Ravi Patel, Customer Admin

NP-200 system security design review

NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007

PRJ-2026-0042-DRV-0001Threat review
Threat workbench

Gateway flood starves dosing command channel

PRJ-2026-0042-TV-000133Treatment plannedHigh

  1. Proposed (passed)
  2. Confirmed (passed)
  3. Assessed (passed)
  4. Treatment planned (current)
  5. Mitigation pending (pending)
  6. Verified (pending)
  7. Closed (pending)

An attacker floods the NimbusLink Gateway service from the clinical network, exhausting connection and queue resources so that legitimate remote dosing commands and status traffic are delayed or dropped during active infusions.

Deterministic ruleConfidence high

Actor: Network-resident attacker; low skill; volumetric or slow-drip resource exhaustion.

Elements
AE-000051NimbusLink Gateway edge serviceAE-000042Infusion dosing command processor
Flows
DF-000077Remote dosing commandDF-000081Telemetry upload
Sources
SRC-0004drawio node gw-edge (exposed listener)
Function
Remote command availability and telemetry continuity