{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,23]],"date-time":"2026-07-23T11:30:41Z","timestamp":1784806241361,"version":"3.55.0"},"reference-count":51,"publisher":"MDPI AG","issue":"5","license":[{"start":{"date-parts":[[2019,3,5]],"date-time":"2019-03-05T00:00:00Z","timestamp":1551744000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Medical Cyber-Physical Systems (MCPS) hold the promise of reducing human errors and optimizing healthcare by delivering new ways to monitor, diagnose and treat patients through integrated clinical environments (ICE). Despite the benefits provided by MCPS, many of the ICE medical devices have not been designed to satisfy cybersecurity requirements and, consequently, are vulnerable to recent attacks. Nowadays, ransomware attacks account for 85% of all malware in healthcare, and more than 70% of attacks confirmed data disclosure. With the goal of improving this situation, the main contribution of this paper is an automatic, intelligent and real-time system to detect, classify, and mitigate ransomware in ICE. The proposed solution is fully integrated with the ICE++ architecture, our previous work, and makes use of Machine Learning (ML) techniques to detect and classify the spreading phase of ransomware attacks affecting ICE. Additionally, Network Function Virtualization (NFV) and Software Defined Networking (SDN)paradigms are considered to mitigate the ransomware spreading by isolating and replacing infected devices. Different experiments returned a precision\/recall of 92.32%\/99.97% in anomaly detection, an accuracy of 99.99% in ransomware classification, and promising detection and mitigation times. Finally, different labelled ransomware datasets in ICE have been created and made publicly available.<\/jats:p>","DOI":"10.3390\/s19051114","type":"journal-article","created":{"date-parts":[[2019,3,5]],"date-time":"2019-03-05T11:19:50Z","timestamp":1551784790000},"page":"1114","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":93,"title":["Intelligent and Dynamic Ransomware Spread Detection and Mitigation in Integrated Clinical Environments"],"prefix":"10.3390","volume":"19","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2027-4239","authenticated-orcid":false,"given":"Lorenzo","family":"Fern\u00e1ndez Maim\u00f3","sequence":"first","affiliation":[{"name":"Department of Computer Engineering, University of Murcia, 30100 Murcia, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Alberto","family":"Huertas Celdr\u00e1n","sequence":"additional","affiliation":[{"name":"Telecommunications Software &amp; Systems Group, Waterford Institute of Technology, X91 K0EK Waterford, Ireland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1004-881X","authenticated-orcid":false,"given":"\u00c1ngel L.","family":"Perales G\u00f3mez","sequence":"additional","affiliation":[{"name":"Department of Computer Engineering, University of Murcia, 30100 Murcia, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"F\u00e9lix J.","family":"Garc\u00eda Clemente","sequence":"additional","affiliation":[{"name":"Department of Computer Engineering, University of Murcia, 30100 Murcia, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8167-9163","authenticated-orcid":false,"given":"James","family":"Weimer","sequence":"additional","affiliation":[{"name":"Department of Computer &amp; Information Science, University of Pennsylvania, Philadelphia, PA 19104-6309, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Insup","family":"Lee","sequence":"additional","affiliation":[{"name":"Department of Computer &amp; Information Science, University of Pennsylvania, Philadelphia, PA 19104-6309, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2019,3,5]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"156","DOI":"10.4258\/hir.2016.22.3.156","article-title":"Medical Internet of Things and Big Data in Healthcare","volume":"22","author":"Dimitrov","year":"2016","journal-title":"Healthc. Inform. Res."},{"key":"ref_2","first-page":"1:1","article-title":"Research Directions for Cyber Physical Systems in Wireless and Mobile Healthcare","volume":"1","author":"Stankovic","year":"2016","journal-title":"ACM Trans. Cyber Phys. Syst."},{"key":"ref_3","unstructured":"Arney, D., Plourde, J., Schrenker, R., Mattegunta, P., Whitehead, S.F., and Goldman, J.M. (2014, January 14). Design Pillars for Medical Cyber-Physical System Middleware. Proceedings of the 5th Workshop on Medical Cyber-Physical Systems, Berlin, Germany."