A network behavior security monitoring method, system, device and storage medium

By collecting and analyzing network traffic information in the medical equipment network, timely judging and isolating abnormal data transmission, the problem of rapid dissemination of abnormal data affecting the stability of medical networks is solved, and more effective network behavior security monitoring and isolation are achieved.

CN119051988BActive Publication Date: 2025-05-16XINYICHENG TECH (JIANGSU) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411526933.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-30
Publication Date
2025-05-16
Estimated Expiration
2044-10-30

AI Technical Summary

Technical Problem

After the existing medical equipment network behavior security monitoring methods detect abnormalities, abnormal data quickly spread to other medical information subsystems, resulting in the stable operation of the entire medical network being affected.

Method used

A network behavior security monitoring method is adopted. After monitoring the data transmission signal, network traffic information is periodically collected, preliminary judgment is made according to the preset abnormal judgment rules, and an emergency isolation mechanism is triggered when data transmission is unsafe, to isolate and track abnormal transmission data.

Benefits of technology

Effectively prevent the impact of abnormal data transmission on other medical information subsystems, reduce the risk of attack spread, and provide detailed attack information to quickly locate and repair problems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119051988B_ABST
    Figure CN119051988B_ABST
Patent Text Reader

Abstract

The present application relates to a network behavior security monitoring method, system, device and storage medium, which belongs to the field of network security monitoring technology, wherein the method includes collecting network traffic information; obtaining a first detection result based on the network traffic information; when the first detection result is that the data transmission is unsafe, triggering an emergency isolation mechanism; when the first detection result is that the data transmission may be abnormal, obtaining the network traffic information within a preset verification time to obtain the actual total traffic within the verification time; obtaining the historical traffic data set and the corresponding historical process log of the link to be verified, and performing correlation analysis and verification based on the historical traffic data set and the historical process log to obtain the verification result; when the verification result is that the data transmission is unsafe, triggering the emergency isolation mechanism. The present application uses the emergency isolation mechanism to immediately isolate the abnormal transmission data in a specific isolation link for circulation when unsafe data transmission is detected, effectively reducing the risk of attack spread.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of network behavior security monitoring, and in particular to a network behavior security monitoring method, system, device and storage medium. Background Art

[0002] In today's era of rapid development of medical information technology, medical information systems play a vital role in medical services. However, due to the particularity and complexity of the medical industry, network security issues are becoming increasingly prominent. When the communication network established by several medical devices is attacked, first of all, the patient's medical data may be stolen, tampered with or leaked. Medical data contains sensitive content such as patients' personal privacy information, medical records, diagnosis results, etc. Once leaked, it will not only infringe on the patient's privacy rights, but may also be used by criminals for illegal purposes, such as identity theft, insurance fraud, etc.; secondly, the failure of the medical information subsystem may affect the normal provision of medical services. For example, if the electronic medical record system cannot be accessed normally, doctors cannot view the patient's medical record information in time, which may lead to misdiagnosis or delayed treatment. If the control system of medical equipment is attacked, it may cause equipment failure and even endanger the patient's life safety.

[0003] At present, the network behavior security monitoring of medical devices is mainly achieved through firewalls and intrusion detection systems. These monitoring methods / systems are mainly used to limit network traffic, block unauthorized access according to preset rules, or detect potential attacks by monitoring abnormal behavior in network traffic, thereby limiting external network access to medical devices and preventing medical devices from sending data to untrusted networks. However, traditional firewalls and intrusion detection systems are often based on known attack patterns and signatures for detection, and may not be able to detect new and unknown attacks in a timely manner; when faced with complex medical device network environments, false positives or missed positives may occur.

[0004] In addition, currently these traditional network security detection methods / systems can usually only alert relevant technical personnel to take emergency protection through alarms after detecting an attack. In the case that most medical information subsystems are connected to a unified network, once one of the information subsystems is attacked, the abnormal surge in data traffic may quickly spread to other medical information subsystems, thereby affecting the stable operation of the entire medical network. Summary of the invention

[0005] In order to improve the problem that after the current network behavior security monitoring method detects anomalies, the anomalies still spread rapidly to other medical information subsystems, thereby affecting the stable operation of the entire medical network, the present application provides a network behavior security monitoring method, system, device and storage medium.

[0006] In the first aspect, the present application provides a network behavior security monitoring method, which adopts the following technical solution:

[0007] A network behavior security monitoring method is based on a network behavior security monitoring system, wherein the network behavior security monitoring system is adapted to a medical information system including a plurality of information subsystems, each of which corresponds to a different type of medical equipment, and the information subsystem is used to receive and store transmission data collected and sent by all corresponding medical equipment, and the network behavior security monitoring method includes:

[0008] After detecting the data transmission signal, periodically collect the network traffic information in the current communication link;

[0009] Performing a preliminary transmission security judgment on the data transmission according to the preset abnormality judgment rule and the network traffic information to obtain a first detection result, wherein the first detection result includes that the data transmission is unsafe and there is an abnormal risk in the data transmission;

[0010] When the first detection result is that the data transmission is unsafe, triggering an emergency isolation mechanism to isolate and track the abnormal transmission data;

[0011] When the first detection result is that there is an abnormal risk in data transmission, the communication link corresponding to the first detection result is used as a link to be verified, and multiple network flow information in the link to be verified within a preset verification time are obtained to obtain a network flow information set, wherein the network flow information set includes the multiple network flow information obtained;

[0012] Obtaining the actual total flow of the transmission data within a preset verification time according to the network flow information set;

[0013] Obtaining a historical traffic data set of the link to be verified and historical process logs of the two information subsystems corresponding to the link to be verified, and performing correlation analysis and verification on the transmission data according to the historical traffic data set, the actual total traffic and the historical process logs to obtain a verification result, wherein the verification result includes that the data transmission is unsafe;

[0014] When the verification result is that the data transmission is unsafe, the emergency isolation mechanism is triggered to isolate and track the abnormal transmission data.

