A Remote Video Transmission Method and System for an Internet Medical Platform
By generating security assessment indexes in the Internet medical platform, monitoring the system status in real time and issuing early warnings, the privacy leakage problem during remote diagnosis is solved, the security and stability of the system are improved, and the privacy of patients and the reliability of medical services are guaranteed.
Patent Information
- Application Number
- CN202411764449.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-04
- Publication Date
- 2025-08-05
- Estimated Expiration
- 2044-12-04
AI Technical Summary
Internet medical platforms have a risk of privacy leakage during remote diagnosis, resulting in patient health information being obtained by criminals, which may cause identity theft, blackmail, misdiagnosis or tamper with medical data, threatening the health and safety of patients' medical systems.
By obtaining network security monitoring information and permission control information, generating an abnormality detection sensitivity index and data access permission control index, comprehensive analysis and generate a security evaluation index, and comparing it with preset thresholds, monitoring the system status in real time, and issuing early warning information to prevent privacy leakage.
Real-time security monitoring of Internet medical platforms is realized, quickly identify high-risk privacy leakage, reduce the risk of patient privacy leakage, improve system stability and operation efficiency, and ensure the reliability and security of telemedicine services.
Smart Images

Figure CN119629310B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of remote video transmission of an Internet medical platform, and in particular to a remote video transmission method and system for an Internet medical platform. Background Art
[0002] The remote video transmission system of the Internet medical platform refers to the use of Internet technology to achieve remote real-time video communication between doctors and patients, which is used in scenarios such as medical consultation, diagnosis, treatment and follow-up. Through this system, patients do not need to go to the hospital in person, but can communicate with doctors "face to face" with the help of smart devices such as mobile phones and computers. The system usually includes real-time audio and video transmission functions to ensure that doctors can observe the patient's condition through video. At the same time, it can also share medical records, images, laboratory test results and other information to facilitate doctors to make accurate diagnoses. During this process, the platform will use encryption technology to protect the patient's privacy, ensure that data will not be illegally stolen or leaked during transmission, and protect the patient's personal information security.
[0003] The system relies on efficient and stable data transmission technology to ensure clear and smooth video and synchronized audio, thereby avoiding diagnostic errors. At the same time, remote video transmission systems are often integrated with electronic medical records, remote monitoring, AI-assisted diagnosis and other functions to improve diagnosis and treatment efficiency and improve patients' medical experience. The platform usually follows strict data privacy protection standards, such as GDPR or HIPAA, to ensure the privacy of patients' health information during storage and transmission. Remote video transmission is particularly suitable for chronic disease management, remote consultations, follow-up visits and medical services in remote areas, making medical resources more equitable, reducing patients' time costs and transportation burdens, and ensuring the security of patient data.
[0004] The existing technology has the following deficiencies:
[0005] If an anomaly occurs during the remote diagnosis process on an Internet medical platform, resulting in the leakage of patient privacy, and the system fails to detect or prevent such leakage in a timely manner, it may trigger a series of serious consequences. Patient health information, such as medical records, diagnostic reports and medication usage records, usually contains sensitive content. If this information is obtained by criminals, it may be used for identity theft, fraud or extortion. For example, medical information involving sexually transmitted diseases, mental health problems or cancer may be used to blackmail patients, and even private medical information may be maliciously sold to insurance companies or other companies, resulting in increased insurance premiums or loss of insurance eligibility for patients.
[0006] In addition, privacy leaks may also allow hackers or criminals to tamper with patients' medical data, which directly threatens patients' medical safety. Tampered medical records or health records may cause doctors to make incorrect diagnoses or prescribe inappropriate medications, posing serious risks to patients' health or even life-threatening. In general, privacy leaks will not only cause direct harm to individual patients, but may also pose a major threat to the trust and security of the entire medical system.
[0007] The above information disclosed in this Background section is only for enhancement of understanding of the background of the present disclosure and therefore it may contain information that does not form the prior art that is already known to a person of ordinary skill in the art. Summary of the Invention
[0008] The purpose of the present invention is to provide a remote video transmission method and system for an Internet medical platform to solve the problems in the above background technology.
