NP-200 system security design review
NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007
PRJ-2026-0042-DRV-0001Threat review
Threat workbench
Gateway flood starves dosing command channel
PRJ-2026-0042-TV-000133Treatment plannedHigh
- Proposed (passed)
- Confirmed (passed)
- Assessed (passed)
- Treatment planned (current)
- Mitigation pending (pending)
- Verified (pending)
- Closed (pending)
An attacker floods the NimbusLink Gateway service from the clinical network, exhausting connection and queue resources so that legitimate remote dosing commands and status traffic are delayed or dropped during active infusions.
Deterministic ruleConfidence high
Actor: Network-resident attacker; low skill; volumetric or slow-drip resource exhaustion.
- Gateway reachable on VLAN.
- No rate limiting or bounded queues on the command listener.
- Open and hold connections against the gateway command listener.
- Exhaust worker pool and queue depth.
- Legitimate commands time out; delivery falls back to local-only control.
- Sources
- SRC-0004drawio node gw-edge (exposed listener)
- Function
- Remote command availability and telemetry continuity
Inherent
HighL4 × I3
Residual
MediumL2 × I3
Factors (1 to 5)
Exploitability4
Impact: confidentiality1
Impact: integrity1
Impact: availability3
Impact: authenticity1
Detectability2
| Category | Value | Share |
|---|---|---|
| Exploitability | 4 | 33% |
| Impact: confidentiality | 1 | 8% |
| Impact: integrity | 1 | 8% |
| Impact: availability | 3 | 25% |
| Impact: authenticity | 1 | 8% |
| Detectability | 2 | 17% |
Safety consequence: NoneScope: Shared clinical environmentUncertainty: Low
- Exploitability
- 4/5
- Trivially executable from any VLAN host; no limiter present.
- Impact: confidentiality
- 1/5
- None.
- Impact: integrity
- 1/5
- None.
- Impact: availability
- 3/5
- Remote command path degraded; local control retained (safe degradation).
- Impact: authenticity
- 1/5
- None.
- Safety consequence
- None
- Device falls back to local-only operation per design.
- Affected scope
- Shared clinical environment
- One gateway serves a ward segment.
- Detectability
- 2/5
- Connection saturation visible to gateway health telemetry.
- Uncertainty
- Low
- Exposure verified from topology.
High 12 = L4 x I3; treatment adopted (REM-215).
- Responsible implementer
- Owen Blake (Cloud Platform Engineer)
- Accountable manager
- Tomas Novak
- Independent security reviewer
- Priya Raman
- Risk owner
- Marcus Chen
- Target date
- 26 Jun 2026
- Disposition
- Confirmed by Marcus Chen, 15 Apr 2026
- Treatment adopted (passed)
- Implemented (current)
- Evidence accepted (pending)
- Retest passed (pending)
- Closed (pending)
- REM-203Gateway network allowlist for command listenerdefense-in-depthAdopted
- REM-215Rate limiting and bounded queues on gateway command channelAdopted
- VOB-000213Allowlist enforcement and bypass-attempt alerting testPendingdue 12 Jun 2026
- VOB-000218Gateway command-channel soak and flood testPendingdue 17 Jul 2026
EvidenceNot requestedRetestNot scheduled
- Treatment adoptedTomas Novak · REM-215 rate limiting + bounded queues; REM-203 allowlist contributes defense-in-depth.
- ConfirmedMarcus Chen
- Proposed by deterministic rule SVC-DOS-01 (run TMR-0009)system