},{"key":"ref_4","unstructured":"(2013). Medical Devices and Medical Systems\u2014Essential Safety Requirements for Equipment Comprising the Patient-Centric Integrated Clinical Environment (ICE)\u2014Part 1: General Requirements and Conceptual Model, ASTM International."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"305","DOI":"10.2147\/MDER.S50048","article-title":"Cybersecurity vulnerabilities in medical devices: A complex environment and multifaceted problem","volume":"8","author":"Williams","year":"2015","journal-title":"Med. Devices"},{"key":"ref_6","unstructured":"(2011). Networked Medical Devices: Security and Privacy Threats, Symantec. Technical Report."},{"key":"ref_7","unstructured":"(2016). Sixth Annual Benchmark Study on Privacy & Security of Healthcare Data, Ponemon Institute. Technical Report."},{"key":"ref_8","unstructured":"(2018). Data Breach Investigations Report, Verizon. Technical Report."},{"key":"ref_9","unstructured":"Osborne, C. (2019, March 04). US Hospital Pays $55,000 to Hackers after Ransomware Attack. Available online: https:\/\/www.zdnet.com\/article\/us-hospital-pays-55000-to-ransomware-operators\/."},{"key":"ref_10","unstructured":"Mohney, G. (2019, March 04). Hospitals Remain Key Targets as Ransomware Attacks Expected to Increase. Available online: https:\/\/abcnews.go.com\/Health\/hospitals-remain-key-targets-ransomware-attacks-expected-increase\/story?id=47416989."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Kathareios, G., Anghel, A., Mate, A., Clauberg, R., and Gusat, M. (2017, January 18\u201321). Catch It If You Can: Real-Time Network Anomaly Detection with Low False Alarm Rates. Proceedings of the 2017 16th IEEE International Conference on Machine Learning and Applications (ICMLA), Cancun, Mexico.","DOI":"10.1109\/ICMLA.2017.00-36"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"680","DOI":"10.1016\/j.future.2016.11.009","article-title":"Mobile edge computing, Fog et al.: A survey and analysis of security threats and challenges","volume":"78","author":"Roman","year":"2018","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"187","DOI":"10.1109\/MCOM.2015.7081093","article-title":"Toward an SDN-enabled NFV architecture","volume":"53","author":"Matias","year":"2015","journal-title":"IEEE Commun Mag."},{"key":"ref_14","unstructured":"Huertas, A., Garcia, F.J., Weimer, J., and Lee, I. (2018, January 17\u201320). ICE++: Improving Security, QoS, and High Availability of Medical Cyber-Physical Systems through Mobile Edge Computing. Proceedings of the IEEE 20th International Conference on e-Health Networking, Applications and Services (Healthcom), Ostrava, Czech Repupblic."},{"key":"ref_15","unstructured":"(2019, March 04). The Hospital Room of the Future Datasets. Available online: http:\/\/perception.inf.um.es\/ICE-datasets\/."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Hatcliff, J., King, A., Lee, I., Macdonald, A., Fernando, A., Robkin, M., Vasserman, E., Weininger, S., and Goldman, J.M. (2012, January 17\u201319). Rationale and Architecture Principles for Medical Application Platforms. Proceedings of the 2012 IEEE\/ACM Third International Conference on Cyber-Physical Systems, Beijing, China.","DOI":"10.1109\/ICCPS.2012.9"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"39","DOI":"10.1515\/bmt-2017-0040","article-title":"OpenICE medical device interoperability platform overview and requirement analysis","volume":"63","author":"Arney","year":"2017","journal-title":"Biomed. Eng.\/Biomed. Tech."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Rajkumar, S., Srikanth, M., and Ramasubramanian, N. (2017, January 20\u201322). Health monitoring system using Raspberry PI. Proceedings of the International Conference on Big Data, IoT and Data Science (BID), Pune, India.","DOI":"10.1109\/BID.2017.8336583"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"191","DOI":"10.1016\/j.future.2016.09.020","article-title":"Obstacles in Data Distribution Service Middleware: A Systematic Review","volume":"68","author":"Tekinerdogan","year":"2017","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"48","DOI":"10.1016\/j.maturitas.2018.04.008","article-title":"Cybersecurity in healthcare: A narrative review of trends, threats and ways forward","volume":"113","author":"Coventry","year":"2018","journal-title":"Maturitas"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Almohri, H., Cheng, L., Yao, D., and Alemzadeh, H. (2017, January 17\u201319). On Threat Modeling and Mitigation of Medical Cyber-Physical Systems. Proceedings of the IEEE\/ACM International Conference on Connected Health: Applications, Systems and Engineering Technologies (CHASE), Philadelphia, PA, USA.","DOI":"10.1109\/CHASE.2017.69"},{"key":"ref_22","first-page":"4","article-title":"Toward a Safe and Secure Medical Internet of Things","volume":"2","author":"Soroush","year":"2016","journal-title":"IIC J. Innov."