Medical institution preposed data security monitoring method

By introducing AI and machine learning algorithms into medical institutions, combined with dynamic update mechanisms and multi-level security defenses, the high false alarm rate and high risk of missed reports of existing monitoring methods have been resolved, rapid identification and real-time response to new threats have been achieved, and the accuracy and adaptability of data security monitoring have been improved.

CN120724431AInactive Publication Date: 2025-09-30BAOYING COUNTY PEOPLES HOSPITAL
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510841280.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-23
Publication Date
2025-09-30
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing front-end data security monitoring methods for medical institutions have high false alarm rates and high risks of missed reports, and cannot be updated in a timely manner to respond to new types of network attacks, resulting in the inability of security monitoring methods to quickly adapt to new threat patterns.

Method used

AI and machine learning algorithms are used for data threat detection. Combined with dynamic update mechanisms, multi-level security defense and adaptive learning mechanisms, real-time monitoring and policy adjustments are achieved through user behavior analysis and visualization tools. A comprehensive protection layer is formed using multiple security measures, external threat intelligence sources are integrated, and automated processes and model optimization are performed.

Benefits of technology

Reduce false alarm rates, improve the ability to identify new threats, reduce the risk of missed reports, ensure the system can quickly adapt to new threats, and provide an intuitive data display interface to help managers quickly understand the security situation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120724431A_ABST
    Figure CN120724431A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of medical data, and particularly relates to a medical institution preposed data security monitoring method, which specifically comprises the following steps: data threat detection and analysis: automatically identifying abnormal behaviors and potential threats of medical institution preposed data by using AI and a machine learning algorithm, normal operation modes are identified through a training model, behaviors deviating from the modes are marked as suspicious activities, the AI and machine learning technologies are introduced, legal activities and malicious attempts are accurately distinguished, false alarms caused by excessive sensitivity are avoided, and the false alarm rate is reduced; the continuous learning and updating capability enables the system to identify novel threats more quickly and reduce the risk of missing report, and by means of a dynamic updating mechanism and external threat intelligence, the system can grasp latest threat information in the first time and adjust a defense strategy according to the latest threat information so as to quickly adapt to the new threats.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of medical data technology, and in particular to a method for monitoring the security of front-end data of a medical institution. Background Art

[0002] Pre-emptive data security monitoring in medical institutions refers to a series of security checks and monitoring measures performed on data before it is formally processed or stored. This approach aims to prevent data leakage, tampering, and other security threats, and ensure the integrity, confidentiality, and availability of data.

[0003] However, the existing monitoring methods still have the following technical problems:

[0004] Existing data security monitoring methods have a high false alarm rate and a large risk of missed alarms. Too many false alarms will waste time and resources, while missed alarms may result in real threats not being discovered in time and monitoring methods cannot be updated in a timely manner. As network attack methods continue to evolve, security monitoring methods cannot quickly adapt to new threat patterns.

[0005] To this end, a front-end data security monitoring method for medical institutions is proposed to solve the above-mentioned problems. Summary of the Invention

[0006] The purpose of the present invention is to provide a method for front-end data security monitoring of a medical institution to solve the problems raised in the above background technology.

[0007] To achieve the above-mentioned purpose, the present invention provides the following technical solution: a method for monitoring the security of pre-data in a medical institution. The specific contents of the method are as follows:

[0008] Data threat detection and analysis: Leverage AI and machine learning algorithms to automatically identify abnormal behavior and potential threats in healthcare institutions' front-end data. Models are trained to identify normal operating patterns and flag behaviors that deviate from these patterns as suspicious activity.

[0009] Dynamic update mechanism: This ensures that the monitoring system can obtain the latest threat intelligence in a timely manner and automatically adjust its strategies to respond to emerging attack methods. It integrates external threat intelligence sources, enables the system to update its knowledge base in real time, and regularly evaluates and updates internal rule sets through automated processes.