[0015] In a specific feasible implementation scheme, the abnormality determination rule includes a primary abnormality rule and a secondary abnormality rule. The primary abnormality rule includes the following determination factors: maximum flow warning value, allowed flow transmission direction and limited data packet format. The primary abnormality rule is used to determine whether the transmission data is caused by obvious network attack and intrusion; the secondary abnormality rule includes the following determination factors: specified network protocol, flow increase rate and data packet size. The secondary abnormality rule is used to determine whether the transmission data is different from the normal data transmission situation; the first detection result also includes that the data transmission is normal; the data transmission is initially judged for transmission security according to the preset abnormality determination rule and the network flow information, and the first detection result includes:

[0016] If all the transmission data in the network traffic information does not comply with the first-level abnormality rule and the second-level abnormality rule, the first detection result is that the data transmission is normal;

[0017] If any transmission data that meets the first-level abnormality rule exists in the network traffic information, the first detection result is that the data transmission is unsafe;

[0018] If there is no transmission data that complies with the first-level abnormal rule and there is any transmission data that complies with the second abnormal rule in the network traffic information, the first detection result is that there is an abnormal risk in the data transmission.

[0019] In a specific implementation scheme, the triggering of the emergency isolation mechanism to isolate and track the abnormal transmission data includes:

[0020] The communication link corresponding to the first detection result that the data transmission is unsafe is used as the first link, and the key node preset in the first link is used as a stage node, wherein the key node is a virtual network node in the communication link, which is set between every two communication-connected information subsystems and each of the key nodes is connected to other key nodes;

[0021] Determine an isolation link according to a current stage node and the first link, wherein the isolation link is a closed communication link composed of the stage node and the other key nodes;

[0022] When the abnormal transmission data is cyclically transmitted in the isolation link, acquiring abnormal data features corresponding to the abnormal transmission data;

[0023] A comparison and match is performed in a preset abnormal type library according to the abnormal data features to obtain a suspected abnormal type.

[0024] In a specific implementation scheme, determining the isolation link according to a current stage node and the first link includes:

[0025] Selecting one of the starting node and the ending node of the first link as the phase endpoint of this round;

[0026] A second link of this round is obtained according to the phase endpoint of this round, wherein the second link refers to another communication link that can be connected to the communication link where the phase endpoint is located, and the phase endpoint is on the second link;

[0027] Determine whether there are other communication links at the starting node or the ending node of the second link in this round;

[0028] If the judgment result is no, then exclude the second link of this round and repeat the step of obtaining a second link of this round according to the phase endpoint of this round until a second link of this round that meets the condition is obtained;

[0029] If the judgment result is yes, the key node in the second link of the current round is used as the stage node of the next round, and one of the start node and the end node of the second link is selected as the stage endpoint of the next round;

[0030] Repeat multiple rounds of operations until all the phase nodes meet the isolation condition, then terminate the operation, and obtain the isolation link based on all the phase nodes.

[0031] In a specific implementation scheme, the communication link between every two phase nodes in the isolated link is an isolated sub-link, and after the step of obtaining the isolated link according to all the phase nodes, the step further includes:

[0032] When the abnormally surged flow of the transmitted data is greater than the carrying capacity of the isolation link, all the current isolation sub-links are excluded, and the step of determining the isolation link based on the current stage node and the first link is repeated according to the remaining communication links until another isolation link is obtained.

[0033] In a specific feasible implementation scheme, the historical process log includes all process operations occurring between the two information subsystems within a certain period of time, and is used to reflect the mutual communication between the corresponding two information subsystems within a certain period of time; the historical traffic data set includes the fluctuation of the traffic size of the transmission data corresponding to each process operation in the historical process log, and is used to reflect the network traffic situation of the link to be verified corresponding to each process operation under normal circumstances.

[0034] In a specific implementation scheme, the transmission data is verified by correlation analysis based on the historical traffic data set, the actual total traffic, and the historical process log, and the verification result obtained includes:

[0035] Identify, according to the historical traffic data set, the standard traffic conditions corresponding to the link to be verified and each of the process operations under normal circumstances, wherein the standard traffic conditions include the average traffic size and average duration generated on the link to be verified when the corresponding process operation is executed;

[0036] Obtain the current process log within the verification time, and determine the current ideal total flow of the transmission data according to the current process log and the standard flow situation, wherein the ideal total flow is the sum of the flow of the transmission data generated on the link to be verified when all the process operations within the verification time are executed;

[0037] Obtaining a deviation value according to the actual total flow and the ideal total flow, wherein the deviation value is the difference between the actual total flow and the ideal total flow;

[0038] Comparing the deviation value with a preset difference threshold;

[0039] When the deviation value exceeds the difference threshold, the verification result is determined to be that the data transmission is unsafe; otherwise, the verification result is determined to be that the data transmission is normal.

[0040] In the second aspect, the present application provides a monitoring management platform, which adopts the following technical solutions:

[0041] A monitoring and management platform includes a memory and a processor, wherein the memory stores at least one instruction, at least one program, code set or instruction set, and the at least one instruction, at least one program, code set or instruction set is loaded and executed by the processor to implement the network behavior security monitoring method as described in the first aspect.

[0042] In a third aspect, the present application provides a network behavior security monitoring system, which adopts the following technical solutions:

[0043] A network behavior safety monitoring system adopts a monitoring management platform as described in the second aspect, and the network behavior safety monitoring system is adapted to a medical information system including a plurality of information subsystems, and each of the information subsystems corresponds to a different type of medical equipment, including:

[0044] A plurality of network behavior sensing machines are provided and correspond to each of the information subsystems one by one, and are used to collect network traffic information of the corresponding information subsystem when receiving transmission data and sending transmission data;

[0045] The monitoring and management platform is communicatively connected with all network behavior perception machines, and is used to monitor and manage the communication transmission between information subsystems based on the network traffic information.

[0046] In a fourth aspect, the present application provides a computer-readable storage medium, which adopts the following technical solution:

[0047] A computer-readable storage medium, wherein at least one instruction, at least one program, code set or instruction set is stored in the readable storage medium, and the at least one instruction, at least one program, code set or instruction set is loaded and executed by a processor to implement the network behavior security monitoring method as described in the first aspect.

