News: 1716338772

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Uncle Sam to inject $50M into auto-patcher for hospital IT

(2024/05/22)


The US government's Advanced Research Projects Agency for Health (ARPA-H) has pledged more than $50 million to fund the development of technology that aims to automate the process of securing hospital IT environments.

ARPA-H has called this program Universal PatchinG and Remediation for Autonomous DEfense, or [1]UPGRADE for short. The agency basically wants techies to get together and build a suite of software tools that can scan for vulnerabilities and weaknesses in hospital computer systems, and then automatically deploy patches for identified threats, developing and testing fixes and mitigations as needed.

As such, the agency this week invited teams to apply for funding totaling tens of millions of dollars to create UPGRADE and see it through to completion.

[2]

Modern medical facilities typically use a lot of internet or network-connected devices, and taking these offline to patch or protect them can disrupt patient services. Not patching them, however, leaves clinics vulnerable to compromise. To accommodate these hospital-specific concerns, the UPGRADE platform will test software fixes in a model environment before deploying them "with minimum interruption" to the devices that need them, if the plans come to fruition.

[3]

[4]

The project thus seeks participants focused on four specific areas: Creating a vulnerability mitigation software platform; developing digital twins of hospital equipment; auto-detecting flaws; and auto-developing custom defenses.

ARPA-H is a US government funding agency that President Joe Biden created two years ago. It's [5]tasked with making "pivotal investments in breakthrough technologies" that advantage medicine and healthcare — specifically technologies that "cannot readily be accomplished through traditional research or commercial activity." And its director reports to the US Dept of Health and Human Services (HHS) Secretary.

[6]

"We continue to see how interconnected our nation's health care ecosystem is and how critical it is for our patients and clinical operations to be protected from cyberattacks," HHS Deputy Secretary Andrea Palm said in a [7]statement . "ARPA-H's UPGRADE will help build on HHS' Healthcare Sector Cybersecurity Strategy to ensure that all hospital systems, large and small, are able to operate more securely and adapt to the evolving landscape."

HHS, incidentally, sets hospitals [8]voluntary healthcare-specific cybersecurity performance goals that look likely to become mandatory.

[9]Ransomware can mean life or death at hospitals. DEF CON hackers to the rescue?

[10]Ignore Uncle Sam's 'voluntary' cybersecurity goals for hospitals at your peril

[11]Uncle Sam urges action after Black Basta ransomware infects Ascension

[12]UnitedHealth's 'egregious negligence' led to Change Healthcare ransomware infection

UPGRADE, and what it hopes to accomplish, is a big task. It's also potentially a life-saving one, as [13]ransomware and other criminal gangs increasingly target medical facilities with the intent of [14]locking IT and medical staff out of critical systems needed to deploy ambulances, [15]provide medications and [16]services , and access patients' [17]vital information .

"Healthcare is both acutely being targeted, and it has been more and more targeted over the last few years," ARPA-H program manager Andrew Carney told The Register in an [18]earlier interview . "It's also uniquely sensitive to disruptions compared to many other critical infrastructure sectors."

Carney, at the time, was discussing another recent ARPA-H partnership, this one with the Defense Advanced Research Projects Agency (DARPA) for the Artificial Intelligence Cyber Challenge ( [19]AIxCC ).

[20]

AIxCC is the two-year competition that DARPA [21]announced last summer at the annual Black Hat conference in Las Vegas. It focuses on building AI-based tools that automatically secure code used in critical infrastructure. Participants in this challenge are now competing in trials to see which teams will advance to the semifinals at DEF CON in August.

During the semi-finals, seven teams will each be awarded $2 million before advancing to the final competition at the DEF CON conference in 2025. ®

Get our [22]Tech Resources



[1] https://arpa-h.gov/research-and-funding/programs/upgrade

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zk1t4yCb46g3C5QIpmDDWAAAANE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zk1t4yCb46g3C5QIpmDDWAAAANE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zk1t4yCb46g3C5QIpmDDWAAAANE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://arpa-h.gov/about/faqs

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zk1t4yCb46g3C5QIpmDDWAAAANE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://arpa-h.gov/news-and-events/arpa-h-announces-program-automate-cybersecurity-health-care-facilities

[8] https://www.theregister.com/2024/02/05/us_voluntary_cybersecurity_goals_hospitals/

[9] https://www.theregister.com/2024/03/26/aixcc_healthcare/

[10] https://www.theregister.com/2024/02/05/us_voluntary_cybersecurity_goals_hospitals/

[11] https://www.theregister.com/2024/05/13/cisa_ascension_ransomware/

[12] https://www.theregister.com/2024/05/08/unitedhealths_egregious_negligence/

[13] https://www.theregister.com/2024/05/13/cisa_ascension_ransomware/

[14] https://www.theregister.com/2024/03/08/change_healthcare_restores_first_system/

[15] https://www.theregister.com/2024/04/29/canada_london_drugs/

[16] https://www.theregister.com/2023/10/25/canadian_hospitals_spamoflague/

[17] https://www.theregister.com/2022/10/12/hospital_outages_ransomware/

[18] https://www.theregister.com/2024/03/26/aixcc_healthcare/

[19] https://arpa-h.gov/news-and-events/arpa-h-joins-darpas-ai-cyber-challenge

[20] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zk1t4yCb46g3C5QIpmDDWAAAANE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[21] https://www.theregister.com/2023/08/09/darpa_aixcc/

[22] https://whitepapers.theregister.com/



I'm going to take a short position on this program

elDog

While it makes some sense to totally circumvent the behemoth legacy purveyors of the health-care infrastructure, it is this very huge mess of pasta that masquerades as a "system" that will make the "patching" so difficult.

I'll just hypothesize that some of these systems are built using Oracle and perhaps PeopleSoft or SalesForce. All of these have so many installed versions that are somewhere on the updated software spectrum. Oracle, as an example, is infamous for making its software interfaces opaque - even after spending many $$ to get access to them.

I've used the dynamic patch technologies for 30+ years and it has become more and more difficult to make them work as the underlying hardware and software become more complex.

I never made a mistake in my life. I thought I did once, but I was wrong.
-- Lucy Van Pelt