[0010] Multi-layered security defense: Build a comprehensive protection layer that includes multiple security measures, including but not limited to intrusion detection systems (IDS), firewalls, encryption technology, and access control. These technologies are combined to create a complementary effect, and deep packet inspection is used to analyze malicious code in network traffic.

[0011] Adaptive learning: Establish a closed-loop learning mechanism that allows the system to learn and improve from each event it handles. Every time an alert or event occurs, detailed information is recorded for subsequent analysis and model parameters are adjusted accordingly. A team is assigned to review AI decision-making results and provide manual intervention and correction suggestions.

[0012] User behavior analysis: Focuses on monitoring users' daily activity patterns, identifying abnormal behavior, collecting and analyzing multi-dimensional information such as user login time, location, and device type used, establishing a personal behavior baseline, and triggering alerts when behavior deviates from the baseline;

[0013] Set up visual dashboards and reporting tools: Provide an intuitive and easy-to-understand data display interface to help managers quickly understand the current security situation. Develop or use existing BI tools to generate graphical reports, support on-demand customization of views, and facilitate managers at different levels to view the required information.

[0014] Preferably, in data threat detection and analysis, the specific steps for automatically identifying abnormal behaviors and potential threats in medical institution front-end data using AI and machine learning algorithms are as follows:

[0015] (1) Collecting pre-existing data from medical institutions. Data sources include log files, user activity records, and external threat intelligence. Data preprocessing is performed by removing irrelevant information, filling missing values, unifying the format, and extracting key features that facilitate model learning, such as timestamps, IP addresses, and operation types.

[0016] (2) Select a suitable model, including unsupervised learning models, supervised learning models, and semi-supervised learning models, and then train the model. First, use a large amount of historical normal data to train the model so that the model can learn normal data. After the model training is completed, it is applied to new data. If the input data deviates significantly from the normal pattern learned by the model, it is considered to be abnormal;

[0017] (3) Use a real-time data analysis framework to process real-time data streams, detect abnormal behaviors in a timely manner, set reasonable thresholds for different indicators, trigger alarms once exceeded, and establish a closed-loop system that allows the model to learn and improve from each event. Security experts regularly review the model output to ensure its accuracy and manually adjust the model parameters to improve performance.

[0018] Preferably, in the dynamic update mechanism, specific steps to ensure that the monitoring system can obtain the latest threat intelligence in a timely manner are:

[0019] (1) Identify and select reliable threat intelligence sources. Internal sources include utilizing the organization's internal security event logs and known attack patterns. External sources include subscribing to threat reports from well-known cybersecurity companies and government agencies, and joining industry or regional information sharing and analysis centers.

[0020] (2) Automated access to intelligence sources, using APIs to integrate selected intelligence sources into existing security monitoring systems, and regularly checking and maintaining these connections to ensure their continued availability and up-to-dateness;

[0021] (3) Preprocess the collected threat intelligence, clean the data to remove irrelevant information, and unify the data formats from different sources to facilitate subsequent processing;

[0022] (4) Establish standardized processes: Develop standard processes for handling newly received intelligence;

[0023] (5) Integrate multi-source intelligence, combining information from multiple channels to form a comprehensive view, and use correlation analysis technology to find the connections between different intelligence to help predict potential risks;

[0024] (6) Deploy machine learning models to automatically analyze threat intelligence, identify security risks that affect the organization, adjust model parameters based on historical data to improve accuracy, and immediately update firewall rules, intrusion detection system signatures, or other protective measures when new threats are detected.

[0025] The preferred approach to building a comprehensive protection layer that includes multiple security measures is to configure firewalls to prevent unauthorized external access, deploy IDS / IPS to monitor suspicious behavior in network traffic and take appropriate actions, use encrypted communication channels to ensure the security of remote access, and enforce strong authentication mechanisms.