[0009] In order to achieve the above object, the present invention provides the following technical solution: comprising the following steps:
[0010] Obtain various parameter information generated during the remote diagnosis process of the Internet medical platform, including network security monitoring information and authority control information, and process the network security monitoring information and authority control information;
[0011] Comprehensively analyze the processed network security monitoring information and permission control information to generate a security assessment index, and use the security assessment index to evaluate the remote diagnosis process of the Internet medical platform;
[0012] Compare and analyze the security assessment index generated during the remote diagnosis process of the Internet medical platform with the pre-set reference threshold of the security assessment index to determine the operating status of the remote diagnosis of the Internet medical platform and issue early warning information for existing security risks;
[0013] When judging the operating status of the remote diagnosis of the Internet medical platform, several security assessment indexes generated in real time during the remote diagnosis process of the Internet medical platform are collected for comprehensive analysis to judge the operating status of the Internet medical platform;
[0014] Preferably, the acquired network security monitoring information and permission control information include an anomaly detection sensitivity index and a data access permission control index, respectively, and the anomaly detection sensitivity index and the data access permission control index are calibrated as ADSI and ACRI, respectively;
[0015] Preferably, the abnormal detection sensitivity index ADSI and the data access permission control index ACRI after analysis and processing during the remote diagnosis process of the Internet medical platform are used to generate a security assessment index AS, based on the following formula:
[0016] ,
[0017] Where, f1 and f2 are the preset proportional coefficients of the anomaly detection sensitivity index ADSI and the data access control index ACRI, respectively, and both f1 and f2 are greater than 0;
[0018] Preferably, within the detection window, network security monitoring information is collected, features are extracted from the collected network security monitoring information, normal activity data is modeled using a statistical model, and the range of abnormal activity data is defined;
[0019] Calculate the anomaly score for each behavior based on its deviation from normal activity data. The calculation expression is as follows:
[0020] ,
[0021] Where Q i represents the abnormality score, that is, the abnormality score of the i-th behavior, W j represents the weight of the jth feature, reflecting the importance of the feature to anomaly detection, F ij represents the value of the i-th behavior on the j-th feature, represents the normal behavior model prediction value of the jth feature, and m represents the total number of features;
[0022] Based on the anomaly score, the anomaly detection sensitivity index of the entire system is calculated to evaluate the system's ability to detect abnormal activities. The calculation expression is as follows:
[0023] ,
[0024] In the formula, ADSI represents the anomaly detection sensitivity index, n represents the total number of behaviors, and τ adjusts the system's evaluation of different anomaly scores Q. i The sensitivity of , max(Q) represents the maximum value of all abnormality scores;
[0025] Preferably, under the detection window, collect and define the permission access matrix P, where the element P rs represents the access permission level of user r to resource s. The dimension of the access matrix is R×S, where R is the total number of users, S is the total number of resources, and the element P rs is one of the elements in the permission access matrix P;
[0026] Calculate the authority distribution imbalance index of all users. The calculation expression is as follows:
[0027] ,
[0028] Where E represents the authority distribution imbalance index, D rsIt is an element of the permission distribution matrix D, which represents the permission weight of user r to resource s;
[0029] Calculate the permission control consistency index. The calculation expression is as follows:
[0030] ,
[0031] Where H represents the authority control consistency index, C st It is one of the elements of the permission control consistency index F, indicating the permission consistency between resource s and resource t;
[0032] The data access permission control index is generated by combining the permission distribution imbalance index E and the permission control consistency index F. The calculation expression is as follows:
[0033] ,
[0034] Where ACRI represents the data access permission control index, max(E) represents the theoretical maximum value of the permission distribution imbalance index, and max(H) represents the theoretical maximum value of the permission control consistency index.
[0035] Preferably, the safety assessment index generated during the remote diagnosis process of the Internet medical platform is compared with a pre-set safety assessment index reference threshold, and the analysis results are as follows:
[0036] If the safety assessment index is less than or equal to the pre-set safety assessment index reference threshold, a high-risk data anomaly signal is generated and an early warning prompt is issued for the high-risk data anomaly signal;
[0037] If the safety assessment index is greater than the pre-set safety assessment index reference threshold, a low-risk data anomaly signal is generated, and no warning prompt is issued for the low-risk data anomaly signal;
[0038] Preferably, when determining the operating status of the remote diagnosis of the Internet medical platform, a plurality of security assessment indexes generated in real time during the remote diagnosis process of the Internet medical platform are collected to establish a data set, and a comprehensive analysis is performed on the plurality of security assessment indexes in the data set;
[0039] Calculate the average value and standard deviation of several safety assessment indices in the data set, and mark the average value and standard deviation of the safety assessment indices as AS 平均 and AS 标准 , and the average value of the safety assessment index AS 平均 and the standard deviation of the safety assessment index AS 标准 The average value of the pre-set safety assessment index reference threshold AS 参考平均 and the standard deviation reference threshold of the safety assessment index AS 参考标准The comparison results are as follows:
[0040] If AS 平均 ≤AS 参考平均 , then an early warning signal is generated. When an early warning signal is generated, it indicates that an abnormality has occurred during the operation of the remote diagnosis of the Internet medical platform, and the system needs to be inspected and maintained;
[0041] like , indicating that the remote diagnosis operation of the Internet medical platform is unstable, and the operation process is sometimes good and sometimes bad, which generates an unstable signal and also requires inspection and maintenance of the system;
[0042] like , indicating that the remote diagnosis operation of the Internet medical platform is in a stable state, generating an operation stability signal, indicating that the system is running normally and no intervention is required;
[0043] A remote video transmission system for an Internet medical platform, characterized by comprising a data acquisition module, a comprehensive analysis module, a hidden danger perception module, an early warning module, and a feedback module;
[0044] The data acquisition module obtains various parameter information generated during the remote diagnosis process of the Internet medical platform, including network security monitoring information and authority control information, and processes the network security monitoring information and authority control information;
[0045] The comprehensive analysis module comprehensively analyzes the processed network security monitoring information and permission control information to generate a security assessment index, which is used to evaluate the remote diagnosis process of the Internet medical platform;
[0046] The hidden danger perception module compares and analyzes the safety assessment index generated during the remote diagnosis process of the Internet medical platform with the pre-set safety assessment index reference threshold, determines the operating status of the remote diagnosis of the Internet medical platform, and issues early warning information on existing safety hazards through the early warning module;
[0047] The feedback module collects several security assessment indexes generated in real time during the remote diagnosis process of the Internet medical platform for comprehensive analysis to determine the operating status of the Internet medical platform when judging the operating status of the remote diagnosis of the Internet medical platform.
[0048] In the above technical solution, the technical effects and advantages provided by the present invention are:
[0049] The present invention can monitor the system status in real time at each step of the diagnostic process by obtaining the network security monitoring information and permission control information generated during the remote diagnosis process of the Internet medical platform, especially the anomaly detection sensitivity index and the data access permission control index. By generating a comprehensive security assessment index and comparing it with a preset reference threshold, the system operation status can be judged quickly and accurately. When the security assessment index exceeds the preset threshold, the system will generate a high-risk data anomaly signal and issue an early warning, prompting the system administrator to intervene and maintain, thereby preventing potential privacy leakage problems from further expanding. This real-time monitoring and early warning mechanism effectively improves the system's sensitivity to anomaly detection, can identify high-risk issues that may lead to patient privacy leakage in advance, and ensures the operational security of the platform.