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Nguyen, H., Acharya, B., Ivanov, R., Haeberlen, A., Phan, L.T.X., Sokolsky, O., Walker, J., Weimer, J., Hanson, W., and Lee, I. (2016, January 27\u201329). Cloud-Based Secure Logger for Medical Devices. Proceedings of the IEEE First International Conference on Connected Health: Applications, Systems and Engineering Technologies (CHASE), Washington, DC, USA.","DOI":"10.1109\/CHASE.2016.48"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"34","DOI":"10.1145\/3076125.3076129","article-title":"Protecting Interoperable Clinical Environment with Authentication","volume":"14","author":"Cheng","year":"2017","journal-title":"SIGBED Rev."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"14","DOI":"10.1109\/MNET.2016.1600110NM","article-title":"Using Software-Defined Networking for Ransomware Mitigation: The Case of CryptoWall","volume":"30","author":"Cabaj","year":"2016","journal-title":"IEEE Netw."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"353","DOI":"10.1016\/j.compeleceng.2017.10.012","article-title":"Software-defined networking-based crypto ransomware detection using HTTP traffic characteristics","volume":"66","author":"Cabaj","year":"2018","journal-title":"Comput. Electr. Eng."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Cusack, G., Michel, O., and Keller, E. (2018, January 21). Machine Learning-Based Detection of Ransomware Using SDN. Proceedings of the 2018 ACM International Workshop on Security in Software Defined Networks & Network Function Virtualization, Tempe, AZ, USA. SDN-NFV Sec\u201918.","DOI":"10.1145\/3180465.3180467"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"343","DOI":"10.1007\/s00500-014-1511-6","article-title":"Evaluation of machine learning classifiers for mobile malware detection","volume":"20","author":"Narudin","year":"2016","journal-title":"Soft Comput."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Fern\u00e1ndez-Maim\u00f3, L., Huertas-Celdr\u00e1n, A., Gil-P\u00e9rez, M., Garc\u00eda-Clemente, F.J., and Mart\u00ednez-P\u00e9rez, G. (2018). Dynamic management of a deep learning-based anomaly detection system for 5G networks. J. Ambient Intell. Humaniz. Comput., 1\u201315.","DOI":"10.1007\/s12652-018-0813-4"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Alhawi, O.M.K., Baldwin, J., and Dehghantanha, A. (2018). Leveraging Machine Learning Techniques for Windows Ransomware Network Traffic Detection. Cyber Threat Intelligence, Springer.","DOI":"10.1007\/978-3-319-73951-9_5"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Takeuchi, Y., Sakai, K., and Fukumoto, S. (2018, January 13\u201316). Detecting Ransomware Using Support Vector Machines. Proceedings of the 47th International Conference on Parallel Processing Companion, Eugene, OR, USA. Number 1.","DOI":"10.1145\/3229710.3229726"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Wan, Y., Chang, J., Chen, R., and Wang, S. (2018, January 27\u201330). Feature-Selection-Based Ransomware Detection with Machine Learning of Data Analysis. Proceedings of the 3rd International Conference on Computer and Communication Systems (ICCCS), Nagoya, Japan.","DOI":"10.1109\/CCOMS.2018.8463300"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"158","DOI":"10.1016\/j.eswa.2018.02.039","article-title":"Trusted detection of ransomware in a private cloud using machine learning methods leveraging meta-features from volatile memory","volume":"102","author":"Cohen","year":"2018","journal-title":"Expert Syst. Appl."