[0026] Preferably, in adaptive learning, the method of establishing a closed-loop learning mechanism is as follows: collect all relevant security event data, clean the original data, remove noise and irrelevant information, convert data from different sources into a unified format for subsequent processing and analysis, use IDS / IPS and WAF monitoring tools to monitor network activities in real time, and promptly discover potential security threats, configure an automated rule engine, automatically trigger alarms according to predefined standards, preliminarily classify and evaluate events that trigger alarms, determine their severity and scope of impact, use machine learning algorithms to identify emerging behavioral patterns, mark suspicious or abnormal behaviors, conduct more detailed investigations for events marked as high priority, including manual review and correlation analysis, use threat intelligence analysis and behavioral analysis to deeply explore the truth behind the events, establish a feedback mechanism, and feed back the results of each event processing to the system as the basis for future decision-making, adjust model parameters based on feedback, optimize detection algorithms, improve accuracy and efficiency, implement online learning or incremental learning algorithms, so that the model can continue to learn new knowledge without retraining, regularly introduce the latest threat intelligence, and enhance the model's ability to identify new attacks.

[0027] Preferably, the visual dashboard includes a real-time monitoring panel and a threat intelligence view; the reporting tool includes a customized report generator.

[0028] Compared with the prior art, the present invention has the following beneficial effects:

[0029] This application introduces AI and machine learning technologies to accurately distinguish between legitimate activities and malicious intentions, avoid false alarms caused by oversensitivity, and reduce the false alarm rate; the ability to continuously learn and update enables the system to identify new threats more quickly and reduce the risk of missed reports. With the help of dynamic update mechanisms and external threat intelligence, the system can grasp the latest threat information in the first time, adjust defense strategies accordingly, and quickly adapt to new threats. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] Figure 1 Schematic diagram of this monitoring method. DETAILED DESCRIPTION

[0031] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0032] In the description of the present invention, it should be understood that the terms "upper", "lower", "front", "back", "left", "right", "top", "bottom", "inside", "outside", etc., indicating directions or positional relationships, are based on the directions or positional relationships shown in the accompanying drawings, and are only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific direction, be constructed and operated in a specific direction, and therefore should not be understood as limiting the present invention.

[0033] Example:

[0034] See also Figure 1 , the present invention provides a technical solution:

[0035] A method for monitoring the security of pre-installed data in a medical institution. The specific contents of the method for monitoring the security of pre-installed data in a medical institution are as follows:

[0036] Data threat detection and analysis: Leveraging AI and machine learning algorithms to automatically identify abnormal behavior and potential threats in healthcare institutions' front-end data, the model is trained to identify normal operating patterns and flag behaviors that deviate from these patterns as suspicious. The model self-optimizes based on historical data and real-time feedback, reducing false positives and improving detection of unknown threats.

[0037] Dynamic update mechanism: This ensures that the monitoring system can obtain the latest threat intelligence in a timely manner and automatically adjust its strategies to respond to emerging attack methods. It integrates external threat intelligence sources, enables the system to update its knowledge base in real time, and regularly evaluates and updates internal rule sets through automated processes.

[0038] Multi-layered security defense: Build a comprehensive defense layer that includes multiple security measures, including but not limited to intrusion detection systems (IDS), firewalls, encryption, and access control. Different technologies are combined to create a complementary effect. ML models are added to IDS to enhance its judgment, and deep packet inspection is used to analyze malicious code in network traffic.

[0039] Adaptive learning: Establish a closed-loop learning mechanism that allows the system to learn and improve from each event it handles. Every time an alert or event occurs, detailed information is recorded for subsequent analysis and model parameters are adjusted accordingly. A team is assigned to review AI decision-making results and provide manual intervention and correction suggestions.