[0050] The present invention collects several safety assessment indexes generated in real time during the remote diagnosis process, establishes a data set, and calculates the average value and standard deviation to more carefully evaluate the stability of the system. If the average value and standard deviation of the safety assessment index deviate significantly from the set reference threshold, the system will generate an early warning signal or an instability signal, indicating that there is instability or abnormality in the operation of the system. Through this method, the platform can more accurately identify situations where the system is in an unstable state or operating abnormally, and issue maintenance recommendations in a timely manner. This system status analysis method helps optimize maintenance strategies, not only reduces the risk of patient privacy leakage, but also improves the overall operating efficiency and stability of the system, and ensures the reliability and security of telemedicine services. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, a brief introduction to the drawings required for use in the embodiments will be given below. Obviously, the drawings described below are only some embodiments recorded in the present invention. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.
[0052] Figure 1 This is a flow chart of a remote video transmission method and system for an Internet medical platform of the present invention.
[0053] Figure 2 This is a module schematic diagram of a remote video transmission method and system for an Internet medical platform of the present invention. DETAILED DESCRIPTION
[0054] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in many forms and should not be construed as limited to the examples set forth herein. Instead, these example embodiments are provided so that the description of the present disclosure will be more comprehensive and complete and will fully convey the concept of the example embodiments to those skilled in the art.
[0055] The present invention provides Figure 1 The remote video transmission method of an Internet medical platform shown includes the following steps:
[0056] Obtain various parameter information generated during the remote diagnosis process of the Internet medical platform, including network security monitoring information and authority control information, and process the network security monitoring information and authority control information;
[0057] The network security monitoring information and permission control information obtained include anomaly detection sensitivity index and data access permission control index, which are calibrated as ADSI and ACRI respectively.
[0058] The anomaly detection sensitivity index indicates the system's monitoring capability and sensitivity to abnormal activities;
[0059] During remote diagnosis on internet medical platforms, changes in anomaly detection sensitivity can have a significant impact on system security and risk management. Lower anomaly detection sensitivity means the system may lose vigilance against minor abnormal activities, especially those that occur gradually and are more subtle. Hackers can exploit this vulnerability to steal or tamper with patients' health data without being detected, leading to data leaks or misleading diagnoses, thereby endangering patients' medical safety. Furthermore, unauthorized personnel may be able to access sensitive data without detection, further amplifying the risk of privacy leaks and increasing platform security risks.
[0060] On the contrary, a higher anomaly detection sensitivity indicates that the system is in a highly alert state and can effectively monitor more subtle abnormal activities. Even small-scale or gradually developing attacks can be discovered and prevented in a timely manner, thereby better protecting patient data security and the overall operation of the platform.
[0061] The logic for obtaining the anomaly detection sensitivity index is as follows:
[0062] In the detection window, network security monitoring information is collected, features are extracted from the collected network security monitoring information, normal activity data is modeled using statistical models, and the range of abnormal activity data is defined;
[0063] It should be noted that normal activity data and abnormal activity data are two types of key data used by network security monitoring systems to identify and distinguish system behaviors;
[0064] Normal activity data
[0065] Definition: Normal activity data refers to the standard behavior of various user and system operations when there are no security threats or abnormal situations in the system. It represents the data generated when legitimate users operate in accordance with system regulations and permissions.
[0066] Common types:
[0067] User login records: records of legitimate users logging into the system using correct credentials;
[0068] Legal file access: Users access, read, or modify files according to their permissions;
[0069] System update and maintenance logs: logs generated during normal system operation and updates, such as regular system backups and software updates;
[0070] Regular network traffic: traffic data generated by normal user network requests, such as uploading or downloading legal files, sending emails, video conferencing, etc.
[0071] Daily query and operation records: Doctors, nurses and other medical personnel perform normal operations such as querying patient information, prescribing medicine, and updating medical records on the medical platform;
[0072] Unusual activity data
[0073] Definition: Abnormal activity data refers to data generated when abnormal behavior occurs in the system or involves potential security threats, unauthorized access, or other malicious behavior. This type of data may indicate a cyberattack, data leakage, or unauthorized activity.
[0074] Common types:
[0075] Unauthorized access attempts: Login failure records generated when a user or malicious person attempts to access the system using incorrect credentials or unauthorized means;
[0076] Unusual file modifications: Unauthorized users attempt to access or tamper with sensitive files, such as medical or medication records;
[0077] Malware activity: Signs of malware or virus transmission are detected in the system, such as the creation of unknown files or the execution of automated programs;
[0078] Abnormal network traffic: sudden large amounts of data transmission (such as DDoS attacks) or requests from unusual sources (such as high-frequency requests from unknown IP addresses);
[0079] Database tampering or leakage: hackers modify database information, steal sensitive data, or attempt to export data in bulk after intrusion;
[0080] Abnormal system privilege changes: Unauthorized users or programs attempt to change privileges to grant themselves or others increased system access rights;
[0081] Normal activity data reflects the records of legitimate users operating the system in a secure environment in a regular manner, including logins, file accesses, network requests, etc.
[0082] Abnormal activity data refers to abnormal operations captured when potential security issues occur in the system, such as unauthorized access, malicious attacks, abnormal traffic, etc.
