A method for secure isolation of the internal network of a hospital based on an all-optical network architecture
Through the combination of all-optical network slicing technology and intelligent self-healing mechanism, the problem of insufficient bandwidth and security in the hospital network is solved, efficient traffic management and real-time abnormal detection are achieved, and the stability and security of the hospital network are ensured.
Patent Information
- Application Number
- CN202411794494.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-09
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2044-12-09
AI Technical Summary
The existing hospital network architecture has shortcomings in bandwidth requirements, traffic management and security, and it is difficult to meet the needs of high-definition images, real-time monitoring, etc., and traditional security protection methods cannot effectively identify abnormal behaviors and potential threats in the internal network, and lack automated and intelligent abnormal detection and isolation mechanisms.
All-optical network slicing technology, optical time domain multiplexing technology, wavelength selective switching technology and intelligent self-healing mechanism are adopted, combined with decision tree integration algorithm, graph neural network and isolated forest algorithm, to achieve safe isolation, traffic prediction and abnormal detection of the internal network of the hospital.
It realizes dynamic bandwidth allocation according to different departments and business needs, improves network stability and security, has efficient traffic management, real-time abnormal isolation and network self-healing capabilities, and significantly improves the operational efficiency and security of the hospital network.
Smart Images

Figure CN119628926B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security, and particularly to a method for isolating the internal network security of a hospital based on an all-optical network architecture. Background Art
[0002] With the rapid development of information technology, especially in the healthcare industry, the security and stability of the network have increasingly become an important issue. As a public service unit, the internal network of a hospital carries a large amount of medical data and business information. These data not only involve the personal privacy and medical records of patients, but also include important information such as the hospital's operation data and equipment monitoring data. Therefore, the security of the hospital network is directly related to the quality of medical services, the protection of patients' privacy, and the daily operation of the hospital.
[0003] The existing hospital network architectures generally adopt network structures based on traditional Ethernet and IP technologies. Although this architecture meets the basic needs of the hospital network to a certain extent, with the continuous development of medical informatization, especially the digitization and intelligence of medical devices, the traditional network architecture gradually exposes many deficiencies. For example, the bandwidth requirements of the internal network of a hospital have increased sharply. Especially with the increase in the transmission requirements of high-definition images and real-time monitoring data, the existing network architecture faces problems such as insufficient bandwidth and traffic congestion. In addition, the data transmission requirements vary greatly among multiple departments and sections within the hospital. The traditional network management methods fail to fully consider the traffic isolation and resource allocation between different business areas and sections, resulting in the inability to timely guarantee the network bandwidth of some sections and affecting the transmission and use of medical data.
[0004] In addition, with the continuous evolution of network attack methods, the security problems of the internal network of a hospital have become more prominent. The traditional network security protection methods based on firewalls, intrusion detection systems, etc. mainly focus on perimeter defense and traffic detection, and it is difficult to effectively identify abnormal behaviors and potential security threats in the internal network. In the internal network of a hospital, especially when data flows between multiple sections and departments, threats such as malware, viruses, and network attacks may spread through the internal network, and the traditional security protection systems often cannot respond quickly, resulting in the inability to timely detect and isolate security vulnerabilities. The existing technologies fail to effectively monitor the network traffic in the virtualized environment in real time, predict traffic, optimize resources, and isolate abnormal traffic, and there are deficiencies in the protection ability of the internal network of a hospital and the inability to respond to emergencies in real time.
[0005] To address the above problems, some emerging technologies have been applied to hospital networks in recent years. For example, Software-Defined Network (SDN) technology can dynamically adjust network resources and monitor and manage network traffic in real time. However, existing SDN control platforms still have certain limitations in traffic management and bandwidth allocation, especially when facing a large number of dynamic traffic demands, they cannot achieve precise resource allocation and dynamic optimization. In addition, traditional network slicing technology is mainly applied to the network architecture of telecom operators, and its application in hospital internal networks has not been popularized. As an emerging network architecture, all-optical network slicing technology can provide a flexible and efficient resource management method for hospital internal networks through virtualization and dynamic bandwidth allocation. However, this advanced optical network technology has not been widely adopted in hospital networks, resulting in significant deficiencies in the resource utilization efficiency and bandwidth management of existing technologies.
[0006] In terms of hospital network security isolation, although certain progress has been made based on technologies such as intrusion detection and traffic analysis, the detection technology for traffic anomalies and security threats in virtual optical slices is still relatively weak. Existing technologies mostly rely on traditional traffic monitoring and manual intervention, lacking automated and intelligent anomaly detection and isolation mechanisms. Traffic anomaly detection mostly depends on the setting of specific rules and cannot flexibly adjust detection strategies according to different network environments and traffic patterns, resulting in poor recognition ability of abnormal behaviors. Especially in high-traffic and complex network environments, it is difficult to identify potential security threats in a timely and accurate manner.
[0007] On the other hand, although artificial intelligence technologies such as decision tree ensemble algorithms, graph neural networks, and isolation forest algorithms have achieved certain applications in traffic prediction and anomaly detection, they are mostly applied to single algorithms or models and lack multi-level and multi-angle comprehensive analysis and optimization. For example, graph neural networks can effectively model spatio-temporal relationships when dealing with complex network traffic, but their computational complexity is relatively high, and they need to be carefully tuned according to the specific network environment in practical applications, resulting in challenges in their application in hospital networks.
[0008] Existing technologies also lack an efficient and comprehensive method for hospital internal network security isolation that can utilize the advantages of the all-optical network architecture for dynamic bandwidth allocation and traffic isolation, and combine advanced artificial intelligence algorithms, blockchain technology, and intelligent self-healing mechanisms to achieve real-time monitoring, traffic prediction, anomaly detection, and isolation of network traffic. Network isolation in existing technologies mostly relies on traditional security protection devices and manual configuration, lacking intelligent and adaptive processing mechanisms. Facing the complex network requirements and high-concurrency traffic in hospital internal networks, existing methods cannot provide sufficient flexibility and scalability, resulting in uneven distribution of network resources and the emergence of security vulnerabilities, affecting the stability and security of hospital networks.