[0040] User behavior analysis: Focuses on monitoring users' daily activity patterns, identifying abnormal behavior, collecting and analyzing multi-dimensional information such as user login time, location, and device type used, establishing a personal behavior baseline, and triggering alerts when behavior deviates from the baseline;

[0041] Set up visual dashboards and reporting tools: Provide an intuitive and easy-to-understand data display interface to help managers quickly understand the current security situation. Develop or use existing BI tools to generate graphical reports, support on-demand customization of views, and facilitate managers at different levels to view the required information.

[0042] In data threat detection and analysis, the specific steps for using AI and machine learning algorithms to automatically identify abnormal behaviors and potential threats in medical institutions' front-end data are as follows:

[0043] (1) Collecting pre-existing data from medical institutions. Data sources include log files, user activity records, and external threat intelligence. Data preprocessing is performed by removing irrelevant information, filling missing values, unifying the format, and extracting key features that facilitate model learning, such as timestamps, IP addresses, and operation types.

[0044] (2) Select a suitable model, including unsupervised learning models, supervised learning models, and semi-supervised learning models, and then train the model. First, use a large amount of historical normal data to train the model so that the model can learn normal data. After the model training is completed, it is applied to new data. If the input data deviates significantly from the normal pattern learned by the model, it is considered to be abnormal;

[0045] Unsupervised learning models, such as Isolation Forest and Autoencoder, are suitable for unlabeled datasets; supervised learning models, such as Decision Tree, Random Forest, and Support Vector Machine (SVM), are suitable for labeled datasets; semi-supervised learning models combine a small amount of labeled data with a large amount of unlabeled data for training, and are suitable for situations where some data is labeled.

[0046] (3) Use a real-time data analysis framework to process real-time data streams, detect abnormal behaviors in a timely manner, set reasonable thresholds for different indicators, trigger alarms once exceeded, and establish a closed-loop system that allows the model to learn and improve from each event. Security experts regularly review the model output to ensure its accuracy and manually adjust the model parameters to improve performance.

[0047] In the dynamic update mechanism, the specific steps to ensure that the monitoring system can obtain the latest threat intelligence in a timely manner are:

[0048] (1) Identify and select reliable threat intelligence sources. Internal sources include utilizing the organization's internal security event logs and known attack patterns. External sources include subscribing to threat reports from well-known cybersecurity companies and government agencies, and joining industry or regional information sharing and analysis centers.

[0049] (2) Automated access to intelligence sources, using APIs to integrate selected intelligence sources into existing security monitoring systems, and regularly checking and maintaining these connections to ensure their continued availability and up-to-dateness;

[0050] (3) Preprocess the collected threat intelligence, clean the data to remove irrelevant information, and unify the data formats from different sources to facilitate subsequent processing;

[0051] (4) Establish standardized processes: Develop standard processes for handling newly received intelligence;

[0052] (5) Integrate multi-source intelligence, combining information from multiple channels to form a comprehensive view, and use correlation analysis technology to find the connections between different intelligence to help predict potential risks;

[0053] (6) Deploy machine learning models to automatically analyze threat intelligence, identify security risks that affect the organization, adjust model parameters based on historical data to improve accuracy, and immediately update firewall rules, intrusion detection system signatures, or other protective measures when new threats are detected.

[0054] The approach to building a comprehensive protection layer that includes multiple security measures is to configure firewalls to block unauthorized external access, deploy IDS / IPS to monitor suspicious behavior in network traffic and take appropriate actions, use encrypted communication channels to ensure the security of remote access, and enforce strong authentication mechanisms.

[0055] Building a comprehensive layer of protection encompassing multiple security measures is crucial for healthcare organizations to proactively monitor data security. This multi-layered defense strategy aims to provide comprehensive protection by combining different types of control measures to effectively address a wide range of potential security threats.