[0048] In summary, the present application includes at least one of the following beneficial technical effects:

[0049] 1. Through the emergency isolation mechanism, when unsafe data transmission is detected, the abnormal transmission data is immediately isolated and circulated in a specific isolation link. This prevents the abnormal transmission data from affecting other medical information subsystems and greatly reduces the risk of attack spread. At the same time, the isolated abnormal transmission data is tracked and the abnormal type is judged in the isolation link, which can provide more detailed attack information for relevant technical personnel, helping them to quickly locate the problem and take targeted measures to repair it;

[0050] 2. Compared with traditional network behavior security monitoring methods, this application mainly focuses on protecting against internal attacks on information systems, greatly improving the weakness of traditional network security detection methods in dealing with internal abnormal transmission data, and providing more comprehensive protection for medical data security; at the same time, when responding to attacks, traditional monitoring methods may cause system performance degradation or equipment failure due to the inability to effectively control abnormal transmission data. The emergency isolation mechanism can quickly isolate abnormal transmission data, reduce its impact on the network and equipment, and ensure the stable operation of medical equipment and information subsystems;

[0051] 3. When this application detects network security anomalies, it can first isolate the abnormal transmission data by itself. Without human intervention, it not only effectively avoids the leakage of sensitive data, but also ensures the normal operation of other information subsystems; in addition, relevant technical personnel can perform faster network maintenance and patch vulnerabilities based on the tracing results after the monitoring and management platform issues an alarm. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] Figure 1 It is a structural diagram of a network behavior security monitoring system according to an embodiment of the present application.

[0053] Figure 2It is a structural diagram of an embodiment of the present application for reflecting the communication relationship between the information subsystem, the medical information system and the medical equipment.

[0054] Figure 3 It is a structural diagram for reflecting the communication relationship between the network behavior perception machine and the information subsystem according to an embodiment of the present application.

[0055] Figure 4 It is a flowchart of a network behavior security monitoring method according to another embodiment of the present application.

[0056] Figure 5 It is a structural diagram of another embodiment of the present application for showing an isolation link formed by key nodes. DETAILED DESCRIPTION

[0057] In order to make the objectives, technical solutions and advantages of the present application clearer, the implementation methods of the present application will be further described in detail below with reference to the accompanying drawings.

[0058] The following is a further detailed description of an embodiment of a network behavior security monitoring method, system, device and storage medium of the present application in conjunction with all the drawings in the specification.

[0059] An embodiment of the present application discloses a network behavior security monitoring system.

[0060] Reference Figure 1 A network behavior security monitoring system is adapted to a medical information system including several medical devices, in which the medical devices may be vital sign monitoring devices such as electrocardiogram monitors, medical imaging devices such as X-ray machines, laboratory testing devices such as blood analyzers, patient identification devices such as RFID readers, and equipment monitors such as equipment status sensors; these medical devices are used to collect various transmission data within medical institutions, and the transmission data include any one of patient information (basic information, medical history information, examination and testing information, diagnosis information, and treatment information), medical resource information (equipment information, drug information, medical staff information), and management information (financial information and administrative information).

[0061] The medical information system includes several information subsystems corresponding to different types of medical equipment, each of which is used to receive and store the transmission data collected and sent by all corresponding medical equipment; each information subsystem includes a second processor and a second memory corresponding to one of them, and the second memory is used to store at least one instruction, at least one program, code set or instruction set; the second processor executes the data transmission steps between the information subsystems when running at least one instruction, at least one program, code set or instruction set. The specific steps of data transmission are prior art and will not be repeated here. The relationship between the medical information system and the information subsystem of this embodiment is explained in detail below:

[0062] Reference Figure 2 In this embodiment, for ease of understanding, all medical devices are classified according to their types, and several medical devices of the same type are regarded as an information subsystem, that is, several medical devices in the same information subsystem will send and store their collected transmission data in the corresponding information subsystem; at the same time, the data communication in this embodiment is mainly realized by the information subsystems corresponding to the two medical devices. For example, when medical device B needs to access and obtain data in medical device A, the information subsystem B corresponding to medical device B will send an access request to the information subsystem A corresponding to medical device A, and obtain the required transmission data after the application is passed.

[0063] Based on the above medical information system, a network behavior security monitoring system of the present application includes several network behavior sensing machines, a monitoring management platform and a display device:

[0064] Reference Figure 3 Each information subsystem is equipped with a network behavior perception machine, which can be a network probe, protocol analyzer or other traffic monitoring equipment, and is used to periodically collect network traffic information of the corresponding information subsystem when receiving and sending transmission data; each network behavior perception machine stores corresponding abnormality judgment rules, and the abnormality judgment rules include specific situations such as the maximum traffic warning value and the allowed traffic transmission direction; the network behavior perception machine is also used to perform preliminary transmission security judgment on data transmission according to preset abnormality judgment rules and network traffic information to obtain a first detection result, and the first detection result includes that the data transmission is normal, the data transmission is unsafe, and there is an abnormal risk in the data transmission.

[0065] The monitoring and management platform is communicatively connected with all network behavior perception machines. Several key nodes are stored in the monitoring and management platform. These key nodes are virtual network nodes realized by software. In this embodiment, a key node is set on the communication link for transmitting data between every two information subsystems, and all key nodes on all communication links corresponding to the same information subsystem are interconnected (the interconnection in this embodiment does not mean that each key node needs to be directly connected to all other key nodes, but only means that each key node can directly / indirectly reach any other key node through one or more other key nodes. In this embodiment, this setting can realize that when each information subsystem transmits data, all its corresponding key nodes can form a closed loop halfway when the data reaches other information subsystems. This will be explained in detail here in conjunction with subsequent examples and method steps) and bidirectional data transmission is allowed as an example; these key nodes can be run on general servers or virtual machines, which usually use software defined networks (SDN) ), network function virtualization (NFV), etc., separate network functions from traditional hardware devices to achieve flexible data transmission management and control; at the same time, virtual key nodes can be flexibly configured and managed in a software-defined manner, that is, the staff can set the key node at a certain point of a certain communication link as needed through the monitoring and management platform, and can also freely adjust the connection relationship between all the set key nodes through the monitoring and management platform; the method for making nodes in the communication link is a prior art and will not be repeated here (in this embodiment, during data transmission under normal circumstances, the destination address in each key node is consistent with the destination address in the transmission data, that is, the transmission path of the data will not change when it passes through the key node; when the emergency isolation mechanism is triggered, the monitoring and management platform will assign a new destination address to the relevant key node, that is, the new stage node mentioned in the following method step S300, at which time all transmission data passing through the key node will be pushed to the new stage node).