[0009] Therefore, how to provide a method for secure isolation of the internal network of a hospital based on an all-optical network architecture is an urgent problem to be solved by those skilled in the art. Summary of the Invention
[0010] An object of the present invention is to propose a method for secure isolation of the internal network of a hospital based on an all-optical network architecture. The present invention makes full use of all-optical network slicing, optical time-division multiplexing technology, wavelength selective switching technology and intelligent self-healing mechanism, and combines decision tree ensemble algorithm, graph neural network and isolation forest algorithm to achieve secure isolation, traffic prediction and anomaly detection of the internal network of the hospital. This method can dynamically adjust the bandwidth and resources according to different departments and business requirements, ensure the security, reliability and flexibility of the network, and has efficient traffic management, real-time anomaly isolation and network self-healing capabilities, significantly improving the operation efficiency and security of the hospital network.
[0011] A method for secure isolation of the internal network of a hospital based on an all-optical network architecture according to an embodiment of the present invention includes the following steps:
[0012] S1. Based on all-optical network slicing technology, divide the internal network of the hospital into multiple virtual optical slices, and the virtual optical slices dynamically allocate bandwidth and resources according to different departments and business requirements;
[0013] S2. Use optical time-division multiplexing technology to perform time-domain isolation on the data streams in different virtual optical slices, and use wavelength selective switching technology to transmit different data streams on different optical wavelengths;
[0014] S3. Real-time monitor and manage the bandwidth allocation of virtual optical slices through a software-defined network control platform, and dynamically adjust the optical path resources according to the traffic requirements of each business area within the hospital;
[0015] S4. Based on the decision tree ensemble algorithm, perform traffic prediction and resource optimization, model the historical data to predict the traffic change trend in the future period, and optimize the allocation of network resources according to the prediction results;
[0016] S5. Use graph neural network to analyze the spatio-temporal relationship of network traffic, identify potential traffic anomalies and security threats, and detect and isolate abnormal traffic in real time;
[0017] S6. Detect the abnormal behavior of virtual optical slices in the hospital network through the isolation forest algorithm, identify the boundary between normal and abnormal traffic, and use dynamic threshold technology to mark and isolate abnormal traffic;
[0018] S7. Record the transmission logs of all network traffic through blockchain technology and perform non-tamperable auditing;
[0019] S8. When a network failure occurs, the intelligent self-healing mechanism automatically selects redundant optical path resources for switching, and the software-defined network controller is used to achieve optical path restoration.
[0020] Optionally, the S2 specifically includes:
[0021] S21. Using optical time-division multiplexing technology, the data stream is divided into different time periods in each virtual optical slice, and the transmission data of each virtual optical slice is carried out within the specified time period:
[0022] T i =[t1,t2,...,t n ;
[0023] Among them, T i represents the transmission time period of the i-th virtual optical slice, and n represents the number of virtual optical slice data transmission time periods;
[0024] S22. According to the needs of each virtual optical slice, the wavelength selective switch technology is used to allocate different data streams to different optical wavelengths for transmission;
[0025] S23. According to the traffic demand of the network, appropriate time slots are allocated to each virtual optical slice to ensure that each virtual optical slice performs data transmission within the specified time period and avoid time slot overlap;
[0026] S24. According to the traffic prediction model, dynamically adjust the time slot length of each virtual optical slice:
[0027] L i =f(Load forecast ), where
[0028] Among them, L i represents the dynamic time slot resource of the i-th virtual optical slice, Load forecast represents the predicted traffic load, Load k represents the traffic load of the k-th virtual optical slice, f(Load forecast ) represents the time slot adjustment function output by the traffic prediction model, and m represents the number of virtual optical slices;
[0029] S25. According to the bandwidth requirements of each virtual optical slice, dynamically adjust the wavelength allocation in the wavelength selective switch technology;
[0030] S26. Using the wavelength selective switch technology, dynamically adjust the wavelength allocation during high traffic periods, and the high-priority virtual optical slices obtain more optical wavelength resources.
[0031] Optionally, the S3 specifically includes:
[0032] S31. Real - time monitor each virtual optical slice in the hospital's internal network through the software - defined network control platform, and collect the bandwidth usage, traffic load, and change trend of data traffic of each virtual optical slice; the software - defined network control platform regularly evaluates the data traffic of each virtual optical slice to determine whether bandwidth allocation needs to be adjusted;
[0033] S32. Through the software - defined network control platform, based on the real - time monitoring data, judge the traffic requirements of virtual optical slices in each service area, and dynamically adjust the bandwidth quotas of each virtual optical slice;
[0034] S33. Combining the hospital's network traffic requirements and priorities, the software - defined network control platform allocates resources to virtual optical slices according to the priority policy; for emergency medical data and monitoring data with high - priority traffic, automatically allocate bandwidth and optical path resources preferentially;
[0035] S34. According to the traffic requirements of each service area within the hospital, the software - defined network control platform calculates in real - time the required bandwidth and resources for each service area, and dynamically adjusts the allocation of optical path resources according to the actual operation situation of the hospital;
[0036] S35. During periods of low network load, the software - defined network control platform automatically releases unnecessary bandwidth resources and re - allocates the bandwidth resources to virtual optical slices with higher load.
[0037] Optionally, the specific steps of S4 include:
[0038] S41. Collect historical data of each department within the hospital, including bandwidth usage, traffic load, latency, and data transmission volume in different time periods. By long - term monitoring the traffic characteristics of the hospital network, use the collected historical data as training samples for the decision - tree ensemble algorithm;
[0039] S42. Use the decision - tree ensemble algorithm to model the collected historical data. By analyzing the traffic patterns in different service areas, divide the input historical data into multiple nodes for decision - making to form multiple leaf nodes;
[0040] S43. Based on the historical - data modeling, predict the traffic requirements for future time periods. The output value generated by the decision - tree ensemble algorithm provides a basis for the traffic allocation of each department and service area within the hospital:
[0041]
[0042] where \(R(t)\) represents the predicted traffic requirement at time \(t\), \(w\) i represents the weight of the \(i\) - th feature, \(x\) i (t) represents the value of the \(i\) - th feature at time \(t\), and \(N\) represents the number of features;
[0043] S44. Dynamically adjust the bandwidth resources of virtual optical slices in the hospital network according to the prediction results, allocate more bandwidth to high-traffic service areas and less bandwidth to low-traffic departments according to the traffic prediction results:
[0044]
[0045] Among them, B i (t) represents the bandwidth allocated to the kth service area at time t, and R k (t) represents the traffic demand of the kth service area, and B total represents the total bandwidth, M represents the number of service areas, and R j (t) represents the traffic demand of the jth service area;
[0046] S45. Monitor the deviation between the actual network traffic and the prediction results, compare the error between the actual traffic and the predicted traffic, and adjust and optimize the parameters of the decision tree;
[0047] S46. Adjust the bandwidth resources of the virtual optical slices according to the optimized traffic prediction results.
