Enhancing IoMT security: an advanced FAHP-based security scoring system for medical devices evaluation
摘要
Internet-of-Medical-Things (IoMT) face numerous security threats such as unauthorized access, data leakage, denial-of-service attacks, and device manipulation. Many issues are related to the increasing connectivity of medical devices that often lack built-in protections, their complex ecosystem, and the ever growing number of cyber-attacks. Medical devices are becoming more and more connected despite lacking built-in security. Hence, it becomes necessary to protect patients and their data from security threats. In order to deal with the risks of networked medical devices, we need to evaluate the security risks and prioritize the mitigation solutions. This paper proposes an advanced security scoring system (ASSS) to support security analysts, healthcare system administrators, and ordinary users in evaluating security risks and selecting countermeasures. Our approach integrates fuzzy set theory to capture uncertainty in expert judgments with fuzzy analytic hierarchy process (FAHP), a multi-criteria decision-making (MCDM) method, to rank devices and prioritize mitigation strategies. It relies on a structured quantitative risk analysis of the connected medical devices (CMDs) in a pre-deployment context. A step-by-step risk analysis presents in details the framework’s ability to rank IoMT devices based on their main vulnerabilities and adaptability with the user preferences and the use case scenario. Results from a case of application highlight the effectiveness of the proposed solution that enables risk-aware decision-making, thereby supporting safer integration of IoMT devices into healthcare environments. While effective under uncertainty, the model’s dependence on expert input and scalability limitations highlight opportunities for future refinement.