[0066] The following explains the communication link by taking the example of information subsystem B obtaining the transmission data in information subsystem A after obtaining access rights: the communication link between information subsystems A and B is composed of a starting node A (i.e., information subsystem A) representing the data storage address, an ending node B (i.e., information subsystem B) representing the data destination address, and a key node (A, B) arranged between the starting node and the ending node, which can be used to reflect the transmission process of the transmission data in information subsystem A.

[0067] The monitoring management platform is used to isolate and track abnormally transmitted data through several key nodes when the first detection result is that the data transmission is unsafe;

[0068] The monitoring and management platform is used to obtain the network traffic information in the corresponding network behavior perception machine when the first detection result shows that there is an abnormal risk in data transmission, and to perform real-time monitoring and early warning of current data transmission based on changes in the network traffic information. Later, when network security anomalies are detected, the transmission data of the abnormal transmission is isolated and tracked through several key nodes.

[0069] The display device is used to present the first detection result and network traffic information to relevant technical personnel.

[0070] The monitoring and management platform includes a first processor and a first memory, wherein the first memory is used to store at least one instruction, at least one program, code set or instruction set; the first processor executes the following steps of the network behavior security monitoring method when running at least one instruction, at least one program, code set or instruction set.

[0071] The following is a detailed description of the implementation of the network behavior security monitoring method in combination with the above-mentioned network behavior security monitoring system:

[0072] Reference Figure 4 Another embodiment of the present application provides a network behavior security monitoring method, including:

[0073] S100, after monitoring the data transmission signal, periodically collecting network traffic information in the current communication link;

[0074] Among them, the data transmission signal refers to the sign that there is a sign that data is being transmitted in the communication link between two information subsystems. This embodiment takes the start of communication of a specific protocol between the corresponding two information subsystems as an example; this embodiment takes every two minutes as a collection cycle, and the cycle is mainly freely set by the staff on the monitoring and management platform. Usually, the value of the cycle needs to consider factors such as the maximum load of the network, the requirements for real-time security detection, the speed of collecting data, and the consumption of system resources. If the cycle is too short, it may consume too many system resources and greatly affect the real-time nature of the detection; if the cycle is too long, it may not be possible to discover potential network security problems in time; network traffic information includes the size of the traffic, the source of the traffic, the direction of the traffic, the type of network protocol, the source address and destination address of the transmitted data, the port number and other data, which are used to reflect the status and characteristics of data transmission in the current network.

[0075] S200, performing a preliminary transmission security judgment on the data transmission according to a preset abnormality judgment rule and network traffic information to obtain a first detection result;

[0076] Among them, the first detection result includes that data transmission is normal, data transmission is unsafe, and there is an abnormal risk in data transmission; the abnormal judgment rules include the first-level abnormal rules and the second-level abnormal rules. The first-level abnormal rules include the judgment elements such as the maximum flow warning value, the allowed flow transmission direction, and the limited data packet format. For example, a large number of unknown data packets from unknown source addresses, a surge in flow within a certain time period exceeding the flow warning value, and the destination address of the transmitted data is unknown, which are obviously abnormal network intrusion features; the second-level abnormal rules include the judgment elements such as the network protocol specified between the two information subsystems, the rate of increase of flow, and the size of the data packet. For example, the rate of increase of flow reaches a certain threshold, the data packet is greater than a certain standard length, and an unknown network protocol / port appears. The first-level abnormal rules and the second-level abnormal rules are formulated by the staff in advance according to the standard network protocols, security standards, common network security threats, etc. between the information subsystems. Among them, the first-level abnormal rules are used to judge whether the transmitted data comes from obvious network attacks and intrusions, so as to intercept some relatively obvious malicious network attacks and intrusions at the first time; the second-level abnormal rules are used to judge whether the transmitted data is different from the normal data transmission situation, so as to monitor and verify the possible network attacks and intrusions in real time.

[0077] Specifically, S200 includes:

[0078] S210, if all the transmission data in the network traffic information do not comply with the first-level abnormality rule and the second-level abnormality rule, the first detection result is that the data transmission is normal;

[0079] If there is any transmission data that meets the first-level abnormality rule in the network traffic information, the first detection result is that the data transmission is unsafe;

[0080] If there is no transmission data that meets the first-level abnormality rule and there is any transmission data that meets the second abnormality rule in the network traffic information, the first detection result is that there is an abnormal risk in the data transmission;

[0081] Among them, taking into account normal business growth, such as the frequent use of electronic medical record systems and medical imaging systems (equivalent to two information subsystems) during outpatient peak hours, more users' visits when new medical services are launched, and failures of some medical equipment (including mechanical failures of the equipment itself and failures of the corresponding network), such as repeated sending of data packets due to router failures, broadcast storms caused by incorrect switch port settings, etc., all of which will cause network traffic to be higher than the usual standard value. Therefore, whether the network behavior that meets the second exception rule is actually a malicious attack or a security incident requires in-depth detection using the subsequent step S400 to minimize false alarms.

[0082] S300, when the first detection result is that the data transmission is unsafe, triggering an emergency isolation mechanism to isolate and track the abnormal transmission data;

[0083] Specifically, the emergency isolation mechanism in S300 includes the following steps:

[0084] S310: The communication link corresponding to the first detection result that data transmission is unsafe is used as a first link, and a key node in the first link is used as a stage node.

[0085] S320, determining an isolation link according to a current phase node and the first link;

[0086] Specifically, S320 includes:

[0087] S321, selecting one of the start node and the end node of the first link as the phase endpoint of this round;

[0088] S322, obtaining a second link of this round according to the phase endpoint of this round;

[0089] The second link refers to another communication link that can be connected to the communication link where the stage endpoint is located, and the stage endpoint is on the second link.