[0048] Optionally, the S5 specifically includes:
[0049] S51. Collect real-time data of the internal network traffic of the hospital to form a basic data set of network traffic;
[0050] S52. Build a graph neural network model based on the basic data set of network traffic, use the departments and service areas in the hospital network as nodes, and establish traffic association relationships; each node represents a department or a service area, and the edges between nodes represent the traffic transmission paths between different departments or service areas;
[0051] S53. Input the basic data set of network traffic as the features of nodes and edges into the graph neural network for spatio-temporal relationship modeling, and adopt a combination of multi-layer perceptron and graph convolutional network to calculate the high-order relationships between nodes;
[0052] S54. Perform traffic prediction through the graph neural network model to obtain the traffic trends between departments and service areas in the hospital network, and adopt multi-scale graph convolutional layers to enhance the learning ability of the graph neural network model:
[0053]
[0054] Among them, represents the hidden state of node v at the k+1 layer, σ represents the activation function, represents the hidden state of node u at the k layer, represents the hidden state of node v at the k layer, and N(v) represents the neighbor nodes of node v, Auv represents the weight of the edge between node u and node v, D v represents the degree matrix of node v, D u represents the degree matrix of node u, and α represents the adjustment factor, represents additional learning of node features;
[0055] S55. Calculate the predicted value of the traffic through the graph neural network, and combine the historical traffic data for traffic anomaly detection:
[0056]
[0057] Among them, ΔR i (t) represents the traffic deviation of the i-th department or business area at time t, represents the actual traffic of the i-th department or business area at time t, represents the predicted traffic value of the i-th department or business area at time t;
[0058] S56. When it is recognized that the traffic deviation value ΔR i (t) exceeds the preset threshold, it is determined that there is traffic anomaly, and the boundary judgment of the abnormal traffic adopts the adaptive threshold method to automatically adjust the threshold according to the current network state;
[0059] S57. When the traffic anomaly is detected, isolate the abnormal traffic through the software-defined network control platform. The isolation process includes dynamically adjusting the network routing and directing the abnormal traffic to the monitoring slice for processing.
[0060] Optionally, the specific content of S6 includes:
[0061] S61. Collect the traffic data of each virtual optical slice in the hospital internal network. The traffic data is collected and stored in real time by the network monitoring system to form a complete traffic feature data set;
[0062] S62. Perform anomaly detection on the traffic feature data based on the isolation forest algorithm. By constructing multiple decision trees and recursively splitting the data in the trees, identify the abnormal data points; the anomaly score of each data point reflects the degree of anomaly of the data point relative to other data points;
[0063] S63. Through the tree splitting mechanism in the isolation forest algorithm, perform anomaly measurement on the data points of each virtual optical slice. Randomly split the traffic data through multiple decision trees. The more times of splitting, the higher the anomaly score of the data point, indicating that the data point is more likely to be abnormal traffic:
[0064]
[0065] Among them, S anomaly(t) represents the traffic anomaly score at time t, D represents the total number of trees, 1(T i (t) > θ i ) represents the indicator function. When the anomaly score T i (t) of the i-th tree is greater than the threshold θ i it is 1, otherwise it is 0;
[0066] S64. According to the calculated traffic anomaly score S anomaly (t), the dynamic threshold technology is used to judge whether there is abnormal traffic, and based on the statistical characteristics of historical traffic data, the optimal anomaly detection threshold at the current moment is calculated in real time;
[0067] S65. When the traffic score of a certain virtual optical slice exceeds the set anomaly score threshold, the traffic of the virtual optical slice is considered abnormal traffic and enters the isolation process:
[0068]
[0069] Among them, represents the traffic value after isolation, represents the actual traffic of the i-th department or business area at time t, θ threshold represents the set anomaly score threshold;
[0070] S66. After the traffic is marked as abnormal, the software-defined network control platform separates the abnormal traffic from the normal traffic for isolation and blocking. The isolated abnormal traffic no longer participates in network transmission until the abnormal state is lifted.
[0071] Optionally, the intelligent self-healing mechanism includes: real-time monitoring of the optical path resource status in the hospital network, detecting network faults or performance degradation; when a fault occurs, automatically scheduling redundant optical path resources for automatic switching; after the fault is recovered, recording the event and performing log auditing.
[0072] The beneficial effects of the present invention are:
[0073] First of all, the present invention uses the all-optical network slicing technology to divide the hospital network into multiple virtual optical slices, enabling reasonable and dynamic bandwidth allocation for the network traffic of different departments and business areas, thus effectively avoiding the bandwidth bottleneck problem caused by uneven resource allocation in the traditional network architecture. Each virtual optical slice can dynamically adjust the bandwidth and resources according to actual needs, so that different business requirements within the hospital can be fully met, thereby ensuring the real-time transmission of medical data and the smooth development of medical services.
[0074] Secondly, the present invention effectively isolates data streams in different virtual optical slices through optical time-division multiplexing technology and wavelength selective switch technology. Data transmission between different service areas does not interfere with each other, reducing the risk of network congestion and resource conflicts. This refined resource management method not only improves the stability of the hospital network but also enhances the network scalability, enabling the hospital network to operate efficiently in the face of increasing traffic demands.
[0075] In addition, the present invention monitors and manages virtual optical slices in real time through a software-defined network (SDN) control platform, which can dynamically adjust network resources according to traffic changes and demand changes. The SDN platform can monitor the traffic and bandwidth usage of each virtual optical slice in real time and flexibly adjust network routing and resource allocation based on real-time data. This dynamic resource scheduling method based on real-time data analysis and traffic prediction can efficiently respond to network traffic fluctuations, ensure the priority guarantee of critical tasks, and avoid service interruptions or performance degradation caused by network congestion or resource shortages.
