DICOMHawk: A Cyber Deception Framework for Medical Imaging Infrastructure
Open-source deception framework for medical imaging infrastructure aims to overcome fingerprinting limitations of current DICOM honeypots, giving defenders richer adversary intelligence.
Summary written by editorial AI · Source link below
arXiv:2607.15754v1 Announce Type: new Abstract: Cyber-attacks against exposed healthcare infrastructure threaten sensitive patient data and clinical operations, yet existing defensive tools for DICOM-based medical imaging systems provide limited interaction and are easily fingerprinted. We introduce DICOMHawk, a cyber-deception framework that emulates DICOM and PACS services using realistic interactions, dynamically populated medical records, and embedded honeytokens. In an 86-day comparison an
Editorial Analysis
Healthcare is a top target under NIS2; a credible DICOM honeypot can improve threat intelligence and early breach detection for hospitals and imaging centres.
If you operate healthcare infrastructure, pilot DICOMHawk alongside existing network monitoring to detect scanning and exploitation attempts.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at arXiv Crypto & Security in a new tab.
More from the Research Desk
- Is That Really My X-Ray? Measuring Internet-Exposed DICOM Services in the Presence of Deception20 Jul
- Characterizing Phishing Pages by JavaScript Capabilities20 Jul
- Intentional Electromagnetic Interference Attacks on Facial Recognition20 Jul
- DoSQ: A Cross-Layer Denial of Service Quality Attack by Exploiting Side Channels in 5G NR20 Jul
- Vogls: a Fast Interactive Full-timing Simulator for Pre-silicon Power Side-Channel Analysis20 Jul