[0090] S323, determining whether there are other communication links at the starting node or the ending node of the second link of this round;

[0091] S324, if the judgment result is no, then exclude the second link of this round and return to S322 to obtain another second link of this round that can be connected to the first link;

[0092] If the judgment result is yes, the key node in the second link of this round is used as the stage node of the next round, and one of the start node and the end node of the second link is selected as the stage endpoint of the next round;

[0093] S325, repeat multiple rounds of operations until all the obtained stage nodes meet the isolation condition, then terminate the operation, and obtain the isolation link according to all the stage nodes;

[0094] Among them, satisfying the isolation condition means that a closed communication link independent of the various information subsystems within the medical institution can be formed between all the stage nodes finally obtained, that is, the last stage node in the second link obtained can be directly connected to the stage node in the first link; the isolation link is a communication link formed by connecting all the stage nodes according to the order of acquisition.

[0095] It should be noted that the communication link between each two stage nodes in the isolation link is an isolation sub-link. During the execution of the above steps S321-S325, the monitoring and management platform will save all the isolation sub-links in the isolation link as an isolation sub-link set; at the same time, when the abnormal surge in the flow of transmission data is greater than the carrying capacity of the isolation link formed in S325, S320 also includes the following steps:

[0096] S326, exclude the current isolated sub-link set, and repeat S321-S325 according to the remaining communication links until another isolated link is obtained.

[0097] Reference Figure 5 , the following takes the communication link between information subsystem A and information subsystem B (which can be understood as a small local area network) with a carrying capacity of 100Mbps (that is, 100 megabits of data can be transmitted per second), and the average traffic is 30Mbps under normal business. At this time, the communication link is attacked by a distributed denial of service (DDOS), and the attack traffic is as high as 200Mbps. At this time, the first detection result of the communication link A→B corresponding to the transmission of data from the starting node A (information subsystem A) to the terminating node B (information subsystem B) is that the data transmission is unsafe. As an example, the above emergency isolation mechanism is explained in detail:

[0098] First, according to S310, the first link A→B and the first stage node (A, B) in this case are obtained; assuming that the first stage endpoint B and the first second link B→F are currently obtained according to S321 and S322, since there are other communication links (i.e. B→C) at the starting node B (i.e. stage endpoint B) of the second link B→F / there are other communication links (i.e. F→A) at the ending node F (i.e. stage endpoint F), the second link is determined to be B→F; then according to S324, the second stage node (B, F) is obtained. In step S325, the monitoring management platform will repeat steps S322-S324 according to the obtained second stage endpoint F (or B) to obtain the second second link F→A (or B→C) and the third stage node (A, F) in sequence. At this time, the ending node A of the second second link F→A coincides with the starting node A of the first link A→B, and it is determined that the three stage nodes can be connected to form a loop, and the isolation link L1 is obtained: (A, B)→(B, F)→(A, F);

[0099] However, since the carrying capacity of the first isolated link L1 obtained above is not sufficient to cope with the surge in network traffic, at this time, steps S321-S325 are repeated according to S326 and the previously obtained isolated sub-link set to obtain a new round of isolated links L2: Assume that the first stage endpoint B and the first second link A→D are obtained according to S321 and S322. Since there are other communication links (i.e., D→E) at the termination node D (i.e., stage endpoint D) of the second link A→D, the second link is determined to be A→D (there are only communication links A→F and first links A→B at the starting node A, where the key node on the communication link A→F is (A, F), and the isolated sub-link of (A, F)→(A, B) is included in the isolated sub-link set corresponding to the isolated link L1. The latter first link A→B does not meet the definition that the second link cannot overlap with the first link. Therefore, in this case, the starting node A cannot be used as the stage endpoint of this round); then According to S324, the second stage node (A, D) is obtained. In step S325, the monitoring and management platform will repeat steps S322-S324 according to the obtained second stage endpoint D to obtain the second second link D→E and the third stage node (D, E) in sequence. However, since the stage node (D, E) cannot be directly connected to the stage node (A, B), the loop continues, repeating steps S322-S324 to obtain the third second link E→C, the fourth stage node (C, E), the fourth second link C→B and the fifth stage node (B, C) in sequence. At this time, the termination node B of the second link C→B coincides with the termination node B of the first link, and it is determined that the four stage nodes can be connected to form a loop, and the isolation link L2 is obtained: (A, B)→(A, D)→(D, E)→(C, E)→(B, C), and each isolation sub-link of the isolation link L2 does not overlap with any isolation sub-link in the isolation link L1.

[0100] Table 1 is used below to briefly explain the data processing sequence of the emergency isolation mechanism in step S30:

[0101] Table 1:

[0102]

[0103] It should be noted that the isolation link in this embodiment mainly takes three-segment isolation sub-link as an example. At the same time, in order to facilitate the explanation of the above steps, in this embodiment, the key nodes on all communication links corresponding to the same information subsystem are mainly connected. However, in actual situations, if there are two information subsystems that only maintain a communication connection relationship with each other, the use of the above-mentioned key node connection method will result in the two information subsystems corresponding to only the same communication link and having only one key node. Because in actual applications, the connection method of different key nodes needs to be considered in combination with multiple factors to try to avoid the situation where a single key node cannot form a closed isolation link; specifically, the staff mainly needs to consider the following factors when connecting different key nodes:

[0104] First, the function and importance of the information subsystem should be considered; if the information subsystem involves critical business or sensitive data, the key nodes connected to it should come from information subsystems with similar security levels and business requirements. For example, the key nodes corresponding to the medical record management system can be connected to the key nodes corresponding to the electronic medical record system, because they both involve sensitive patient information and require higher security protection;

[0105] Secondly, network traffic and performance requirements must be considered; by connecting key nodes corresponding to information subsystems with low network traffic and low performance requirements, network congestion and performance impact on key business systems can be avoided. For example, the key nodes corresponding to the hospital's internal training system can be connected to the key nodes corresponding to some auxiliary management systems, but should not be connected to the key nodes corresponding to the real-time medical monitoring system.

[0106] In addition, the business relevance between information subsystems should also be considered. If two information subsystems have a certain relevance in business processes, then the connection of their corresponding key nodes can improve work efficiency and the convenience of data sharing. For example, the key nodes corresponding to the pharmacy management system can be connected with the key nodes corresponding to the doctor's prescription system to update drug inventory information and process prescriptions in a timely manner;

[0107] Finally, the consistency of security policies and access control also needs to be considered when connecting key nodes. Ensure that the connected key nodes follow the same security rules and access permission settings to prevent unauthorized access and data leakage. For example, if an information subsystem adopts strict encryption and authentication mechanisms, the key nodes connected to it should also come from information subsystems that adopt the same security measures.

