skip to content

Segment rules for an unpatchable imaging modality are keyed to its fixed IP. How can an attacker inherit that permit?

level: middleimportance: should knowfreq 45%

answer

  1. the device can prove nothing about itself
  2. a location, not an identity
  3. who else can occupy that address
  4. swaps and decommissions break the register
  5. the 2am fix is a wider rule

basics

~20 s

An address-keyed permit trusts a field in the packet, not an identity the device proves, so whoever answers at that address inherits it. Holding the binding true costs static addressing, a hand-kept register and change coordination on every device swap.

solid answer

~50 s

The device can prove nothing about itself: no certificate, no agent, no credential, often not even a consistent hostname. So the permit is bound to the only stable handle available, an address, and the boundary enforces it by reading the source field of arriving packets. Anything that comes to occupy that address inherits the permit: a decommissioned modality whose address is re-leased, a replacement unit an engineer statically configures a digit wrong, a second host given the same address, or an adversary on the same layer-2 domain who claims it. The price is on the other side of the same coin. The binding only stays true if addressing is frozen and a register is maintained by hand, and the moment a swap breaks it the clinical flow fails at an inconvenient hour. The fix applied under that pressure is almost always to widen the rule to the whole subnet, and nobody narrows it afterwards.

go deeper

for a junior

Know that a rule written against an IP address checks the address in the packet and nothing about the machine behind it, and that the address has to be reserved rather than leased for the rule to keep working.

for a middle

Explain the gap between location and identity, list the ways an address changes hands - decommission, swap, duplicate configuration, adjacency - and describe the manual register the binding depends on.

for a senior

Show that you plan for the repair as well as the attack: anticipate the outage-driven widening, tie the address to the access port, alert on the device going silent, and reconcile the register against what the boundary actually sees.

for a principal

Frame address-keyed policy as an operational contract with another department, with a cost in change coordination and renumbering freedom, and decide when that cost justifies replacing the device rather than continuing to write policy around it.

## Why the permit is keyed to an address at all Everything you would normally key a policy to is an assertion the endpoint makes about itself: a client certificate, an agent identity, a machine account, a signed supplicant response. A device that accepts no patch, no agent and no credential can make none of them. What is left is the address it occupies, and so the segment rule for a clinical modality ends up shaped like *this address may originate to that address on that port, and nothing else*. It works, and it is usually the right answer, but a candidate should be able to say precisely what it does and does not assert. ## What the boundary actually verifies It verifies the source field of a packet arriving on an interface. Combined with anti-spoofing at the edge - source filtering that drops traffic arriving on a port from addresses that do not belong to that segment - it verifies that a packet with that source arrived from the place that address is supposed to live. It does not verify that the machine at that address is the modality. Those are different claims, and the gap between them is where the permit leaks. ## The concrete inheritance paths - **Decommissioning.** The modality is retired. The permit outlives it because nobody told the network team, and the address is later re-issued to something else - or claimed deliberately. - **Replacement.** Clinical engineering swaps a unit under a service contract. The replacement is configured by the vendor engineer, possibly with a different address, possibly with the old one, and the register is updated days later or never. - **Duplication.** Someone statically configures a second host with the same address. Depending on where each sits, some of the permitted flow is now originated by the wrong machine. - **Claiming it.** An adversary already on the same layer-2 domain can answer for the address. This is why the size of that domain matters and why a device with a valuable permit should not share a broad broadcast domain with general-purpose hosts. - **The device itself.** Most important and most often forgotten: the modality is the machine at that address, and it is unpatchable. If it is exploited, the permit is being used by exactly the right address and nothing about the binding is violated. Address-keying provides no defence at all against the case it was written for. ## The price of keeping the binding true This is the half candidates skip, and on a defensive design question it is half the answer. - **Addressing is frozen.** The address becomes part of the device's configuration contract, so re-addressing a subnet - a merger, a site renumber, an IPv6 rollout - now requires coordinated work with a department that schedules around clinical activity, not around your change window. - **A register is maintained by hand.** Device, address, permitted flows, exception owner, expiry. It is manual because the device cannot enrol itself in anything, and a register nobody reconciles quietly becomes fiction. - **Every swap is a change ticket in two organisations.** The network team learns about hardware changes only if clinical engineering tells them, and the incentive to tell them is weak because the device works either way until a rule blocks it. - **The failure mode is a widening.** A broken binding fails closed, which is correct security behaviour and terrible clinical behaviour. The flow stops, the escalation arrives, and at 02:00 the fastest restoration is to widen the rule from one address to the subnet, or from one port to any. That widening is written in an outage, is never reviewed, and is exactly the extra reach an intruder needed. Anticipating it is the mark of someone who has lived with this. ## What to do about it You cannot make the device prove who it is, so improve the binding's surroundings instead. Reserve the address permanently rather than relying on a lease. Filter at the access port so the address can only be sourced from the port the device is actually plugged into, which turns a soft binding into something an attacker has to be physically or logically adjacent to abuse. Keep the device's layer-2 neighbourhood small. Alert when the address goes quiet, because silence usually means the device was replaced and the register is now wrong. And treat any widened rule created during an outage as an incident follow-up item with a date, not as a permanent fixture. ## The honest summary Address-keyed policy is the correct control for a population that can carry no control of its own, and it buys real reduction in reachable surface. What it never buys is authentication of the endpoint. It is a permit attached to a location, and both an operational accident and an adversary can arrive at that location.

  • What does source filtering at the access port add to an address-keyed permit?
    It ties the address to the physical port the device is plugged into, so traffic claiming that source from anywhere else is dropped before it reaches the segment boundary. It does not authenticate the device, but it forces an attacker to be adjacent to the right port rather than merely somewhere on the network.
  • Why is a broken binding still dangerous when it fails closed?
    Because the failure lands on clinical traffic, and the restoration happens under time pressure with a clinician escalating. The rule gets widened to the subnet or to any port to make the flow work, and that emergency widening is rarely reviewed afterwards. The security loss comes from the repair, not the outage.
  • Does address-keying help at all if the modality itself is exploited?
    No. The traffic then originates from precisely the address the permit names, so the binding is satisfied. Address-keying constrains impersonation of the device, never compromise of it, which is why the permitted origination set has to be narrow enough to be useless to an intruder.

saying these in an interview costs you the question

  • Treats an IP-keyed rule as authentication of the device
  • Assumes a reserved address cannot be occupied by anything else
  • Ignores decommissioned devices whose permits outlive them
  • Never mentions who maintains the device-to-address register
  • Calls an emergency subnet-wide widening a temporary fix

context