Incorporating S.P.I.C.Y. DICOM Polyglot Threats into Cyber Warfare Exercises
DOI:
https://doi.org/10.34190/eccws.25.1.4843Keywords:
DICOM, Polyglot, Healthcare, Cybersecurity, S.P.I.C.Y., Operational gap, Automated pipelineAbstract
The technical feasibility of crafting polyglot files, objects valid under multiple file formats, has been repeatedly demonstrated in various contexts, including the DICOM medical imaging standard. While prior work has established that DICOM polyglots are technically constructible, a significant operational gap exists between this known vulnerability and the preparedness of healthcare organizations to detect and mitigate such data-centric threats. This paper addresses this critical oversight by shifting the focus from how to construct DICOM polyglots to why they pose an unmitigated, systemic risk in clinical workflows. We argue that this operational gap stems from three primary issues: non-uniform inspection across heterogeneous security tools, misplaced trust in the structural compliance of medical data, and insufficient threat modelling for automated pipelines. Our feasibility analysis, using a controlled DICOM/Portable Executable (PE) polyglot, demonstrates that mainstream security tools exhibit substantial inconsistencies in detection, with different systems interpreting the same object according to varying, often shallow, parsing assumptions. This non-uniform inspection allows the polyglot to remain stealthy and polyglot. To provide a structured framework for analyzing and mitigating this threat, we introduce the S.P.I.C.Y. framework, defined by five operational characteristics: Stealthy, Polyglot, Infiltrative, Cascading, and Yield. S.P.I.C.Y. helps practitioners measure the operational impact of malicious data artifacts that propagate through trusted, automated workflows, such as Picture Archiving and Communication Systems (PACS) and Vendor Neutral Archives (VNAs). The Infiltrative and Cascading characteristics highlight how an object, once past initial inspection, maintains its dual functionality across multiple automated processes. Finally, we redefine Yield to include not just execution, but the operational value gained from persistence within trusted infrastructure. By applying the S.P.I.C.Y. framework, organizations can move beyond traditional security models and strategically address the critical blind spots created by operational complexity and the assumed trust placed in medical data standards.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 European Conference on Cyber Warfare and Security

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.