[0108] It should be noted that after the isolation link is formed, the monitoring and management platform will assign each relevant key node the address of the corresponding next key node as the updated destination address. At this time, all abnormal transmission data passing through the key nodes on the first link will be fixedly pushed into one or more isolation links at the key nodes for circulation, and will no longer continue to maintain the previous transmission track to a certain information subsystem. In this way, the attacked information subsystem can be effectively protected, and in the data flow cycle (i.e., the attack process), the abnormal transmission data can be traced in the following steps S330-S340.

[0109] S330, when abnormal transmission data is transmitted in the isolated link, obtaining abnormal data features corresponding to the abnormal transmission data;

[0110] The abnormal transmission data information includes the type, source, destination address, protocol type, data packet size, timestamp and other data of the abnormal transmission data.

[0111] S340, performing comparison and matching in a preset abnormal type library according to the abnormal data features to obtain a suspected abnormal type;

[0112] Among them, the abnormal type library includes all abnormal types that have occurred in the past and the known abnormal features corresponding to each abnormal type; specifically, this step can be carried out by comparing each abnormal data feature of the abnormal transmission data with the known abnormal features in the abnormal type library in turn: if the type of the abnormal transmission data is consistent with the common data type of a certain abnormal type in the library, for example, the library records a specific type of network attack that usually manifests itself as a certain specific data type, then it is preliminarily determined that the abnormality may belong to this type; then, check the source address of the abnormal transmission data, if it overlaps with the known malicious source address or suspicious address range in the library, the possibility of matching is further increased; if the destination address is a key information subsystem or sensitive area, and matches the known attack target, the possibility of the corresponding abnormal type will also be increased; then analyze the protocol type, if it is consistent with the protocol used by the specific abnormality in the library, such as some attacks specifically exploit specific network protocol vulnerabilities, the matching degree will also be enhanced; at the same time, compare the data packet size, if the data packet size of the abnormal transmission data is within the common data packet size range of a certain abnormal type in the library, it is also used as a basis for matching. Finally, the timestamp can also be used as a reference factor. If abnormal transmission data related to a certain abnormal type in the library frequently appears within a specific time period and the time characteristics are consistent, it can also help determine the abnormal type. By comprehensively considering the matching of these abnormal data characteristics with the abnormal type library, it is determined that the abnormal type to which the abnormal transmission data most likely belongs is the prior art, which will not be repeated here. Step S34 is mainly used to preliminarily determine the abnormal type while waiting for professionals, which helps professionals to take targeted countermeasures in a timely manner and improve maintenance efficiency.

[0113] S400, when the first detection result is that there is an abnormal risk in data transmission, the communication link corresponding to the first detection result is used as a link to be verified, and multiple network flow information in the link to be verified within the verification time is obtained to obtain a network flow information set;

[0114] Among them, the verification time length for obtaining the network traffic information set can be set according to actual conditions. Generally, a time period ranging from a few minutes to tens of minutes can be selected. It can be set manually or freely adjusted by the monitoring and management platform according to the change range of the traffic size in the previous network traffic information (when the change range is large, it is regarded as the network traffic fluctuation is large, and there is a greater probability of anomalies. At this time, shortening the verification time will ensure the real-time nature of anomaly monitoring; when the change range is small, it is regarded as the network traffic fluctuation is relatively stable, and the existing anomalies may be more hidden and difficult to find. At this time, appropriately extending the verification time will improve the accuracy of anomaly monitoring); the network traffic information set includes multiple network traffic information obtained within the verification time.

[0115] S500, obtaining the actual total flow of data transmitted within the verification time according to the network flow information set;

[0116] Among them, the actual total flow refers to the total size of the transmission data flow during the current verification time. This data can be obtained by fitting and predicting the changes in network flow data at different time points during the verification time (with the time point as the x-axis and the flow size as the y-axis, and calculating the area between the fitting line segment reflecting the change of flow size over time and the x-axis during the verification time. This area is the current total flow). This is existing technology and will not be repeated here. At the same time, this data can also be used to draw a curve showing the change of network flow over time and present the corresponding curve on a display device, so that staff can intuitively understand the dynamic change trend of flow.

[0117] S600, obtaining a historical traffic data set of the link to be verified and historical process logs of two information subsystems corresponding to the link to be verified, and performing correlation analysis and verification on the transmission data according to the historical traffic data set, the actual total traffic and the historical process logs to obtain a verification result;

[0118] Among them, the historical process log includes all process operations of the corresponding information subsystem within a certain period of time. The process operations can be new user login, software update, configuration change, receiving unfamiliar access requests, etc. The historical process log is used to reflect the mutual communication between the corresponding two information subsystems within a certain period of time. The certain period of time in this embodiment takes the most recent month as an example; the historical traffic data set includes the fluctuation of the transmission data traffic size corresponding to each process operation in the historical process log, which is used to reflect the network traffic generated by a certain process operation under normal circumstances on the link to be verified; the verification results include unsafe data transmission and normal data transmission.

[0119] Specifically, the correlation analysis verification in S600 mainly includes:

[0120] S610, identifying, according to the historical traffic data set, a standard traffic situation corresponding to the link to be verified and each process operation under normal circumstances;

[0121] The standard traffic situation of this embodiment includes: when the two information subsystems corresponding to the link to be verified perform corresponding process operations, the average traffic size and average duration generated on the link to be verified.

[0122] S620, obtaining the current process log within the verification time, and determining the ideal total flow rate of the current transmission data according to the current process log and the standard flow rate;

[0123] Among them, the ideal total flow is: the sum of the flow of transmission data generated on the link to be verified when the two information subsystems corresponding to the link to be verified perform all process operations within the verification time; specifically, calculating the sum of the flow based on all process operations and the average flow size and average duration corresponding to each process operation is an existing technology and will not be repeated here.

[0124] S630, obtaining a deviation value according to the actual total flow and the ideal total flow;

[0125] The deviation value refers to the difference between the actual total flow and the ideal total flow.