[0076] In terms of security, the present invention introduces advanced artificial intelligence technologies such as decision tree ensemble algorithms, graph neural networks, and isolation forest algorithms for traffic prediction and detection of abnormal traffic. These algorithms can accurately predict the future traffic change trend and timely detect potential network security threats. Through the modeling and analysis of traffic feature data, abnormal traffic can be effectively identified, and abnormal traffic can be marked and isolated in real time through dynamic threshold technology to prevent malicious traffic from invading the hospital network. Compared with traditional static firewalls or intrusion detection systems, AI-based traffic prediction and anomaly detection have higher flexibility and accuracy, and can take isolation measures in a timely manner when network anomalies occur, reducing potential security risks.
[0077] The present invention also uses blockchain technology to record the transmission logs of all network traffic, providing an immutable audit mechanism. By recording and tracking the whole process of network traffic through blockchain technology, the transparency and traceability of data transmission are ensured, providing a strong guarantee for the security management of the hospital network.
[0078] Finally, when a network failure occurs, the intelligent self-healing mechanism of the present invention can automatically detect the network failure and select redundant optical path resources for rapid switching, ensuring the continuous availability of the network. After the failure is recovered, the system can record the event and conduct log auditing, providing detailed fault information for the hospital network administrators, which is convenient for subsequent analysis and optimization. This self-healing mechanism improves the reliability of the hospital network, reduces the service interruption time caused by network failures, and ensures the continuity and stability of medical services. Brief Description of the Drawings
[0079] The accompanying drawings are used to provide a further understanding of the present invention, and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention, and do not constitute a limitation to the present invention. In the accompanying drawings:
[0080] Figure 1 is the overall flowchart of a method for hospital internal network security isolation based on an all-optical network architecture proposed by the present invention;
[0081] Figure 2 is a schematic diagram of the application of optical time-division multiplexing technology and wavelength selective switch technology in a method for hospital internal network security isolation based on an all-optical network architecture proposed by the present invention. Detailed implementation manners
[0082] Now, the present invention will be further described in detail with reference to the accompanying drawings. These drawings are all simplified schematic diagrams, only illustrating the basic structure of the present invention in a schematic manner, so they only show the components related to the present invention.
[0083] Refer to Figure 1 and Figure 2 , a method for hospital internal network security isolation based on an all-optical network architecture, includes the following steps:
[0084] S1. Based on the all-optical network slicing technology, divide the hospital internal network into multiple virtual optical slices, and the virtual optical slices dynamically allocate bandwidth and resources according to different departments and service requirements;
[0085] S2. Use optical time-division multiplexing technology to perform time-domain isolation on the data streams in different virtual optical slices, and use wavelength selective switch technology to transmit different data streams on different optical wavelengths;
[0086] S3. Through the software-defined network control platform, monitor and manage the bandwidth allocation of virtual optical slices in real time, and dynamically adjust the optical path resources according to the traffic requirements of each business area within the hospital;
[0087] S4. Based on the decision tree ensemble algorithm, perform traffic prediction and resource optimization, model the historical data to predict the traffic change trend in the future period, and optimize the allocation of network resources according to the prediction results;
[0088] S5. Use graph neural networks to analyze the spatio-temporal relationship of network traffic, identify potential traffic anomalies and security threats, and detect and isolate abnormal traffic in real time;
[0089] S6. Detect the abnormal behaviors of virtual optical slices in the hospital network through the isolation forest algorithm, identify the boundary between normal and abnormal traffic, and use dynamic threshold technology to mark and isolate abnormal traffic;
[0090] S7. Record the transmission logs of all network traffic through blockchain technology and conduct tamper-proof audits;
[0091] S8. When a network failure occurs, automatically select redundant optical path resources for switching through the intelligent self-healing mechanism, and use the software-defined network controller to achieve optical path restoration.
[0092] In this embodiment, the S2 specifically includes:
[0093] S21. Using optical time-division multiplexing technology, divide the data stream into different time periods in each virtual optical slice according to time, and the transmission data of each virtual optical slice is carried out within the specified time period:
[0094] T i =[t1,t2,...,t n ;
[0095] Among them, T i represents the transmission time period of the i-th virtual optical slice, and n represents the number of virtual optical slice data transmission time periods;
[0096] S22. According to the needs of each virtual optical slice, use wavelength selective switching technology to allocate different data streams to different optical wavelengths for transmission;
[0097] S23. According to the traffic demand of the network, allocate appropriate time slots for each virtual optical slice to ensure that each virtual optical slice conducts data transmission within the specified time period and avoid time slot overlap;
[0098] S24. According to the traffic prediction model, dynamically adjust the time slot length of each virtual optical slice:
[0099] L i =f(Load forecast ), where
[0100] Among them, L i represents the dynamic time slot resource of the i-th virtual optical slice, Load forecast represents the predicted traffic load, Load k represents the traffic load of the k-th virtual optical slice, f(Load forecast ) represents the time slot adjustment function output by the traffic prediction model, and m represents the number of virtual optical slices;
[0101] S25. Dynamically adjust the wavelength allocation in the wavelength selective switching technology according to the bandwidth requirements of each virtual optical slice;
[0102] S26. Using wavelength selective switching technology, dynamically adjust the wavelength allocation during high traffic periods, and the high-priority virtual optical slices obtain more optical wavelength resources.
[0103] In this embodiment, S3 specifically includes:
[0104] S31. Real-time monitor each virtual optical slice in the hospital internal network through the software-defined network control platform, and collect the bandwidth usage, traffic load, and change trend of data traffic of each virtual optical slice; the software-defined network control platform regularly evaluates the data traffic of each virtual optical slice to determine whether bandwidth allocation needs to be adjusted;
[0105] S32. Through the software-defined network control platform, judge the traffic demand of virtual optical slices in each service area according to the real-time monitoring data, and dynamically adjust the bandwidth quota of each virtual optical slice;
[0106] S33. Combining the network traffic demand and priority of the hospital, the software-defined network control platform allocates resources to virtual optical slices according to the priority policy; for the emergency medical data and monitoring data with high-priority traffic, automatically allocate bandwidth and optical path resources preferentially;
[0107] S34. According to the traffic demand of each service area inside the hospital, the software-defined network control platform calculates in real time the bandwidth and resources required for each service area, and dynamically adjusts the allocation of optical path resources according to the actual operation situation of the hospital;
[0108] S35. During the period when the network load is low, the software-defined network control platform automatically releases unnecessary bandwidth resources and reallocates the bandwidth resources to the virtual optical slices with higher load.