[0083] By collecting these two types of data, the system can learn how to identify normal and abnormal behaviors and further improve the accuracy of security monitoring and threat detection;
[0084] Network security monitoring information refers to data related to network security that is collected, recorded, and analyzed through various technical means to identify, assess, and respond to potential security threats and vulnerabilities. The following is a detailed description of network security monitoring information, including its main types and contents:
[0085] 1. Network Traffic Data (NetworkTrafficData)
[0086] Content: Records detailed information of data packets transmitted in the network, including source IP address, destination IP address, transmission protocol, port number, data volume, etc.
[0087] Purpose: Helps analyze network traffic patterns, identify abnormal traffic behavior, such as traffic surges and abnormal connection requests, and monitor possible network attacks (such as DDoS attacks) or data leaks;
[0088] 2. User Login Records
[0089] Content: Records detailed information about users logging into the system, including login time, IP address, user ID, login status (successful or failed), authentication method, etc.
[0090] Purpose: Used to detect abnormal login activities, such as failed login attempts, remote logins, and unauthorized login attempts. This information helps identify security incidents such as account hijacking and brute force attacks.
[0091] 3. System Logs
[0092] Content: Records detailed information about system internal events and operations, including system startup and shutdown, error messages, alerts, service status changes, system configuration modifications, etc.
[0093] Function: System logs are used to track the operating status and events within the system, helping to diagnose system failures, identify potential security issues (such as misconfiguration or abnormal system behavior), and conduct incident response and investigations.
[0094] 4. Application Logs
[0095] Content: Records application running events and operations, including application startup and shutdown, error messages, user operation logs, data access records, etc.
[0096] Purpose: Helps identify abnormal behavior at the application layer, such as application crashes, malicious user behavior, and data leaks, providing in-depth insights into application security.
[0097] 5. Security Event Logs
[0098] Content: Records security-related events and alerts, including intrusion detection system (IDS) and intrusion prevention system (IPS) alerts, malware detection reports, abnormal behavior alerts, etc.
[0099] Purpose: Provides real-time alerts and detailed information about network security threats, helping security teams quickly respond to and handle security incidents.
[0100] 6. Device Status Information (DeviceStatusInformation)
[0101] Content: Records the operating status, configuration changes, and performance indicators of network devices (such as routers, firewalls, and switches);
[0102] Purpose: Helps monitor the health and performance of devices, identify potential device failures or configuration issues, and prevent security vulnerabilities caused by device failures;
[0103] 7. Vulnerability Scan Results
[0104] Content: Record the results of regular vulnerability scans, including discovered vulnerabilities, vulnerability severity, and recommended fixes;
[0105] Purpose: Provides information about potential security vulnerabilities in systems and networks, helping to prioritize the repair of high-risk vulnerabilities and enhance the overall security of the system;
[0106] 8. Network Behavior Analysis (NBA)
[0107] Content: Record and analyze the behavioral patterns of network traffic, such as normal traffic patterns, data transmission frequency, communication protocol usage, etc.
[0108] Purpose: By analyzing network behavior patterns and identifying behaviors that are significantly different from normal patterns, it helps detect potential attacks or abnormal activities.
[0109] Summarize
[0110] Network security monitoring information covers a variety of data types, from network traffic to user activity, system status, and application logs. This information plays a key role in network security management. Through comprehensive analysis of various data, it can effectively identify and respond to potential security threats and protect the security of systems and data.
[0111] Calculate the anomaly score for each behavior based on its deviation from normal activity data. The calculation expression is as follows:
[0112] ,
[0113] Where Q i represents the abnormality score, that is, the abnormality score of the i-th behavior, W j represents the weight of the jth feature, reflecting the importance of the feature to anomaly detection, F ij represents the value of the i-th behavior on the j-th feature, represents the normal behavior model prediction value of the jth feature, and m represents the total number of features;
[0114] Based on the anomaly score, the anomaly detection sensitivity index of the entire system is calculated to evaluate the system's ability to detect abnormal activities. The calculation expression is as follows:
[0115] ,
[0116] In the formula, ADSI represents the anomaly detection sensitivity index, n represents the total number of behaviors, and τ adjusts the system's evaluation of different anomaly scores Q. i The sensitivity of , max(Q) represents the maximum value of all abnormality scores;
[0117] Under the detection window, the calculation expression of the anomaly detection sensitivity index shows that the smaller the anomaly detection sensitivity index performance value, the lower the system's sensitivity to abnormal activities, making it easier to ignore potential security threats. Therefore, when the anomaly detection sensitivity index performance value is smaller, it means that the network security monitoring system lacks vigilance against minor or hidden abnormal behaviors, resulting in an increased probability of abnormal hidden dangers in the remote diagnosis process of the networked medical platform. The system may not be able to detect security incidents such as attacks or data tampering in a timely manner. On the contrary, the larger the anomaly detection sensitivity index performance value, the more sensitive the system is to abnormal behavior detection, and the possibility of security risks is lower, which means that the system can more effectively respond to and prevent potential security risks.
[0118] The data access rights control index (ACRI) reflects the strictness of the system's management of user access rights.
[0119] During remote diagnosis on internet medical platforms, changes in data access control can indeed lead to a series of abnormal risks, especially when processing sensitive health data. These risks mainly arise from uncontrolled permission management, improper data access, and potential malicious behavior.
[0120] First, changes in data access control may allow unauthorized users to access sensitive patient information, such as medical records, diagnostic records, and laboratory test results. If permission control mechanisms are no longer strictly assigned, nurses, technicians, or other unrelated users may obtain private data that was originally intended for doctors to view only. Such unauthorized access not only violates patient privacy rights but also poses a potential risk of data leakage, exposing data to third parties who should not have access. This improper access increases the possibility of medical privacy leaks, thereby damaging patient trust and the platform's reputation.