[0126] S640, comparing the deviation value with a preset difference threshold;

[0127] The difference threshold in this embodiment takes 5% of the ideal total flow as an example.

[0128] S650, when the deviation value exceeds the difference threshold, it means that the current network traffic is significantly different from the historical traffic after the same operation under normal circumstances. At this time, the verification result is determined to be that the data transmission is unsafe; otherwise, it means that the current network traffic is relatively consistent with the historical process log. At this time, the verification result is determined to be that the data transmission is normal.

[0129] S700, when the verification result is that the data transmission is unsafe, triggering an emergency isolation mechanism to isolate and track the abnormal transmission data;

[0130] Among them, the steps of the emergency isolation mechanism are the same as S300 and will not be repeated here.

[0131] It should be noted that when the verification result in S600 is that the data transmission is normal, if the network traffic in the link to be verified exceeds the maximum traffic warning value of the link to be verified (i.e., the greatly increased traffic is caused by the increase in normal business volume, etc.), the monitoring and management platform will start the diversion mechanism (give the key node on the link to be verified a set destination address (i.e., the termination node), and the destination address is a key node that can be directly / indirectly connected to the original destination address). At this time, the transmission data exceeding the preset warning value will first be directed to other key nodes connected to the key node, and then reach the original destination address (i.e., a certain information subsystem) through other communication links; for example, the monitoring and management platform can distribute the traffic to multiple paths according to a certain proportion according to the bandwidth and load of different links to ensure the balanced distribution of network traffic and avoid congestion or performance degradation of a single link due to excessive traffic. At the same time, the monitoring and management platform will continue to track the traffic after diversion to ensure that the diversion effect is as expected, to ensure the stable operation of the network and the smooth data transmission. If the diversion effect is not satisfied, the backup transmission path can also be adjusted in real time. Among them, when the starting node, the ending node and the network diagram composed of key nodes are all determined, calculating the best transmission path according to the starting node and the ending node is a prior art and will not be repeated here.

[0132] It should be noted that each time the emergency isolation mechanism is triggered and one or more corresponding isolation links are obtained, the following steps are also included:

[0133] S1000, taking the two information subsystems at both ends of the communication link that triggers the emergency isolation mechanism as target endpoints, and respectively obtaining the flow data in the network behavior perception machine corresponding to the two target endpoints to obtain the first flow and the second flow;

[0134] Among them, the flow data refers to the total size of the data packets passing through the network behavior perception machine (the sum of the sizes of all data packets), the first flow corresponds to the information subsystem as the starting node, and the second flow corresponds to the information subsystem as the ending node.

[0135] S2000, obtaining an isolation evaluation according to the first flow rate and the second flow rate;

[0136] Among them, isolation evaluation includes complete isolation, partial isolation and isolation failure; specifically, S2000 includes:

[0137] S2100, if the second flow rate drops to zero, the isolation is evaluated as complete isolation;

[0138] S2200, if the second flow rate is less than the first flow rate, and the difference is less than a preset judgment threshold, the isolation evaluation is partial isolation;

[0139] Among them, the second flow is less than the first flow, and the difference is less than the preset judgment threshold, indicating that the abnormal transmission data flowing to the information subsystem serving as the termination node has been greatly reduced, but a small amount still remains, which means that the emergency isolation mechanism has played a certain role, but some network connections have not been completely cut off or there is abnormal transmission data that bypasses the isolation mechanism; the judgment threshold is taken as 70% of the first flow as an example.

[0140] S2300: If the second flow is less than the first flow, and the difference is greater than or equal to the judgment threshold, the isolation evaluation is isolation failure, and an alarm is triggered.

[0141] Among them, the second flow is less than the first flow, and the difference is greater than or equal to the judgment threshold, indicating that the emergency isolation mechanism fails to effectively prevent the communication between the two information subsystems. At this time, it is necessary to issue an alarm to the technical staff to further check the settings of key nodes in the emergency isolation mechanism, the network topology structure, or whether there are other unknown communication paths.

[0142] Based on the same inventive concept mentioned above, an embodiment of the present application also discloses a monitoring and management platform, which includes a memory and a processor, wherein the memory stores at least one instruction, at least one program, code set or instruction set, and the at least one instruction, at least one program, code set or instruction set is loaded and executed by the processor to implement a network behavior security monitoring method provided in the above method embodiment.

[0143] Based on the same inventive concept mentioned above, an embodiment of the present application also discloses a computer-readable storage medium, which stores at least one instruction, at least one program, code set or instruction set. The at least one instruction, at least one program, code set or instruction set can be loaded and executed by a processor to implement a network behavior security monitoring method provided in the above method embodiment.

[0144] It should be understood that the "plurality" mentioned in this article refers to two or more. "And / or" describes the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. The character " / " generally indicates that the associated objects are in an "or" relationship.

[0145] Those skilled in the art will appreciate that all or part of the steps to implement the above embodiments may be accomplished by hardware or by instructing related hardware through a program, and the program may be stored in a computer-readable storage medium. The storage medium mentioned above may include, for example, various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0146] The above description is only an optional embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application shall be included in the protection scope of the present application.