[0056] In adaptive learning, the method of establishing a closed-loop learning mechanism is as follows: collect all relevant security event data, clean the raw data, remove noise and irrelevant information, convert data from different sources into a unified format for subsequent processing and analysis, use IDS / IPS and WAF monitoring tools to monitor network activities in real time and promptly detect potential security threats, configure an automated rule engine to automatically trigger alarms according to predefined standards, preliminarily classify and evaluate the events that trigger the alarms to determine their severity and scope of impact, use machine learning algorithms to identify emerging behavioral patterns, and mark suspicious or abnormal behaviors. For events marked as high priority, conduct more detailed investigations, including manual review and correlation analysis, use threat intelligence analysis and behavioral analysis to deeply explore the truth behind the events, establish a feedback mechanism, and feed back the results of each event processing to the system as the basis for future decision-making. Adjust model parameters based on feedback, optimize detection algorithms, and improve accuracy and efficiency. Implement online learning or incremental learning algorithms so that the model can continuously learn new knowledge without retraining, regularly introduce the latest threat intelligence, and enhance the model's ability to identify new attacks.

[0057] Establishing a closed-loop learning mechanism that allows medical institutions' front-end data security monitoring systems to learn and improve from each incident handling process is key to improving overall security and response efficiency. This mechanism can help the system adapt to new threat patterns, reduce false alarms and missed alarms, and optimize defense strategies.

[0058] Visual dashboards include real-time monitoring panels and threat intelligence views; reporting tools include a custom report generator.

[0059] The above shows and describes the basic principles and main features of the present invention and the advantages of the present invention. For those skilled in the art, it is obvious that the present invention is not limited to the details of the above exemplary embodiments, and the present invention can be implemented in other specific forms without departing from the spirit or basic characteristics of the present invention; therefore, no matter from which point of view, the embodiments should be regarded as exemplary and non-restrictive. The scope of the present invention is limited by the appended claims rather than the above description. Therefore, it is intended that all changes that fall within the meaning and scope of the equivalent elements of the claims are included in the present invention, and any figure signs in the claims should not be regarded as limiting the claims involved.

[0060] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

Claims

1. A method for monitoring the security of front-end data of a medical institution, characterized in that: The specific contents of the medical institution's front-end data security monitoring method are as follows: Data threat detection and analysis: Leverage AI and machine learning algorithms to automatically identify abnormal behavior and potential threats in healthcare institutions' front-end data. Models are trained to identify normal operating patterns and flag behaviors that deviate from these patterns as suspicious activity. Dynamic update mechanism: This ensures that the monitoring system can obtain the latest threat intelligence in a timely manner and automatically adjust its strategies to respond to emerging attack methods. It integrates external threat intelligence sources, enables the system to update its knowledge base in real time, and regularly evaluates and updates internal rule sets through automated processes. Multi-layered security defense: Build a comprehensive protection layer that includes multiple security measures, including but not limited to intrusion detection systems (IDS), firewalls, encryption technology, and access control. These technologies are combined to create a complementary effect, and deep packet inspection is used to analyze malicious code in network traffic. Adaptive learning: Establish a closed-loop learning mechanism that allows the system to learn and improve from each event it handles. Every time an alert or event occurs, detailed information is recorded for subsequent analysis and model parameters are adjusted accordingly. A team is assigned to review AI decision-making results and provide manual intervention and correction suggestions. User behavior analysis: Focuses on monitoring users' daily activity patterns, identifying abnormal behavior, collecting and analyzing multi-dimensional information such as user login time, location, and device type used, establishing a personal behavior baseline, and triggering alerts when behavior deviates from the baseline; Set up visual dashboards and reporting tools: Provide an intuitive and easy-to-understand data display interface to help managers quickly understand the current security situation. Develop or use existing BI tools to generate graphical reports, support on-demand customization of views, and facilitate managers at different levels to view the required information.