[0121] Secondly, changes in permissions can lead to incorrect medical decisions. If a doctor's access rights are improperly modified or restricted, they may not be able to obtain a patient's complete medical history, test results, and other critical data in a timely manner, directly affecting the accuracy of the diagnosis and the formulation of treatment plans. This incomplete data or delayed access poses risks to the patient's health, especially in emergency or critical situations, where incorrect decisions may lead to irreversible consequences.
[0122] Furthermore, loose permission control can lead to malicious tampering or sabotage. Hackers or insiders who gain higher permissions could tamper with patient data, forge medical records, or modify diagnostic records, posing serious health risks to patients. Doctors, after obtaining tampered medical data, could make incorrect diagnoses or prescribe the wrong medications, threatening patients' lives.
[0123] In general, changes in data access rights control can pose significant security risks. They can not only lead to the leakage of sensitive data, but also affect the accuracy of diagnostic decisions and even trigger data tampering and malicious attacks. Therefore, precise management of access control is crucial for remote diagnosis on Internet medical platforms and is one of the core elements to ensure platform security and diagnosis and treatment accuracy.
[0124] The logic for obtaining the data access permission control index is as follows:
[0125] Under the detection window, collect and define the permission access matrix P, where the element P rs represents the access permission level of user r to resource s. The dimension of the access matrix is R×S, where R is the total number of users, S is the total number of resources, and the element P rs is one of the elements in the permission access matrix P;
[0126] Permission levels can be represented by discrete values, such as 0 (no access), 1 (read access), 2 (write access), and 3 (administrative access);
[0127] A permission level is a method used to describe the scope and degree of access a user has to system resources. It is typically expressed as discrete values, each corresponding to a specific access right. The following are common permission levels and their meanings:
[0128] 0 (no access):
[0129] The user does not have any permissions to access or operate the resource. This means that the user cannot view, modify, or perform any operations related to the resource.
[0130] 1 (read access):
[0131] Users can view and read the contents of a resource but cannot modify or delete it. For example, users can view the contents of a file but cannot edit or delete it.
[0132] 2 (write permission):
[0133] Users can modify the contents of a resource, including adding, editing, and deleting. In addition to viewing a resource, users can also make changes to it. Typically, this permission allows users to update or modify data.
[0134] 3 (Administrative permissions):
[0135] The user has full control over the resource, including read, write, and delete permissions, as well as other permissions for managing resources (such as configuration permissions, setting permissions, etc.). This permission is usually given to system administrators or users with high-level management responsibilities;
[0136] The role of permission levels:
[0137] Control access: By setting permission levels, you can precisely control different users' access to resources and operation permissions to ensure system security and data integrity;
[0138] Protect sensitive data: By setting higher permission requirements for sensitive data, the risk of data leakage and abuse can be reduced;
[0139] Implement hierarchical management: Different permission levels allow the system to implement hierarchical management, and users with different roles can obtain corresponding access rights according to their responsibilities;
[0140] A statistical model is a mathematical framework used to describe the process of data generation and the regularities behind it. It assumes that data follows a certain probability distribution or regularity, and then establishes mathematical equations or functions to explain data changes and predict possible future outcomes. The core of a statistical model is to use known observational data to infer unknown parameters, identify trends, and detect anomalies.
[0141] Statistical models typically consist of three main parts:
[0142] 1. Random variables: describe the randomness or uncertainty of data;
[0143] 2. Parameters: control the distribution of data, such as mean, variance, etc.
[0144] 3. Error term: represents randomness or noise in the data that cannot be fully explained;
[0145] For example, in network security, statistical models can be used to analyze network traffic, assuming that normal network behavior conforms to a certain statistical distribution, such as the normal distribution; if new observations deviate significantly from this distribution, it may be abnormal behavior;
[0146] There are many statistical and machine learning models for modeling normal activity data. The following are some common ones:
[0147] (1) Gaussian Mixture Model (GMM)
[0148] Description: Assume that the data is a mixture of multiple Gaussian distributions, each representing a different type of normal behavior;
[0149] Usage: Used to model normal activity data and detect anomalies by evaluating whether new data points belong to a known Gaussian distribution;
[0150] (2) Autoregressive Integrated Moving Average (ARIMA)
[0151] Description: It is a time series model that predicts future values from historical data.
[0152] Usage: If the actual observed time series data deviates significantly from the normal pattern predicted by the model, it can be judged as abnormal behavior;
[0153] (3) Support Vector Machine (SVM)
[0154] Description: Train a classification model on normal activity data to construct a boundary to distinguish normal behavior from potential abnormal behavior;
[0155] Usage: For a new observation data point, if the point exceeds the classification boundary, it is considered an anomaly;
[0156] (4) Density Estimation Models
[0157] Description: Estimate the probability density function of normal activity data; a common method is kernel density estimation (KDE);
[0158] Usage: If a new data point falls in a low-density area, it is considered an anomaly;
[0159] (5) Hidden Markov Model (HMM)
[0160] Description: Used to model data with hidden states and random transition processes, such as user click streams and network connection sequences;
[0161] Usage: If the observed behavior sequence deviates from the hidden state inferred in the model, it is considered an anomaly;
[0162] (6) Autoencoder
[0163] Description: A neural network that learns a low-dimensional representation of data by compressing normal data and reconstructing it back.
