A zero-trust medical network security immune defense method and system
By constructing an abnormal behavior feature database and a dynamic vaccine distribution mechanism, and combining artificial immunization algorithms to optimize firewall rules, strict behavioral monitoring and real-time defense of the medical network are achieved. This solves the problem of insufficient protection against internal attacks in traditional medical network security architectures, ensuring the security and stability of the system.
Patent Information
- Application Number
- CN202510214359.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-26
- Publication Date
- 2025-10-24
- Estimated Expiration
- 2045-02-26
AI Technical Summary
Traditional perimeter-based healthcare network security architectures are ineffective at preventing internal attacks, leading to easy access to system data once user accounts are stolen, and a lack of internal network security protection capabilities.
A zero-trust medical network security immune defense method is adopted. An abnormal behavior feature database is constructed through an artificial immune system. The distribution of vaccine resources is dynamically adjusted by combining the Lagrange optimization method. The attack detection rules of the firewall are optimized by using artificial immune algorithms to achieve strict behavioral monitoring and real-time defense for every access.
It enhances the security protection capabilities of medical network systems, enabling timely detection and blocking of attacks, ensuring the security of patient data and medical equipment, and compensating for the shortcomings of traditional perimeter protection.
Smart Images

Figure CN119892486B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of cyberspace security technology, and in particular to a zero-trust medical network security immune defense method and system. Background Art
[0002] The network architecture of the healthcare system is complex and involves multiple layers. From the hospital's internal network to external, unknown terminal access and telemedicine devices, various systems and data interactions form a highly distributed environment. Internal networks include electronic health records (EHRs), hospital information systems (HISs), medical image storage and transmission systems, and drug management and laboratory systems. External networks include telemedicine devices, cloud services, and external personnel access. Furthermore, hospitals also have numerous IoT devices, such as smart infusion pumps and heart monitors, which transmit data to central systems via the hospital network.
[0003] Traditional medical network systems are based on a security architecture based on perimeter protection, such as Figure 1 As shown in the figure, the network is divided into different zones, such as internal and external networks, based on the physical location of devices within the network. Firewalls, intrusion detection systems, and other measures are deployed at the network perimeter, along with corresponding security policies, to build a perimeter security protection system. Using a traditional perimeter-based security architecture, once a user enters the internal application network zone, existing network security measures become ineffective. Once an attacker steals a user's account password, they can easily access the system and data, stealing data resources. In a network perimeter protection architecture, adding more security devices and setting more security policies only strengthens the network perimeter's protection capabilities and fails to effectively prevent internal attacks.
[0004] Therefore, in the related technology, there is an urgent need for a method that can improve the security protection capabilities of medical network systems. Summary of the Invention
[0005] Based on this, it is necessary to provide a zero-trust medical network security immune defense method and system that can improve the security protection capabilities of medical network systems in response to the above technical problems.
[0006] In a first aspect, the present application provides a zero-trust medical network security immune defense method. The method includes:
[0007] Construct an abnormal behavior feature database based on the artificial immune system;
[0008] Dynamically adjust the vaccine resources distributed from the central server to the sub-servers based on the abnormal behavior feature database combined with the Lagrangian optimization method;
[0009] Based on the vaccine resources, an attack detection rule of a firewall is optimized by using an artificial immune algorithm, and the attack detection rule is used for network attack defense.
[0010] Optionally, in an embodiment of the present application, the constructing an abnormal behavior feature database based on an artificial immune system comprises:
[0011] Randomly generating network abnormal behavior features, and screening the network abnormal behavior features in combination with a known network attack behavior data set to obtain a fine-grained network abnormal behavior feature set;
[0012] Based on the fine-grained network abnormal behavior features, a new network abnormal behavior feature is generated by performing a variation tolerance operation to expand the fine-grained network abnormal behavior feature set;
[0013] The new network abnormal behavior feature is classified in a fine-grained manner by using a convolutional neural network to obtain an abnormal behavior feature database.