[0109] In this embodiment, S4 specifically includes:
[0110] S41. Collect the historical data of each department in the hospital, including the bandwidth usage, traffic load, latency, and data transmission volume in different time periods. By long-term monitoring the traffic characteristics of the hospital network, use the collected historical data as the training samples of the decision tree ensemble algorithm;
[0111] S42. Use the decision tree ensemble algorithm to model the collected historical data. By analyzing the traffic patterns in different service areas, divide the input historical data into multiple nodes for decision-making to form multiple leaf nodes;
[0112] S43. Predict the traffic demand in the future period based on the historical data modeling. The output value generated by the decision tree ensemble algorithm provides a basis for the traffic allocation of each department and service area inside the hospital:
[0113]
[0114] wherein, R(t) represents the predicted traffic demand at time t, w idenotes the weight of the i-th feature, x i (t) represents the i-th feature value at time t, and N represents the number of features;
[0115] S44. Dynamically adjust the bandwidth resources of virtual optical slices in the hospital network according to the prediction results, allocate more bandwidth to high-traffic service areas and less bandwidth to low-traffic departments according to the traffic prediction results:
[0116]
[0117] Among them, B i (t) represents the bandwidth allocated to the k-th service area at time t, and R k (t) represents the traffic demand of the k-th service area, and B total represents the total bandwidth, M represents the number of service areas, and R j (t) represents the traffic demand of the j-th service area;
[0118] S45. Monitor the deviation between the actual network traffic and the prediction results, compare the error between the actual traffic and the predicted traffic, and adjust and optimize the parameters of the decision tree;
[0119] S46. Adjust the bandwidth resources of the virtual optical slices according to the optimized traffic prediction results.
[0120] In this embodiment, the specific steps of S5 are as follows:
[0121] S51. Collect real-time data of the internal network traffic of the hospital to form a basic data set of network traffic;
[0122] S52. Build a graph neural network model based on the basic data set of network traffic, use the departments and service areas in the hospital network as nodes, and establish traffic association relationships; each node represents a department or a service area, and the edges between nodes represent the traffic transmission paths between different departments or service areas;
[0123] S53. Input the basic data set of network traffic as the features of nodes and edges into the graph neural network for spatio-temporal relationship modeling, and adopt a combination of a multi-layer perceptron and a graph convolutional network to calculate the high-order relationships between nodes;
[0124] S54. Perform traffic prediction through the graph neural network model to obtain the traffic trends between departments and service areas in the hospital network, and adopt multi-scale graph convolutional layers to enhance the learning ability of the graph neural network model:
[0125]
[0126] Among them, represents the hidden state of node v at the k+1 layer, and σ represents the activation function, represents the hidden state of node u at the k-th layer, represents the hidden state of node v at the k-th layer, and N(v) represents the neighbor nodes of node v, A uv represents the weight of the edge between node u and node v, D v represents the degree matrix of node v, D u represents the degree matrix of node u, and α represents the adjustment factor, represents additional learning of node features;
[0127] S55. Calculate the predicted value of the traffic through the graph neural network, and combine the historical traffic data for traffic anomaly detection:
[0128]
[0129] where, ΔR i (t) represents the traffic deviation of the i-th department or business area at time t, represents the actual traffic of the i-th department or business area at time t, represents the predicted traffic value of the i-th department or business area at time t;
[0130] S56. When it is recognized that the traffic deviation value ΔR i (t) exceeds the preset threshold, it is determined that there is traffic anomaly, and the boundary judgment of the abnormal traffic adopts the adaptive threshold method to automatically adjust the threshold according to the current network state;
[0131] S57. When the traffic anomaly is detected, isolate the abnormal traffic through the software-defined network control platform. The isolation process includes dynamically adjusting the network routing and directing the abnormal traffic to the monitoring slice for processing.
[0132] In this embodiment, the specific content of S6 includes:
[0133] S61. Collect the traffic data of each virtual optical slice in the hospital internal network. The traffic data is collected and stored in real time by the network monitoring system to form a complete traffic feature data set;
[0134] S62. Based on the isolation forest algorithm, perform anomaly detection on the traffic feature data. By constructing multiple decision trees and recursively splitting the data in the trees, identify the abnormal data points; the anomaly score of each data point reflects the degree of anomaly of the data point relative to other data points;
[0135] S63. Through the tree splitting mechanism in the isolation forest algorithm, perform anomaly measurement on the data points of each virtual optical slice. Randomly split the traffic data through multiple decision trees. The more times of splitting, the higher the anomaly score of the data point, indicating that the data point is more likely to be abnormal traffic:
[0136]
[0137] Among them, S anomaly (t) represents the traffic anomaly score at time t, D represents the total number of trees, and 1(T i (t)>θ i ) represents the indicator function. When the anomaly score T i (t) of the i-th tree is greater than the threshold θ i , it is 1; otherwise, it is 0.
[0138] S64. According to the calculated traffic anomaly score S anomaly (t), the dynamic threshold technology is used to determine whether there is abnormal traffic, and based on the statistical characteristics of historical traffic data, the optimal anomaly detection threshold at the current moment is calculated in real time;
[0139] S65. When the traffic score of a certain virtual optical slice exceeds the set anomaly score threshold, the traffic of the virtual optical slice is considered abnormal traffic and enters the isolation process:
[0140]
[0141] Among them, represents the traffic value after isolation, represents the actual traffic of the i-th department or business area at time t, and θ threshold represents the set anomaly score threshold;
[0142] S66. After the traffic is marked as abnormal, the software-defined network control platform separates the abnormal traffic from the normal traffic for isolation and blocking. The isolated abnormal traffic no longer participates in network transmission until the abnormal state is lifted.
