Cyber-Immunity at the Core: Securing Biomedical Devices through Hardware-Level Machine Learning Defense
Hossein Sayadi, Zhangying He, Chelsea William Fernandes, Tahereh Miari · 2023
Healthcare cybersecurity is crucial for protecting hospitals’ networks and computing systems from malicious cyber-attacks. With the increasing motivation and capability of cyber attackers, it is necessary to secure the software and hardware infrastructure of biomedical computing systems used in healthcare. Due to the increasingly digitized nature of modern biomedical devices used in healthcare systems, effective cybersecurity solutions have become more essential. Traditional security protocols focused on software-level protection, with the underlying hardware assumed to be secure. However, recent studies have revealed vulnerabilities in hardware that attackers can exploit to compromise computing systems. To address this, in this paper a bottom-up approach is proposed, delegating security to the underlying hardware to enhance the security and cost-efficiency with less visibility to the attacker. This paper aims to develop effective intelligent countermeasures for hardware-assisted cyber-security at run-time in biomedical devices. It leverages processors’ performance events via Hardware Performance Counters (HPCs) combined with Machine Learning (ML) techniques to fortify biomedical devices at the hardware level. To achieve this objective, we introduce a tailored and cost-effective hardware monitoring framework, complemented by a machine learning-enabled methodology. This approach enhances the accuracy and efficiency of malware detection and identification using real-time data from biomedical processors’ hardware events. The experimental results demonstrate that the XGBoost model, using 4 hardware events, excels in malware detection, boasting 95% detection rate (F-measure and Accuracy), efficient resource utilization, and low inference latency. Additionally, the ExtraTree classifier achieves 87% F-measure and exhibits swift performance in classifying malware types in real-time.