[0014] Optionally, in an embodiment of the present application, the classifying the new network abnormal behavior feature in a fine-grained manner by using a convolutional neural network comprises:
[0015] A fine-grained classification model is constructed based on a convolutional neural network, and the fine-grained classification model comprises a feature extraction part and a fine-grained classification part;
[0016] Based on the fine-grained network abnormal behavior feature set, a model is trained, and the new network abnormal behavior feature is classified in a fine-grained manner by using the trained fine-grained classification model.
[0017] Optionally, in an embodiment of the present application, the dynamically adjusting vaccine resources distributed to a subserver by a central server based on the abnormal behavior feature database in combination with a Lagrange optimization method comprises:
[0018] A time delay function and an adaptive control factor are used to preliminarily adjust and update the distribution of the vaccine resources;
[0019] A Lagrange function is constructed in combination with a constraint condition, an optimal vaccine distribution amount is solved based on the Lagrange function, and the constraint condition comprises a total vaccine amount limit, a subserver load capacity, and a network bandwidth limit.
[0020] Optionally, in an embodiment of the present application, the optimizing an attack detection rule of a firewall based on the vaccine resources in combination with an artificial immune algorithm comprises:
[0021] A preliminary attack detection rule is generated based on a clone selection algorithm;
[0022] A rule base is further optimized based on the preliminary attack detection rule by using a negative selection algorithm.
[0023] Optionally, in an embodiment of the present application, the network attack defense using the attack detection rule includes:
[0024] calculating the similarity between the traffic and the attack detection rule to determine whether the traffic conforms to the attack characteristics.
[0025] In a second aspect, the present application also provides a zero-trust medical network security immune defense system. The system includes:
[0026] a database construction module for generating a set of medical network attack behavior characteristics and constructing a behavior characteristic database;
[0027] a software initialization module for reading the network topology structure and real-time device status of the hospital using the existing integrated network management system of the hospital;
[0028] a data acquisition and preprocessing module for importing the real-time device status database and continuously monitoring and updating the device status in combination with the distributed vaccines;
[0029] a vaccine distribution and synchronization module for dynamic adjustment and distribution of the vaccines;
[0030] an abnormality tracing and processing module for analyzing abnormal behavior, finding the source of the abnormality, and blocking related connections;
[0031] a visual display module for visually displaying the system status and security risks.
[0032] In a third aspect, the present application also provides a computer device. The computer device includes a memory and a processor, the memory stores a computer program, and the processor executes the steps of the method described in each of the above embodiments.
[0033] In a fourth aspect, the present application also provides a computer readable storage medium. The computer readable storage medium stores a computer program, and the computer program is executed by a processor to implement the steps of the method described in each of the above embodiments.
[0034] The above-mentioned zero-trust medical network security immune defense method and system first constructs an abnormal behavior feature database based on an artificial immune system; then dynamically adjusts the vaccine resources distributed by the central server to the sub-servers based on the abnormal behavior feature database combined with the Lagrange optimization method; finally, optimizes the attack detection rules of the firewall based on the vaccine resources combined with the artificial immune algorithm, and uses the attack detection rules for network attack defense. That is, by constructing a fine-grained network abnormal behavior feature database, introducing a dynamic vaccine distribution mechanism to distribute detectors to all terminal nodes in the medical internal network, and using an artificial immune algorithm for anomaly detection, strict behavior monitoring is realized for each access, attack behavior is discovered, blocked and traced in a timely manner, and the above-mentioned technology can cope with the network security problems in the current medical network environment, make up for the disadvantages of traditional medical network security boundary protection, and maximize the protection of the safe storage of patient data and the safe operation of medical equipment and systems. BRIEF DESCRIPTION OF DRAWINGS
[0035] Figure 1 A schematic diagram of a security architecture based on boundary protection in an embodiment;
[0036] Figure 2 A flowchart of a zero-trust medical network security immune defense method in an embodiment;
[0037] Figure 3 A flowchart of the construction of an abnormal behavior feature database in an embodiment;
[0038] Figure 4 A schematic diagram of fine-grained classification in an embodiment;
[0039] Figure 5 A schematic diagram of the overall process of vaccine distribution in an embodiment;
[0040] Figure 6 A schematic diagram of uniform distribution of vaccines under normal circumstances in an embodiment;
[0041] Figure 7 A schematic diagram of dynamic distribution of vaccines under abnormal circumstances in an embodiment;
[0042] Figure 8 A schematic diagram of a time delay model in an embodiment;
[0043] Figure 9 A module tree diagram of a zero-trust medical network security immune defense system in an embodiment;
[0044] Figure 10 A schematic diagram of the functions of each layer of a zero-trust medical network security immune defense system in an embodiment;
[0045] Figure 11 Fig. 3 is a schematic diagram of a visualization interface in one embodiment;
[0046] Figure 12 Fig. 4 is an internal structure diagram of a computer device in one embodiment. DETAILED DESCRIPTION
[0047] For the purposes of the present application, the technical solutions and advantages thereof are more clearly apparent, the following will be further described in detail in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application, and are not used to limit the present application.