[0143] In this embodiment, the intelligent self-healing mechanism includes: real-time monitoring of the optical path resource status in the hospital network to detect network faults or performance degradation; when a fault occurs, automatically scheduling redundant optical path resources for automatic switching; after the fault is recovered, recording the event and performing log auditing.
[0144] Example 1:
[0145] To verify the feasibility of the present invention in implementation, the present invention is applied to a large hospital. The hospital is large in scale and covers multiple departments, including the emergency department, intensive care unit, internal medicine department, surgery department, imaging department, and laboratory department, etc. The internal network of the hospital needs to efficiently and flexibly support the network traffic of different departments and business areas and ensure the security and timely transmission of medical data. The network traffic includes the transmission of daily medical data, hospital management systems, remote consultations, and other communication requirements of various applications. The traditional network architecture has problems such as insufficient bandwidth, inability to adjust in real time during traffic bursts, and a greater threat of network attacks to critical medical data.
[0146] To better solve these problems, the hospital has introduced a network security isolation technology based on the all-optical network architecture. This technology can not only dynamically adjust network resources according to the needs of different departments and services, but also monitor network traffic in real time, predict traffic changes, and quickly respond to the isolation and protection of abnormal traffic.
[0147] In the application of this hospital, first through the all-optical network slicing technology, the hospital's internal network is divided into multiple virtual optical slices. Each virtual optical slice dynamically allocates bandwidth according to the network needs of different departments. For example, the emergency department has high requirements for network bandwidth and real-time performance, and will be preferentially allocated more network resources during certain periods (such as the peak emergency period), while the traffic demands of the imaging department and the laboratory department are relatively stable, so less bandwidth is allocated.
[0148] In terms of network traffic isolation, the hospital uses optical time-division multiplexing technology (OTDM) and wavelength selective switch technology (WSS) to perform time-domain isolation on the data streams in different virtual optical slices, and uses wavelength selective switch technology to allocate different data streams to different optical wavelengths for transmission. In this way, even if the traffic of some departments fluctuates greatly, it will not affect other departments, thus ensuring the safe and stable transmission of internal data in the hospital.
[0149] When using the software-defined network control platform to monitor each virtual optical slice in real time, the hospital can always master the usage of network resources and adjust the bandwidth according to business needs. During certain periods, when the bandwidth demand of the emergency department surges, the hospital's control platform will dynamically adjust the optical path resources to give priority to ensuring the network needs of the emergency department. At the same time, the decision tree ensemble algorithm and graph neural network technology can predict the future traffic demand changes of each department in the hospital through the modeling and real-time analysis of historical traffic data, and make bandwidth adjustments in advance to ensure that the hospital network can still operate stably during high-load periods.
[0150] In addition, when abnormal traffic or potential security threats occur in the hospital network, the anomaly detection mechanism based on the isolation forest algorithm can identify abnormal data points, mark and isolate abnormal traffic through dynamic threshold technology, and avoid potential network attacks or malicious data from interfering with the hospital's medical services. After the traffic is isolated, the software-defined network control platform can quickly adjust the network routing to separate normal traffic from abnormal traffic, ensuring that medical data is not interfered.
[0151] Finally, the hospital's network traffic transmission logs are recorded and encrypted stored by blockchain technology to ensure the immutability of the logs, and when a network failure occurs, redundant optical path resources are automatically selected for switching through the intelligent self-healing mechanism to ensure the continuous operation of the hospital network.
[0152] Table 1 Comparison of the Effects of the Hospital Internal Network Security Isolation Method Based on the All-Optical Network Architecture
[0153] Data Index Before Deployment After Deployment Improvement Rate Frequency of Cybersecurity Incidents (times / month) 35 5 Reduced by 85.7% Network Attack Detection Rate (%) 60% 95% Increased by 58.3% Security Incident Isolation Response Time (seconds) 30 5 Reduced by 83.3% False Omission Rate of Cybersecurity Incidents (%) 40% 5% Reduced by 87.5% Network Defense Level (levels) 3 5 Increased by 2 levels Accuracy of Cybersecurity Log Records (%) 70% 100% Increased by 42.9% Impact of Security Incidents on Medical Data (times / month) 10 0 Reduced by 100% Accuracy of Abnormal Traffic Detection (%) 75% 98% Increased by 30.7%
[0154] By analyzing Table 1 above, it can be clearly seen that the hospital internal network security isolation method based on the all-optical network architecture has significantly better effects after implementation than before, especially in aspects such as the monitoring of security incidents, isolation response, and attack detection accuracy.
[0155] First of all, from the perspective of the frequency of network security incidents, the frequency of network security incidents in the hospital network has decreased significantly after implementation, from 35 times per month to 5 times, and the reduction rate has reached 85.7%. This indicates that by adopting the all-optical network architecture and multiple security protection technologies, the frequency of network attacks in the hospital has been effectively controlled. The network isolation technology and dynamic bandwidth allocation means have greatly enhanced the overall security of the network, reducing external attacks and potential internal security risks.
[0156] Secondly, the network attack detection rate has increased significantly, from the original 60% to 95%. This change is mainly due to the introduction of traffic analysis technology based on graph neural networks and the anomaly detection function of the isolation forest algorithm, enabling the hospital's network to more comprehensively monitor and identify network attacks. With the application of these advanced algorithms, the hospital can detect and defend potential network attacks in a timely manner, thereby reducing the probability of network security incidents.
[0157] In terms of the isolation response time of security incidents, the response time has been significantly shortened from 30 seconds to 5 seconds after implementation, and the reduction rate has reached 83.3%. This is particularly important because when a security incident occurs, the rapidity of network isolation directly affects the protection of data and the recovery speed of the system. After adopting the all-optical network architecture and software-defined network (SDN) control platform, the network can respond in real time and automatically switch redundant paths, greatly shortening the isolation response time and ensuring the continuity and security of the hospital network.
[0158] At the same time, the false negative rate of network security incidents has also decreased significantly, from 40% to 5%, and the reduction rate has reached 87.5%. This means that after implementation, the hospital can more accurately detect security threats in the network, avoiding false negative or false positive problems. Through improved security protection measures, the hospital can comprehensively monitor and record every network security incident to ensure that all abnormal activities are processed in a timely manner.