[0164] Usage: Abnormal data will have large errors during the reconstruction process and will be identified as abnormal;
[0165] (7) k-Nearest Neighbors (k-NN)
[0166] Description: Calculate the distance between a new data point and its nearest k points, and detect anomalies based on the distance;
[0167] Usage: If the distance between a new data point and the adjacent normal data points is large, it is considered an anomaly;
[0168] (8) Bayesian Networks
[0169] Description: Use probabilistic graphical models to represent the dependencies between different variables and combine prior and posterior probabilities for inference;
[0170] Usage: Use the Bayesian update rule to determine whether new data deviates from normal activity patterns;
[0171] 3. Define the scope of abnormal activity data
[0172] Abnormal activity data refers to data that deviates from normal behavior patterns, often reflecting atypical, irregular, or even potentially malicious behavior. This type of data can be defined by modeling and comparing it to normal data, as follows:
[0173] (1) Behavior that is significantly different from normal data
[0174] Definition: Abnormal activity data significantly deviates from the statistical characteristics of normal activity data; for example, a user's network traffic pattern suddenly changes significantly, or a server response time suddenly increases significantly.
[0175] (2) Low-probability events
[0176] Definition: Anomalous activity data has a very low probability of occurring according to a probabilistic model, typically occurring in the tail region of a statistical distribution; for example, in the case of a Gaussian distribution, data points that are outside of two standard deviations from the mean.
[0177] (3) Violation of normal sequence or time pattern
[0178] Definition: In time series, abnormal activity manifests as sudden events or behaviors that cannot be explained by historical data patterns; for example, a surge in server resource consumption over a short period of time, or a sudden, unusual fluctuation in traffic load.
[0179] (4) Unknown or unseen behavior
[0180] Definition: Anomalous activity data may not belong to any known normal behavior category. For example, in a classification model, a new data point does not belong to any existing normal category.
[0181] (5) Violation of specific security rules or policies
[0182] Definition: Abnormal activity may also refer to violations of specific security policies or access control rules; for example, a user logging into the system during an unauthorized time period or accessing restricted resources.
[0183] (6) Relationships or patterns that do not conform to expectations
[0184] Definition: In relational data or graph structures, unusual activity data may refer to behaviors that are inconsistent with normal association patterns; for example, in a social network, a node suddenly establishes connections with multiple unseen nodes.
[0185] By using statistical models to model normal activity data, the scope of abnormal activity data can be defined. Abnormal data is generally considered to be behavior that deviates from normal statistical patterns. It may appear as values significantly different from normal activity, low-probability events, sudden changes in time series, or violations of security rules.
[0186] Calculate the authority distribution imbalance index of all users. The calculation expression is as follows:
[0187] ,
[0188] Where E represents the authority distribution imbalance index, D rs It is an element of the permission distribution matrix D, which represents the permission weight of user r to resource s;
[0189] Calculate the permission control consistency index. The calculation expression is as follows:
[0190] ,
[0191] Where H represents the authority control consistency index, C st It is one of the elements of the permission control consistency index H, indicating the permission consistency between resource s and resource t;
[0192] The data access permission control index is generated by combining the permission distribution imbalance index E and the permission control consistency index F. The calculation expression is as follows:
[0193] ,
[0194] Where ACRI represents the data access permission control index, max(E) represents the theoretical maximum value of the permission distribution imbalance index, and max(H) represents the theoretical maximum value of the permission control consistency index.
[0195] In the detection window, the data access permission control index calculation expression shows that the smaller the data access permission control index performance value, it means that after the abnormal analysis of the permission control information in the detection window, obvious inconsistencies or abnormalities are found in the permission allocation or control. This usually indicates that there are potential security risks in the system. For example, there may be problems such as excessive authorization, inappropriate permission configuration or permission abuse. These problems increase the risk of data leakage, unauthorized access or other abnormalities during the remote diagnosis process. Conversely, when the performance value of the data access permission control index performance value is larger, it usually indicates that the permission control system is operating normally, the permission allocation and control are relatively consistent, and the probability of abnormal risks is small.
[0196] Comprehensively analyze the processed network security monitoring information and permission control information to generate a security assessment index, and use the security assessment index to evaluate the remote diagnosis process of the Internet medical platform;
[0197] The anomaly detection sensitivity index ADSI and data access permission control index ACRI after analysis and processing in the remote diagnosis process of the Internet medical platform are used to generate the security assessment index AS. The formula is:
[0198]
[0199] ,where f1 and f2 are the preset proportional coefficients of anomaly detection sensitivity index ADSI and data access permission control index ACRI, respectively, and both f1 and f2 are greater than 0;
[0200] From the calculation expression of the security assessment index, it can be seen that the smaller the performance value of the anomaly detection sensitivity index generated within the detection window, the smaller the performance value of the data access permission control index, that is, the smaller the security assessment index generated during the remote diagnosis process of the Internet medical platform, the greater the probability of anomalies occurring during the remote diagnosis process of the Internet medical platform; conversely, the larger the performance value of the anomaly detection sensitivity index generated within the detection window, the larger the performance value of the data access permission control index, that is, the larger the security assessment index generated during the remote diagnosis process of the Internet medical platform, the smaller the probability of anomalies occurring during the remote diagnosis process of the Internet medical platform;
[0201] Compare and analyze the security assessment index generated during the remote diagnosis process of the Internet medical platform with the pre-set reference threshold of the security assessment index to determine the operating status of the remote diagnosis of the Internet medical platform and issue early warning information for existing security risks;
[0202] The safety assessment index generated during the remote diagnosis process of the Internet medical platform was compared with the pre-set safety assessment index reference threshold. The analysis results are as follows:
[0203] If the safety assessment index is less than or equal to the pre-set safety assessment index reference threshold, a high-risk data anomaly signal is generated and an early warning prompt is issued for the high-risk data anomaly signal;
[0204] If the safety assessment index is greater than the pre-set safety assessment index reference threshold, a low-risk data anomaly signal is generated, and no warning prompt is issued for the low-risk data anomaly signal;
[0205] If the security assessment index is less than or equal to the pre-set security assessment index reference threshold, a high-risk data anomaly signal is generated. When a high-risk data anomaly signal is generated during the remote diagnosis process of the Internet medical platform, it indicates that the probability of anomalies in the remote diagnosis process of the Internet medical platform is greater. An early warning prompt is issued for the high-risk data anomaly signal, notifying relevant staff to promptly maintain the Internet medical platform to prevent the risk of patient privacy leakage;
[0206] When judging the operating status of the remote diagnosis of the Internet medical platform, several security assessment indexes generated in real time during the remote diagnosis process of the Internet medical platform are collected for comprehensive analysis to judge the operating status of the Internet medical platform;
[0207] When judging the operating status of the remote diagnosis of the Internet medical platform, a number of security assessment indexes generated in real time during the remote diagnosis process of the Internet medical platform are collected to establish a data set, and a comprehensive analysis of the several security assessment indexes in the data set is performed;
[0208] Calculate the average value and standard deviation of several safety assessment indices in the data set, and mark the average value and standard deviation of the safety assessment indices as AS 平均 and AS 标准 , and the average value of the safety assessment index AS 平均 and the standard deviation of the safety assessment index AS 标准 The average value of the pre-set safety assessment index reference threshold AS 参考平均 and the standard deviation reference threshold of the safety assessment index AS 参考标准 The comparison results are as follows:
[0209] If AS 平均 ≤AS 参考平均 , then an early warning signal is generated. When an early warning signal is generated, it indicates that an abnormality has occurred during the operation of the remote diagnosis of the Internet medical platform, and the system needs to be inspected and maintained;
[0210] like , indicating that the remote diagnosis operation of the Internet medical platform is unstable, and the operation process is sometimes good and sometimes bad, which generates an unstable signal and also requires inspection and maintenance of the system;
[0211] like , indicating that the remote diagnosis operation of the Internet medical platform is in a stable state, generating an operation stability signal, indicating that the system is running normally and no intervention is required;
[0212] The present invention can monitor the system status in real time at each step of the diagnostic process by obtaining the network security monitoring information and permission control information generated during the remote diagnosis process of the Internet medical platform, especially the anomaly detection sensitivity index and the data access permission control index. By generating a comprehensive security assessment index and comparing it with a preset reference threshold, the system operation status can be judged quickly and accurately. When the security assessment index exceeds the preset threshold, the system will generate a high-risk data anomaly signal and issue an early warning, prompting the system administrator to intervene and maintain, thereby preventing potential privacy leakage problems from further expanding. This real-time monitoring and early warning mechanism effectively improves the system's sensitivity to anomaly detection, can identify high-risk issues that may lead to patient privacy leakage in advance, and ensures the operational security of the platform.
[0213] The present invention collects several safety assessment indexes generated in real time during the remote diagnosis process, establishes a data set, and calculates the average value and standard deviation to more carefully evaluate the stability of the system. If the average value and standard deviation of the safety assessment index deviate significantly from the set reference threshold, the system will generate an early warning signal or an instability signal, indicating that there is instability or abnormality in the operation of the system. Through this method, the platform can more accurately identify situations where the system is in an unstable state or operating abnormally, and issue maintenance recommendations in a timely manner. This system status analysis method helps optimize maintenance strategies, not only reduces the risk of patient privacy leakage, but also improves the overall operating efficiency and stability of the system, and ensures the reliability and security of telemedicine services.
[0214] The present invention provides Figure 2 The remote video transmission system of an Internet medical platform shown includes a data acquisition module, a comprehensive analysis module, a hidden danger perception module, an early warning module, and a feedback module;
[0215] The data acquisition module obtains various parameter information generated during the remote diagnosis process of the Internet medical platform, including network security monitoring information and authority control information, and processes the network security monitoring information and authority control information;
[0216] The comprehensive analysis module comprehensively analyzes the processed network security monitoring information and permission control information to generate a security assessment index, which is used to evaluate the remote diagnosis process of the Internet medical platform;
[0217] The hidden danger perception module compares and analyzes the safety assessment index generated during the remote diagnosis process of the Internet medical platform with the pre-set safety assessment index reference threshold, determines the operating status of the remote diagnosis of the Internet medical platform, and issues early warning information on existing safety hazards through the early warning module;
[0218] The feedback module collects several security assessment indexes generated in real time during the remote diagnosis process of the Internet medical platform for comprehensive analysis to determine the operating status of the Internet medical platform.
[0219] The embodiment of the present invention provides a remote video transmission method for an Internet medical platform, which is implemented by the remote video transmission system of the Internet medical platform. The specific method and process of the remote video transmission system of an Internet medical platform are detailed in the embodiment of the remote video transmission method of the Internet medical platform, which will not be repeated here.
[0220] The above description is only of certain exemplary embodiments of the present invention by way of illustration. It is undeniable that a person skilled in the art can modify the described embodiments in various ways without departing from the spirit and scope of the present invention. Therefore, the above drawings and descriptions are illustrative in nature and should not be construed as limiting the scope of protection of the claims of the present invention.
