BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Safe\, Secure\, and Effective: What Static Behavior 
 Analysis\n   Reveals About the Software Running Your Medical Devices\n   T
 ags: Biohacking Village | Creator Talk/Panel\n   When: Saturday\, Aug 8\, 
 13:00 - 13:30 PDT\n   Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) -
  [1]Map\n\n   Description:\n\n   When a patient monitor misreads an ECG or
  an infusion pump\n   miscalculates a dose\, the root cause is software be
 havior\, not a CVE.\n   Yet the entire medical device security industry is
  fixated on\n   vulnerability scanning and SBOMs while ignoring the harder
  question\n   the FDA actually asks: does this software behave in ways tha
 t are safe\n   and effective for its clinical purpose?\n\n   Using automat
 ed reverse engineering developed under ARPA-H research\,\n   we analyze co
 mpiled medical device firmware to build Software Bills of\n   Behaviors th
 at map what every function in a binary actually does. We\n   automatically
  categorize hundreds of functions into clinical\n   subsystems: ECG data p
 rocessing\, SpO2 and CO2 signal handling\,\n   physiological waveform disp
 lay\, sensor calibration\, and heatblock\n   control. We then identify whi
 ch subsystems constitute essential\n   performance\, the functions where a
  bug\, an unexpected change\, or a\n   malicious modification doesn't just
  create a cyber incident\, it harms\n   a patient.\n\n   We'll walk throug
 h real device firmware where we found functions that\n   directly modify E
 CG configuration and hardware calibration state\,\n   where logic flaws or
  race conditions could impact device safety\,\n   stability\, or data inte
 grity. We'll show how a firmware update that\n   only touches 10% of funct
 ions can silently alter safety-critical\n   signal processing paths\, and 
 how we automatically assess whether those\n   changes affect clinical oper
 ation or are benign. We'll demonstrate how\n   the Contec CMS8000 patient 
 monitor contained unapproved wireless\n   monitoring capabilities the FDA 
 never cleared\, a safety and regulatory\n   violation invisible to any vul
 nerability scanner.\n\n   Whether you're building devices\, securing hospi
 tals\, or hacking\n   medical firmware\, this talk shifts the frame from "
 is it vulnerable?"\n   to "is it safe?" because the patient on the other e
 nd doesn't care\n   about your CVSS score.\n\n   SpeakerBio:  Andrew Hende
 la\n\n   Andrew Hendela has been automating hard offensive and defensive c
 yber\n   for well over a decade and a half\, from VR\, malware analysis\, 
 and\n   cyber attribution. He is also a co-founder of Karambit.AI\, a star
 tup\n   focused on validating the safety\, security\, and effectiveness of
 \n   software and firmware.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260808T203000Z
DTSTART:20260808T200000Z
LOCATION:Biohacking Village - LVCCW Level 1 Hall 3 1104 (Creator Stage 4)
SUMMARY:Safe\, Secure\, and Effective: What Static Behavior Analysis Reveal
 s About the Software Running Your Medical Devices
END:VEVENT
END:VCALENDAR
