc:rights
Statement dc:rights
  • Copyright 2025 Jude Battista
Language dc:language
en

Identifiers

dc:identifier.*
Handle dc:identifier
https://hdl.handle.net/2142/132606
OAI identifier oai:identifier
oai:www.ideals.illinois.edu:2142/132606

Chain of custody

source
Harvested from
University of Illinois - Urbana-Champaign
Base URL
www.ideals.illinois.edu/oai-pmh
Last updated
2026-07-22
Source record
OAI-PMH GetRecord
citation

Battista, Jude. A demonstration of holes in the unified security in the internet of medical things. Thesis thesis, University of Illinois Urbana-Champaign, 2025. https://hdl.handle.net/2142/132606