Claims
1. A remote video transmission method for an Internet medical platform, comprising the following steps: Obtain various parameter information generated during the remote diagnosis process of the Internet medical platform, including network security monitoring information and authority control information, and process the network security monitoring information and authority control information; Comprehensively analyze the processed network security monitoring information and permission control information to generate a security assessment index, and use the security assessment index to evaluate the remote diagnosis process of the Internet medical platform; Compare and analyze the security assessment index generated during the remote diagnosis process of the Internet medical platform with the pre-set reference threshold of the security assessment index to determine the operating status of the remote diagnosis of the Internet medical platform and issue early warning information for existing security risks; When judging the operating status of the remote diagnosis of the Internet medical platform, several security assessment indexes generated in real time during the remote diagnosis process of the Internet medical platform are collected for comprehensive analysis to judge the operating status of the Internet medical platform; The network security monitoring information and permission control information obtained include anomaly detection sensitivity index and data access permission control index, which are calibrated as ADSI and ACRI respectively. In the detection window, network security monitoring information is collected, features are extracted from the collected network security monitoring information, normal activity data is modeled using statistical models, and the range of abnormal activity data is defined; Calculate the anomaly score of each behavior based on its deviation from normal activity data. The calculation expression is as follows: , Where Q i represents the abnormality score, that is, the abnormality score of the i-th behavior, W j represents the weight of the jth feature, reflecting the importance of the feature to anomaly detection, F ij represents the value of the i-th behavior on the j-th feature, represents the normal behavior model prediction value of the jth feature, and m represents the total number of features; Based on the anomaly score, the anomaly detection sensitivity index of the entire system is calculated to evaluate the system's ability to detect abnormal activities. The calculation expression is as follows: , In the formula, ADSI represents the anomaly detection sensitivity index, n represents the total number of behaviors, and τ adjusts the system's evaluation of different anomaly scores Q. i The sensitivity of the anomaly score is , and max(Q) represents the maximum value of all anomaly scores.
2. The remote video transmission method of an Internet medical platform according to claim 1, characterized in that: The anomaly detection sensitivity index ADSI and data access permission control index ACRI after analysis and processing in the remote diagnosis process of the Internet medical platform are used to generate the security assessment index AS. The formula is: , Where f1 and f2 are the preset proportional coefficients of the anomaly detection sensitivity index ADSI and the data access permission control index ACRI, respectively, and both f1 and f2 are greater than 0.
3. The remote video transmission method of an Internet medical platform according to claim 1, characterized in that: In the detection window, calculate the privilege distribution imbalance index of all users. The calculation expression is as follows: , Where E represents the authority distribution imbalance index, D rs It is an element of the permission distribution matrix, representing the permission weight of user r to resource s, where R is the total number of users and S is the total number of resources; Calculate the permission control consistency index. The calculation expression is as follows: , Where H represents the authority control consistency index, C st It is one of the elements of the permission control consistency index H, indicating the permission consistency between resource s and resource t; The data access permission control index is generated by combining the permission distribution imbalance index E and the permission control consistency index H. The calculation expression is as follows: , Where ACRI represents the data access permission control index, max(E) represents the theoretical maximum value of the permission distribution imbalance index, and max(H) represents the theoretical maximum value of the permission control consistency index.
4. The remote video transmission method of an Internet medical platform according to claim 1, characterized in that: The safety assessment index generated during the remote diagnosis process of the Internet medical platform was compared with the pre-set safety assessment index reference threshold. The analysis results are as follows: If the safety assessment index is less than or equal to the pre-set safety assessment index reference threshold, a high-risk data anomaly signal is generated and an early warning prompt is issued for the high-risk data anomaly signal; If the safety assessment index is greater than the pre-set safety assessment index reference threshold, a low-risk data anomaly signal is generated, and no early warning prompt is issued for the low-risk data anomaly signal.
5. The remote video transmission method of an Internet medical platform according to claim 4, characterized in that: When judging the operating status of the remote diagnosis of the Internet medical platform, a number of security assessment indexes generated in real time during the remote diagnosis process of the Internet medical platform are collected to establish a data set, and a comprehensive analysis of the several security assessment indexes in the data set is performed; Calculate the average value and standard deviation of several safety assessment indices in the data set, and mark the average value and standard deviation of the safety assessment indices as AS 平均 and AS 标准 , and the average value of the safety assessment index AS 平均 and the standard deviation of the safety assessment index AS 标准 The average value of the pre-set safety assessment index reference threshold AS 参考平均 and the standard deviation reference threshold of the safety assessment index AS 参考标准 The comparison results are as follows: If AS 平均 ≤AS 参考平均 , then an early warning signal is generated. When an early warning signal is generated, it indicates that an abnormality has occurred during the operation of the remote diagnosis of the Internet medical platform, and the system needs to be inspected and maintained; like , indicating that the remote diagnosis operation of the Internet medical platform is unstable, and the operation process is sometimes good and sometimes bad, which generates an unstable signal and also requires inspection and maintenance of the system; like , indicating that the remote diagnosis operation of the Internet medical platform is in a stable state, generating a stable operation signal, indicating that the system is running normally and no intervention is required.
6. A remote video transmission system for an Internet medical platform, used to implement the remote video transmission method for an Internet medical platform as described in any one of claims 1 to 5, characterized in that: It includes data collection module, comprehensive analysis module, hidden danger perception module, early warning module and feedback module; The data acquisition module obtains various parameter information generated during the remote diagnosis process of the Internet medical platform, including network security monitoring information and authority control information, and processes the network security monitoring information and authority control information; The comprehensive analysis module comprehensively analyzes the processed network security monitoring information and permission control information to generate a security assessment index, which is used to evaluate the remote diagnosis process of the Internet medical platform; The hidden danger perception module compares and analyzes the safety assessment index generated during the remote diagnosis process of the Internet medical platform with the pre-set safety assessment index reference threshold, determines the operating status of the remote diagnosis of the Internet medical platform, and issues early warning information on existing safety hazards through the early warning module; The feedback module collects several security assessment indexes generated in real time during the remote diagnosis process of the Internet medical platform for comprehensive analysis to determine the operating status of the Internet medical platform when judging the operating status of the remote diagnosis of the Internet medical platform.
Citation Information
Patent Citations
Network security situation awareness early warning method and system
CN117811813A