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Mukesh, S.D. (2018, January 4\u20136). An Analysis Technique to Detect Ransomware Threat. Proceedings of the International Conference on Computer Communication and Informatics (ICCCI), Coimbatore, India.","DOI":"10.1109\/ICCCI.2018.8441502"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Chen, Q., and Bridges, R.A. (2017, January 18\u201321). Automated Behavioral Analysis of Malware: A Case Study of WannaCry Ransomware. Proceedings of the 2017 16th IEEE International Conference on Machine Learning and Applications (ICMLA), Cancun, Mexico.","DOI":"10.1109\/ICMLA.2017.0-119"},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Aidan, J.S., Verma, H.K., and Awasthi, L.K. (2017, January 11\u201312). Comprehensive Survey on Petya Ransomware Attack. Proceedings of the 2017 International Conference on Next Generation Computing and Information Systems (ICNGCIS), Jammu, India.","DOI":"10.1109\/ICNGCIS.2017.30"},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1023\/A:1010933404324","article-title":"Random forests","volume":"45","author":"Breiman","year":"2001","journal-title":"Mach. Learn."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"1443","DOI":"10.1162\/089976601750264965","article-title":"Estimating the support of a high-dimensional distribution","volume":"13","author":"Platt","year":"2001","journal-title":"Neural Comput."},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"93","DOI":"10.1145\/335191.335388","article-title":"LOF: identifying density-based local outliers","volume":"29","author":"Breunig","year":"2000","journal-title":"ACM Sigmod Rec."},{"key":"ref_40","first-page":"3","article-title":"Isolation-based anomaly detection","volume":"6","author":"Liu","year":"2012","journal-title":"ACM Trans. Knowl. Discov. Data (TKDD)"},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Niculescu-Mizil, A., and Caruana, R. (2005, January 7\u201311). Predicting good probabilities with supervised learning. Proceedings of the 22nd International Conference on Machine Learning, Bonn, Germany.","DOI":"10.1145\/1102351.1102430"},{"key":"ref_42","unstructured":"(2017). Network Functions Virtualisation (NFV); Network Operator Perspectives on NFV Priorities for 5G, ETSI NFV ISG. Technical Report."},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1109\/TII.2012.2226594","article-title":"Model-Driven Safety Analysis of Closed-Loop Medical Systems","volume":"10","author":"Pajic","year":"2014","journal-title":"IEEE Trans. Ind. Inform."},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Vargas-Mu\u00f1oz, M.J., Mart\u00ednez-Pel\u00e1ez, R., Velarde-Alvarado, P., Moreno-Garc\u00eda, E., Torres-Roman, D.L., and Ceballos-Mej\u00eda, J.J. (2018, January 21\u201323). Classification of network anomalies in flow level network traffic using Bayesian networks. Proceedings of the 2018 International Conference on Electronics, Communications and Computers (CONIELECOMP), Cholula, Mexico.","DOI":"10.1109\/CONIELECOMP.2018.8327205"},{"key":"ref_45","unstructured":"Horrocks, I., Patel-Schneider, P.F., Boley, H., Tabet, S., Grosof, B., and Dean, M. (2019, March 04). SWRL: A Semantic Web Rule Language Combining OWL and RuleML. Available online: https:\/\/www.w3.org\/Submission\/2004\/SUBM-SWRL-20040521\/."},{"key":"ref_46","unstructured":"Prud\u2019hommeaux, E., and Seaborne, A. (2019, March 04). Available online: https:\/\/www.w3.org\/TR\/sparql11-overview\/."},{"key":"ref_47","unstructured":"(2019, March 04). The OpenStack Project, a ETSI NFV Compliant MANO Framework. Available online: http:\/\/openstack.org."},{"key":"ref_48","unstructured":"(2019, March 04). The OpenDaylight Project. Available online: https:\/\/www.opendaylight.org."},{"key":"ref_49","unstructured":"(2019, March 04). The OpenBaton Project. Available online: http:\/\/openbaton.github.io."},{"key":"ref_50","doi-asserted-by":"crossref","unstructured":"Van Niekerk, B. (2018, January 8\u20139). Information warfare as a continuation of politics: An analysis of cyber incidents. Proceedings of the 2018 Conference on Information Communications Technology and Society (ICTAS), Durban, South Africa.","DOI":"10.1109\/ICTAS.2018.8368758"},{"key":"ref_51","unstructured":"Lab, K. (2019, March 04). A Mining Multitool. Available online: https:\/\/securelist.com\/a-mining-multitool\/86950\/."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/19\/5\/1114\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T12:36:25Z","timestamp":1760186185000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/19\/5\/1114"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,3,5]]},"references-count":51,"journal-issue":{"issue":"5","published-online":{"date-parts":[[2019,3]]}},"alternative-id":["s19051114"],"URL":"https:\/\/doi.org\/10.3390\/s19051114","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,3,5]]}}}