Association control
Authorize calling and called AE titles and restrict the DICOM operations each source may perform.
Inspect DICOM associations, objects, and tags before they reach the PACS.
DICOM Application Firewall operates inside an existing imaging network as a controlled entry point to the PACS. It accepts the incoming association, reads the DICOM object, applies policy, and forwards only permitted content.
Protection can be based on the source, requested operation, image type, dataset structure, tag values, or privacy rules. Every decision becomes part of a clear audit trail.
DICOM-aware policy adds a security layer beyond network ports and addresses.
Authorize calling and called AE titles and restrict the DICOM operations each source may perform.
Validate object structure, required tags, image type, and permitted data before forwarding.
Remove or replace sensitive attributes according to the destination and intended workflow.
Record allowed, blocked, transformed, and quarantined activity with a clear reason.
The PACS receives a new, policy-compliant DICOM association instead of the unchecked source connection.
Make security decisions using DICOM meaning, not only network information.
Stop malformed, unauthorized, or policy-breaking content before storage.
Maintain an audit record of every decision at the PACS boundary.
Discuss association control, content inspection, privacy rules, and audit requirements.