[0159] The improvement of the network defense level is also a major highlight. By introducing more levels of security protection technologies, such as decision tree ensemble algorithms and graph neural networks, the defense level has been increased from 3 layers to 5 layers, enhancing the defense depth and refinement degree of the overall network. This multi-level security defense mechanism can conduct hierarchical management and precise interception of different types of network attacks, improving the network security and protection capabilities.
[0160] In terms of the accuracy of network security logging, the accuracy has increased from 70% to 100% after deployment. This improvement benefits from the application of blockchain technology, which ensures the immutability and accurate recording of security event logs. This not only enhances the hospital's ability to track network security events but also provides reliable evidence and audit records for any future problems.
[0161] It is worth noting that the impact of security events on medical data has achieved a 100% improvement after implementation, and the impact of security events on medical data transmission has been reduced to zero. This is crucial because the integrity and timeliness of medical data are directly related to the health and safety of patients. By adopting network security isolation methods, the hospital not only ensures the security of data transmission but also avoids problems such as the loss or tampering of medical data caused by network attacks.
[0162] Finally, the accuracy of abnormal traffic detection has also been significantly improved, from 75% to 98%, with an increase of 30.7%. This improvement indicates that by applying efficient traffic prediction models and abnormal traffic detection technologies, the hospital can more accurately identify and isolate abnormal traffic, preventing potential network attacks and the intrusion of internal and external threats.
[0163] In summary, from these data, it can be seen that the hospital internal network security isolation method based on the all-optical network architecture has achieved significant improvements in multiple key indicators. From reducing the occurrence of security events, increasing the attack detection rate to reducing the response time and false alarm rate, it fully demonstrates the great advantages of this method in hospital network security management. Especially for the protection of medical data, the method after implementation ensures the stable operation of the hospital network and the integrity of medical data, effectively avoiding problems such as medical data leakage and tampering caused by network attacks, and guaranteeing the normal operation of the hospital and the life safety of patients.
[0164] The above is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution and inventive concept of the present invention, makes equivalent substitutions or changes, and should be covered within the protection scope of the present invention.
Claims
1. A method for secure isolation of the internal network of a hospital based on an all-optical network architecture, characterized in that, It includes the following steps: S1. Based on the all-optical network slicing technology, divide the hospital internal network into multiple virtual optical slices, and dynamically allocate bandwidth and resources for the virtual optical slices according to different departments and service requirements; S2. Use the optical time-division multiplexing technology to isolate the data streams in different virtual optical slices in the time domain, and use the wavelength selective switch technology to transmit different data streams at different optical wavelengths; S3. Through the software-defined network control platform, monitor and manage the bandwidth allocation of virtual optical slices in real time, and dynamically adjust the optical path resources according to the traffic requirements of each business area within the hospital; S4. Based on the decision tree ensemble algorithm, perform traffic prediction and resource optimization, model the historical data to predict the traffic change trend in the future period, and optimize the allocation of network resources according to the prediction results; S5. Use the graph neural network to analyze the spatio-temporal relationship of network traffic, identify potential traffic anomalies and security threats, and detect and isolate abnormal traffic in real time; S6. Detect the abnormal behavior of virtual optical slices in the hospital network through the isolation forest algorithm, identify the boundary between normal and abnormal traffic, and use the dynamic threshold technology to mark and isolate abnormal traffic; S7. Record the transmission logs of all network traffic through the blockchain technology and conduct non-tamperable audits; S8. When a network failure occurs, automatically select redundant optical path resources for switching through the intelligent self-healing mechanism, and use the software-defined network controller to achieve optical path recovery.
2. The method for secure isolation of hospital internal network based on all-optical network architecture according to claim 1, wherein The specific content of S2 includes: S21. Use the optical time-division multiplexing technology to divide the data stream into different time periods in each virtual optical slice, and the transmission data of each virtual optical slice is carried out within the specified time period: T i = [t1, t2,..., t n ; Among them, T i represents the transmission time period of the i-th virtual optical slice, and n represents the number of virtual optical slice data transmission time periods; S22. According to the needs of each virtual optical slice, use the wavelength selective switch technology to allocate different data streams to different optical wavelengths for transmission; S23. According to the traffic requirements of the network, allocate time slots for each virtual optical slice to ensure that each virtual optical slice transmits data within the specified time period and avoid time slot overlap; S24. Dynamically adjust the time slot length of each virtual optical slice according to the traffic prediction model; L i = f(Load forecast ), where Among them, L i represents the dynamic time slot resource of the i-th virtual optical slice, Load forecast represents the predicted traffic load, Load k represents the traffic load of the k-th virtual optical slice, f(Load forecast ) represents the time slot adjustment function output by the traffic prediction model, and m represents the number of virtual optical slices; S25. Dynamically adjust the wavelength allocation in the wavelength selective switch technology according to the bandwidth requirements of each virtual optical slice; S26. Use the wavelength selective switch technology to dynamically adjust the wavelength allocation during high-traffic periods, and the virtual optical slices with high priority obtain more optical wavelength resources.
3. A method for secure isolation of the internal network of a hospital based on an all-optical network architecture according to claim 1, characterized in that, The specific content of S3 includes: S31. Through the software-defined network control platform, monitor each virtual optical slice in the hospital internal network in real time, collect the bandwidth usage, traffic load and the change trend of data traffic of each virtual optical slice; the software-defined network control platform regularly evaluates the data traffic of each virtual optical slice to determine whether the bandwidth allocation needs to be adjusted; S32. Through the software-defined network control platform, judge the traffic requirements of virtual optical slices in each business area according to the real-time monitoring data, and dynamically adjust the bandwidth quota of each virtual optical slice; S33. Combining the network traffic requirements and priorities of the hospital, the software-defined network control platform allocates resources to the virtual optical slices according to the priority policy; for the emergency medical data and monitoring data with high-priority traffic, bandwidth and optical path resources are automatically preferentially allocated. S34. According to the traffic requirements of each business area within the hospital, the software-defined network control platform calculates in real time the bandwidth and resources required for each business area, and dynamically adjusts the allocation of optical path resources based on the actual operation of the hospital. S35. During periods of low network load, the software-defined network control platform automatically releases unnecessary bandwidth resources and reallocates the bandwidth resources to the virtual optical slices with higher load.
