Skip to content
Open access

Black-Box Cybersecurity Assessment of Software as a Medical Device (SaMD): A Case Study

2026 · International Journal of Advanced Computer Science and Applications · Vol 17 · 0 citations · 17 references

TL;DR

A comparative assessment of two Dexcom software platforms: the Dexcom Clarity web portal and the Dexcom ONE+ iPhone application is conducted, and a re-producible evaluation procedure is presented and applicable, standards-compliant mitigation recommendations for each identified issue.

Abstract

Based on Sommerville’s robust software reliability theory and eight design principles based on best practices (DPG), this study conducted a comparative assessment of two Dexcom software platforms: the Dexcom Clarity web portal and the Dexcom ONE+ iPhone application. The first phase of the study employed a “black-box” assessment framework, combining off-the-shelf security analysis tools with application-layer behavioral testing workflows developed specifically for this project. The initial two phases focused on the web portal, analyzing communication encryption and HTTP security header configurations. Subsequent phases involved a more in-depth implementation assessment, focusing on actual interactive features, data types, and automated responses triggered by glucose sensor alerts within the application. However, this approach also revealed that certain system elements required access to the source code for verification. The resulting workflow enables the assessment of all externally visible security attributes while identifying system components that necessitate source code access for validation. Of the eight assessment criteria, four were found to have issues, either in whole or in part. Key issues identified include: session cookies missing the SameSite attribute (G1); acceptance of clinically abnormal carbohydrate values without rejection or warning (G2); inclusion of the unsafe-inline directive in the Content Security Policy (CSP), increasing the risk of Cross-Site Scripting (XSS) attacks (G4); and the absence of a dedicated alert mechanism for Wi-Fi connectivity loss during critical medical functions (G7). Due to the requirement for source code access, this “black-box” approach could not evaluate the remaining four criteria (G3, G5, G6, and G8). Finally, this paper presents a re-producible evaluation procedure and offers applicable, standards-compliant mitigation recommendations for each identified issue.

Read PDF

Similar papers

Open access Aug 2026

Comparative Effectiveness of OWASP WSTG and Top Ten in Web Security Audits

The findings indicate that while the OWASP Top Ten serves as a strategic reference, the WSTG is superior as a primary technical auditing framework, which enhances audit consistency, precision, and efficiency in evaluating modern web environments.

Moch Wahyu Sampurno Utomo, H. Wahanani, Achmad Junaidi · 0 citations
#artificial intelligence Open access Nov 2026

A network-based security information system for safeguarding computer-based test platforms in organizational environments

Computer-based testing (CBT) platforms have transformed education and certification by enabling scalable, efficient, and accessible examinations. However, these systems face significant cybersecurity risks, including unauthorized access, denial-of-service (DoS) attacks, and digital cheating, which threaten fairness and...

Ajani Dele, Owolabi Abdulhakim Adewale, Inaya Adesuwa · 0 citations
Sep 2026

Golden Tester Framework for SAE J1939-91C Cybersecurity

The impending formal adoption of SAE J1939-91C creates an urgent need for rigorous, repeatable validation methods that extend beyond functional conformance. This paper presents a structured validation and benchmarking framework, with a focus on performance characterization across dynamic vehicle configurations. Buildin...

Mark P. Zachos, Prakash Kulkarni · 0 citations

TOP 10

The study aims to integrate OWASP Top 10 categories, controlled practical testing, and CVSS-based risk assessment into a single methodological sequence and to evaluate its practical effectiveness in identifying critical web application vulnerabilities.

Nuriddinova Dilnura, Samarov Sherzod, Hamrayevich · 0 citations
Review Open access Sep 2026

The Role of Penetration Testing in Identifying Cybersecurity Vulnerabilities

It is found that regular, authorized penetration testing can support vulnerability identification, risk assessment, and the implementation of appropriate remediation measures, and the study concludes that regular, authorized penetration testing can support vulnerability identification, risk assessment, and the implemen...

Bibi Iqra · 0 citations
Review Open access Sep 2026

Design and Implementation of a Zero-Trust Architecture for Securing Cloud-Based Healthcare Systems in the US

-The rapid migration of US healthcare systems to cloud infrastructure has substantially expanded the attack surface for cyber threats targeting protected health information (PHI). Traditional perimeter-based security models have proven inadequate against the sophistication of modern ransomware campaigns, insider threat...

Michael Akintomiwa Oyedeji, T. Dawotola, Omobolaji Olakunle Oladapo · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.