In our paper we analyze the attack surface of German hospitals and healthcare providers in 2020 during the COVID-19 Pandemic. The analysis looked at the publicly visible attack surface utilizing a Distributed Cyber Recon System, utilizing distributed Internet scanning, Big Data methods and scan data of 1,483 GB from more than 89 different global Internet scans. From the 1,555 identified German clinical entities, security posture analysis was conducted by looking at more than 13,000 service banners for version identification and subsequent CVE-based vulnerability identification. Primary analysis shows that 32 percent of the analyzed services were determined as vulnerable to various degrees and 36 percent of all hospitals showed numerous vulnerabilities. Further resulting vulnerability statistics were mapped against size of organization and hospital bed count.
翻译:在本文中,我们分析了2020年在COVID-19大流行病期间德国医院和保健提供者的攻击面。分析利用分布式网络调查系统,利用分布式互联网扫描、大数据方法和来自89多个不同全球互联网扫描的1 483GB的扫描数据,审视了公开可见的攻击面。在1 555个查明的德国临床实体中,安全态势分析通过查看13 000多个服务横幅进行版本识别和随后的CVE脆弱性识别。初级分析显示,所分析的服务有32%被确定为不同程度的脆弱程度,所有医院中有36%显示出多种脆弱性。还根据组织和医院床位的大小绘制了由此产生的脆弱性统计数据。