NP-200 system security design review
NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007
PRJ-2026-0042-DRV-0001Threat review
Threat workbench
Replay of captured dosing command re-doses patient
PRJ-2026-0042-TV-000124Treatment plannedHigh
- Proposed (passed)
- Confirmed (passed)
- Assessed (passed)
- Treatment planned (current)
- Mitigation pending (pending)
- Verified (pending)
- Closed (pending)
An attacker who records a legitimate remote dosing command on the clinical network replays it later. Without nonce binding or replay windows on DF-000077, the dosing command processor treats the replayed message as a fresh clinician-authorized command and repeats delivery.
Deterministic ruleConfidence high
Actor: Passive network capture then active replay; moderate skill.
- Attacker can capture gateway-to-pump command traffic (TB-003).
- Commands carry no nonce/sequence binding in the candidate design.
- Capture a valid dosing command exchange.
- Replay the captured request against POST /dose within the drug-library limit window.
- Processor sequences a second, unauthorized delivery.
- Flows
- DF-000077Remote dosing command
- Function
- Infusion dosing delivery (repeat-delivery integrity)
Inherent
HighL4 × I4
Residual
MediumL2 × I4
Factors (1 to 5)
Exploitability4
Impact: confidentiality1
Impact: integrity4
Impact: availability2
Impact: authenticity4
Detectability3
| Category | Value | Share |
|---|---|---|
| Exploitability | 4 | 22% |
| Impact: confidentiality | 1 | 6% |
| Impact: integrity | 4 | 22% |
| Impact: availability | 2 | 11% |
| Impact: authenticity | 4 | 22% |
| Detectability | 3 | 17% |
Safety consequence: IndirectScope: Single deviceUncertainty: Low
- Exploitability
- 4/5
- Capture-and-replay feasible on shared VLAN; no freshness checks.
- Impact: confidentiality
- 1/5
- Replay discloses nothing new.
- Impact: integrity
- 4/5
- Repeat delivery of a prior valid command; bounded by drug-library limits.
- Impact: availability
- 2/5
- Limited availability effect.
- Impact: authenticity
- 4/5
- Replayed message masquerades as fresh clinician intent.
- Safety consequence
- Indirect
- Bounded by hard limits; hazardous only in stacked-dose edge cases.
- Affected scope
- Single device
- Replay targets one captured device session.
- Detectability
- 3/5
- Duplicate command patterns visible in gateway logs after the fact.
- Uncertainty
- Low
- Schema verified; behavior reproduced against mock endpoint.
High 16 = L4 x I4; treatment planned via REM-202.
- Responsible implementer
- Noor Haddad (Firmware Engineer)
- Accountable manager
- Tomas Novak
- Independent security reviewer
- Priya Raman
- Risk owner
- Marcus Chen
- Target date
- 30 Jun 2026
- Disposition
- Confirmed by Marcus Chen, 15 Apr 2026
- Treatment adopted (passed)
- Implemented (current)
- Evidence accepted (pending)
- Retest passed (pending)
- Closed (pending)
- REM-202Signed nonce-bound commands with anti-replay windowAdopted
- VOB-000211Authenticated-command fuzz testPendingdue 10 Jul 2026
EvidenceNot requestedRetestNot scheduled
- Treatment adoptedTomas Novak · Covered by REM-202 signed nonce-bound commands; fuzz obligation VOB-000211 shared with TV-000118.
- ConfirmedMarcus Chen
- Proposed by deterministic rule DFL-REPLAY-01 (run TMR-0009)system