4. A method for secure isolation of an internal hospital network based on an all-optical network architecture according to claim 1, characterized in that, The specific steps of S4 are as follows: S41. Collect the historical data of each department within the hospital, including the bandwidth usage, traffic load, latency, and data transmission volume in different time periods. By long-term monitoring of the traffic characteristics of the hospital network, the collected historical data is used as the training samples for the decision tree ensemble algorithm. S42. Use the decision tree ensemble algorithm to model the collected historical data. By analyzing the traffic patterns of different business areas, the input historical data is segmented into multiple nodes for decision-making to form multiple leaf nodes. S43. Based on the historical data modeling, predict the traffic requirements for future time periods. The output value generated by the decision tree ensemble algorithm provides a basis for the traffic allocation of each department and business area within the hospital. Among them, R(t) represents the predicted traffic demand at time t, w i represents the weight of the i-th feature, x i (t) represents the i-th feature value at time t, and N represents the number of features; S44. Dynamically adjust the bandwidth resources of the virtual optical slices in the hospital network according to the prediction results. Allocate more bandwidth to the high-traffic business areas and less bandwidth to the low-traffic business areas according to the traffic prediction results. Among them, B k (t) represents the bandwidth allocated to the k-th service area at time t, and R k (t) represents the traffic demand of the k-th service area, and B total represents the total bandwidth, M represents the number of service areas, and R j (t) represents the traffic demand of the j-th service area; S45. Monitor the deviation between the actual network traffic and the prediction results, compare the error between the actual traffic and the predicted traffic, and adjust and optimize the parameters of the decision tree. S46. Adjust the bandwidth resources of the virtual optical slices according to the optimized traffic prediction results.
5. A method for secure isolation of the internal network of a hospital based on an all-optical network architecture according to claim 1, characterized in that, The specific steps of S5 are as follows: S51. Collect the real-time data of the hospital internal network traffic to form the basic data set of the network traffic. S52. Build a graph neural network model based on the basic data set of the network traffic. Use the departments and business areas in the hospital network as nodes to establish traffic association relationships; each node represents a department or business area, and the edges between the nodes represent the traffic transmission paths between different departments or business areas. S53. The basic data set of the network traffic is input into the graph neural network as the features of the nodes and edges for spatio-temporal relationship modeling. Adopt a combination of multi-layer perceptron and graph convolutional network to calculate the high-order relationships between the nodes. S54. Through the graph neural network model, perform traffic prediction to obtain the traffic trends between each department and business area of the hospital network. Adopt multi-scale graph convolutional layers to enhance the learning ability of the graph neural network model. Among them, represents the hidden state of node v at the (k + 1)-th layer, σ represents the activation function, represents the hidden state of node u at the k-th layer, represents the hidden state of node v at the k-th layer, N(v) represents the neighbor nodes of node v, A uv represents the weight of the edge between node u and node v, D v represents the degree matrix of node v, D u represents the degree matrix of node u, α represents the adjustment factor, represents the additional learning of node features; S55. Obtain the predicted value of the traffic through the graph neural network calculation, and combine the historical traffic data to perform traffic anomaly detection. Among them, ΔR i (t) represents the traffic deviation of the i-th department or business area at time t, represents the actual traffic of the i-th department or business area at time t, represents the predicted traffic value of the i-th department or business area at time t; S56. When it is recognized that the traffic deviation value ΔR i (t) exceeds the preset threshold, it is determined that there is an abnormal traffic. The boundary judgment of the abnormal traffic adopts an adaptive threshold method to automatically adjust the threshold according to the current network state; S57. When traffic anomalies are detected, isolate the abnormal traffic through the software-defined network control platform. The isolation process includes dynamically adjusting the network routing and directing the abnormal traffic to the monitoring slice for processing.
6. The method for secure isolation of the internal network of a hospital based on an all-optical network architecture according to claim 1, wherein, The specific steps of S6 are as follows: S61. Collect the traffic data of each virtual optical slice in the hospital internal network. The traffic data is collected and stored in real time by the network monitoring system to form a complete traffic feature data set. S62. Perform anomaly detection on the traffic feature data based on the Isolation Forest algorithm. By constructing multiple decision trees and recursively partitioning the data in the trees, identify the anomaly data points. The anomaly score of each data point reflects the degree of anomaly of the data point relative to other data points. S63. Through the tree splitting mechanism in the Isolation Forest algorithm, perform anomaly measurement on the data points of each virtual optical slice. Randomly split the traffic data through multiple decision trees. The more times of splitting, the higher the score of the anomaly point, indicating that the data point is more likely to be abnormal traffic. Among them, S anomaly (t) represents the traffic anomaly score at time t, D represents the total number of trees, and 1(T i (t)>θ i ) represents the indicator function. When the anomaly score T of the i-th tree i (t) is greater than the threshold θ i it is 1, otherwise it is 0; S64. Based on the calculated traffic anomaly score S anomaly (t), use dynamic threshold technology to determine whether there is abnormal traffic, and based on the statistical characteristics of historical traffic data, calculate the optimal anomaly detection threshold at the current moment in real time; S65. When the traffic score of the virtual optical slice exceeds the set anomaly score threshold, consider the traffic of the virtual optical slice as abnormal traffic and enter the isolation process. Among them, represents the isolated traffic value, represents the actual traffic of the i-th department or business area at time t, and θ threshold represents the set abnormal score threshold; S66. After the traffic is marked as abnormal, separate the abnormal traffic from the normal traffic through the software-defined network control platform for isolation and blocking. The isolated abnormal traffic no longer participates in network transmission until the abnormal state is lifted.
7. A method for secure isolation of the internal network of a hospital based on an all-optical network architecture according to claim 1, characterized in that, The intelligent self-healing mechanism includes: real-time monitoring of the optical path resource status in the hospital network to detect network failures or performance degradation; when a failure occurs, automatically schedule redundant optical path resources for automatic switching; after the failure is recovered, record the event and conduct log auditing.
Citation Information
Patent Citations
Enterprise informatization management platform and method based on big data
CN117973812A
Intelligent network integration optimization system
CN118631513A