Claims

1. A network behavior security monitoring method, based on a network behavior security monitoring system, wherein the network behavior security monitoring system is adapted to a medical information system including a plurality of information subsystems, each of which corresponds to a different type of medical equipment, and the information subsystem is used to receive and store the corresponding transmission data collected and sent by all the medical equipment, characterized in that: The network behavior security monitoring method comprises: After detecting the data transmission signal, periodically collect the network traffic information in the current communication link; A preliminary transmission security judgment is performed on the data transmission according to the preset abnormal judgment rules and the network traffic information to obtain a first detection result, wherein the first detection result includes that the data transmission is unsafe, the data transmission is normal, and the data transmission has an abnormal risk, and the abnormal judgment rules include a primary abnormal rule and a secondary abnormal rule, wherein the primary abnormal rule includes the following judgment elements: a maximum traffic warning value, an allowed traffic transmission direction, and a limited data packet format, and the primary abnormal rule is used to judge whether the transmission data is caused by an obvious network attack and intrusion; the secondary abnormal rule includes the following judgment elements: a specified network protocol, a rate of increase of traffic, and a data packet size, and the secondary abnormal rule is used to judge whether the transmission data is different from a normal data transmission situation; When the first detection result is that the data transmission is unsafe, triggering an emergency isolation mechanism to isolate and track the abnormal transmission data; When the first detection result is that there is an abnormal risk in data transmission, the communication link corresponding to the first detection result is used as a link to be verified, and multiple network flow information in the link to be verified within a preset verification time is obtained to obtain a network flow information set, wherein the network flow information set includes the multiple network flow information obtained; Obtaining the actual total flow of the transmission data within a preset verification time according to the network flow information set; Obtain a historical traffic data set of the link to be verified and a historical process log of the two information subsystems corresponding to the link to be verified, and perform correlation analysis and verification on the transmission data according to the historical traffic data set, the actual total traffic and the historical process log to obtain a verification result, wherein the verification result includes that the data transmission is not safe, the historical process log includes all process operations occurring between the two information subsystems within a certain period of time, and is used to reflect the mutual communication between the corresponding two information subsystems within a certain period of time; the historical traffic data set includes fluctuations in the traffic size of the transmission data corresponding to each process operation in the historical process log, and is used to reflect the network traffic situation of the link to be verified corresponding to each process operation under normal circumstances; When the verification result is that the data transmission is unsafe, triggering the emergency isolation mechanism to isolate and track the abnormal transmission data; The performing of a preliminary transmission security judgment on the data transmission according to the preset abnormality judgment rule and the network traffic information to obtain the first detection result specifically includes: If all the transmission data in the network traffic information does not comply with the first-level abnormality rule and the second-level abnormality rule, the first detection result is that the data transmission is normal; If any transmission data that meets the first-level abnormality rule exists in the network traffic information, the first detection result is that the data transmission is unsafe; If there is no transmission data that meets the first-level abnormality rule and there is any transmission data that meets the second abnormality rule in the network traffic information, the first detection result is that there is an abnormal risk in the data transmission; The triggering of the emergency isolation mechanism to isolate and track the abnormal transmission data specifically includes: The communication link corresponding to the first detection result that the data transmission is unsafe is used as the first link, and the key node preset in the first link is used as a stage node, wherein the key node is a virtual network node in the communication link, which is set between every two communication-connected information subsystems and each of the key nodes is connected to other key nodes; Determine an isolation link according to a current stage node and the first link, wherein the isolation link is a closed communication link composed of the stage node and the other key nodes; When the abnormal transmission data is cyclically transmitted in the isolation link, acquiring abnormal data features corresponding to the abnormal transmission data; Compare and match the abnormal data features in a preset abnormal type library to obtain a suspected abnormal type; Determining the isolation link according to the current stage node and the first link specifically includes: Selecting one of the starting node and the ending node of the first link as the phase endpoint of this round; A second link of this round is obtained according to the phase endpoint of this round, wherein the second link refers to another communication link that can be connected to the communication link where the phase endpoint is located, and the phase endpoint is on the second link; Determine whether there are other communication links at the starting node or the ending node of the second link in this round; If the judgment result is no, then exclude the second link of this round and repeat the step of obtaining a second link of this round according to the phase endpoint of this round until a second link of this round that meets the condition is obtained; If the judgment result is yes, the key node in the second link of the current round is used as the stage node of the next round, and one of the start node and the end node of the second link is selected as the stage endpoint of the next round; Repeat multiple rounds of operations until all the phase nodes meet the isolation condition, then terminate the operation, and obtain an isolation link based on all the phase nodes, wherein the communication link between every two phase nodes in the isolation link is an isolation sub-link; After the step of obtaining the isolation link according to all the stage nodes, the method further includes: When the abnormally surged flow of the transmission data is greater than the carrying capacity of the isolation link, all the current isolation sub-links are excluded, and the step of determining the isolation link according to the current one of the phase nodes and the first link is repeated according to the remaining communication links until another isolation link is obtained; The verification result obtained by performing correlation analysis on the transmission data according to the historical traffic data set, the actual total traffic and the historical process log includes: Identify, according to the historical traffic data set, the standard traffic conditions corresponding to the link to be verified and each of the process operations under normal circumstances, wherein the standard traffic conditions include the average traffic size and average duration generated on the link to be verified when the corresponding process operation is executed; Obtain the current process log within the verification time, and determine the current ideal total flow of the transmission data according to the current process log and the standard flow situation, wherein the ideal total flow is the sum of the flow of the transmission data generated on the link to be verified when all the process operations within the verification time are executed; Obtaining a deviation value according to the actual total flow and the ideal total flow, wherein the deviation value is the difference between the actual total flow and the ideal total flow; Comparing the deviation value with a preset difference threshold; When the deviation value exceeds the difference threshold, the verification result is determined to be that the data transmission is unsafe; otherwise, the verification result is determined to be that the data transmission is normal.

2. A monitoring management platform, characterized in that: It includes a memory and a processor, wherein the memory stores at least one instruction, at least one program, code set or instruction set, and the at least one instruction, at least one program, code set or instruction set is loaded and executed by the processor to implement the network behavior security monitoring method as described in claim 1.

3. A network behavior safety monitoring system, using a monitoring management platform as claimed in claim 2, wherein the network behavior safety monitoring system is adapted to a medical information system including a plurality of information subsystems, and each of the information subsystems corresponds to a different type of medical equipment, characterized in that: include: A plurality of network behavior sensing machines are provided and correspond to each of the information subsystems one by one, and are used to collect network traffic information of the corresponding information subsystem when receiving transmission data and sending transmission data; The monitoring and management platform is communicatively connected with all network behavior perception machines, and is used to monitor and manage the communication transmission between information subsystems based on the network traffic information.

4. A computer-readable storage medium, characterized in that: The readable storage medium stores at least one instruction, at least one program, code set or instruction set, and the at least one instruction, at least one program, code set or instruction set is loaded and executed by the processor to implement the network behavior security monitoring method as described in claim 1.

Citation Information

Patent Citations

  • Network security intelligent supervision and management method and system

    CN117834299A

  • Network security monitoring method and system based on log management

    CN118509200A