2. A method for monitoring the security of pre-processing data of a medical institution according to claim 1, characterized in that: In data threat detection and analysis, the specific steps for using AI and machine learning algorithms to automatically identify abnormal behaviors and potential threats in medical institutions' front-end data are as follows: (1) Collecting pre-existing data from medical institutions. Data sources include log files, user activity records, and external threat intelligence. Data preprocessing is performed by removing irrelevant information, filling missing values, unifying the format, and extracting key features that facilitate model learning, such as timestamps, IP addresses, and operation types. (2) Select a suitable model, including unsupervised learning models, supervised learning models, and semi-supervised learning models, and then train the model. First, use a large amount of historical normal data to train the model so that the model can learn normal data. After the model training is completed, it is applied to new data. If the input data deviates significantly from the normal pattern learned by the model, it is considered to be abnormal; (3) Use a real-time data analysis framework to process real-time data streams, detect abnormal behaviors in a timely manner, set reasonable thresholds for different indicators, trigger alarms once exceeded, and establish a closed-loop system that allows the model to learn and improve from each event. Security experts regularly review the model output to ensure its accuracy and manually adjust the model parameters to improve performance.

3. A method for monitoring the security of pre-processed data of a medical institution according to claim 1, characterized in that: In the dynamic update mechanism, the specific steps to ensure that the monitoring system can obtain the latest threat intelligence in a timely manner are: (1) Identify and select reliable threat intelligence sources. Internal sources include utilizing the organization's internal security event logs and known attack patterns. External sources include subscribing to threat reports from well-known cybersecurity companies and government agencies, and joining industry or regional information sharing and analysis centers. (2) Automated access to intelligence sources, using APIs to integrate selected intelligence sources into existing security monitoring systems, and regularly checking and maintaining these connections to ensure their continued availability and up-to-dateness; (3) Preprocess the collected threat intelligence, clean the data to remove irrelevant information, and unify the data formats from different sources to facilitate subsequent processing; (4) Establish standardized processes: Develop standard processes for handling newly received intelligence; (5) Integrate multi-source intelligence, combining information from multiple channels to form a comprehensive view, and use correlation analysis technology to find the connections between different intelligence to help predict potential risks; (6) Deploy machine learning models to automatically analyze threat intelligence, identify security risks that affect the organization, adjust model parameters based on historical data to improve accuracy, and immediately update firewall rules, intrusion detection system signatures, or other protective measures when new threats are detected.

4. A method for monitoring the security of pre-processing data of a medical institution according to claim 1, characterized in that: The approach to building a comprehensive protection layer that includes multiple security measures is to configure firewalls to block unauthorized external access, deploy IDS / IPS to monitor suspicious behavior in network traffic and take appropriate actions, use encrypted communication channels to ensure the security of remote access, and enforce strong authentication mechanisms.

5. A method for monitoring the security of pre-processing data of a medical institution according to claim 1, characterized in that: In adaptive learning, the method of establishing a closed-loop learning mechanism is as follows: collect all relevant security event data, clean the raw data, remove noise and irrelevant information, convert data from different sources into a unified format for subsequent processing and analysis, use IDS / IPS and WAF monitoring tools to monitor network activities in real time and promptly detect potential security threats, configure an automated rule engine to automatically trigger alarms according to predefined standards, preliminarily classify and evaluate the events that trigger the alarms to determine their severity and scope of impact, use machine learning algorithms to identify emerging behavioral patterns, and mark suspicious or abnormal behaviors. For events marked as high priority, conduct more detailed investigations, including manual review and correlation analysis, use threat intelligence analysis and behavioral analysis to deeply explore the truth behind the events, establish a feedback mechanism, and feed back the results of each event processing to the system as the basis for future decision-making. Adjust model parameters based on feedback, optimize detection algorithms, and improve accuracy and efficiency. Implement online learning or incremental learning algorithms so that the model can continuously learn new knowledge without retraining, regularly introduce the latest threat intelligence, and enhance the model's ability to identify new attacks.

6. A method for monitoring the security of pre-processing data of a medical institution according to claim 1, characterized in that: Visual dashboards include real-time monitoring panels and threat intelligence views; reporting tools include a custom report generator.