[0048] In one embodiment, as shown in Figure 2 , a zero-trust medical network security immune defense method is provided, which is described by taking a server in Figure 1 as an example, including the following steps:
[0049] S201: Constructing an abnormal behavior feature database based on an artificial immune system.
[0050] In the embodiments of the present application, first, the fine-grained behavior feature samples based on dynamic immune tolerance are studied by simulating the immune gene mutation mechanism, that is, the fine-grained abnormal behavior features are extracted from the network traffic by imitating the adaptive defense mechanism in the biological immune system. These features undergo cloning, mutation, and self-tolerance processes in the detector generation process to optimize the feature set and form network behavior detectors that can identify different attack types. By classifying and optimizing the features, a "vaccine" database containing fine-grained behavior features is constructed, which is continuously updated and used to detect new network threats.
[0051] Specifically, in one embodiment of the present application, the constructing an abnormal behavior feature database based on an artificial immune system includes:
[0052] S301: Randomly generating network abnormal behavior features, and screening in combination with a known network attack behavior dataset to obtain a fine-grained network abnormal behavior feature set.
[0053] S303: Performing mutation tolerance operation based on the fine-grained network abnormal behavior features to generate new network abnormal behavior features to expand the fine-grained network abnormal behavior feature set.
[0054] S305: Performing fine-grained classification on the new network abnormal behavior features by using a convolutional neural network to obtain an abnormal behavior feature database.
[0055] In one embodiment of the present application, as shown in Figure 3As shown, first, a feature set based on fine-grained medical network abnormal behavior classification is generated. A large number of network abnormal behavior features are randomly generated in the feature space, which are represented as:
[0056] F = {f1, f2, …, f n}
[0057] where each feature vector f i is a d-dimensional vector defined in the feature space R d , that is:
[0058] f i = [f i1 , f i2 , …, f id ]
[0059] These randomly generated feature vectors are a candidate set of abnormal feature behaviors for covering the entire feature space to ensure that different abnormal patterns can be captured. The generated feature vectors have sufficient diversity to meet the needs of fine-grained medical network abnormal behavior classification.
[0060] Screening is performed using a known network attack behavior dataset, which typically contains a variety of known attack patterns and their corresponding feature descriptions, reflecting different types of attack behavior features. Suppose the attack behavior feature set A = {a1, a2, …, a n} is matched with the randomly generated abnormal behavior feature set F, using the Euclidean distance as the metric, the Euclidean distance between any randomly generated behavior feature f i and attack behavior feature a i can be expressed as:
[0061]
[0062] If the distance dist(f i , a j ) < θ, (θ) is a specific threshold, then the feature f i can effectively detect the abnormal behavior a i . Therefore, the fine-grained network abnormal behavior feature set obtained after screening is:
[0063]
[0064] The F selected obtained after screening forms different feature subsets, and each subset contains features corresponding to different types of network attack behaviors. Let the feature set corresponding to each attack behavior a j be F j , that is:
[0065] F j= {f i ∈ F selected | d(f i , a j ) < θ}
[0066] In this way, different feature sets F j can be used to detect different network attack behaviors a j , forming a fine-grained network anomaly behavior feature cluster.
[0067] After that, the immune gene mutation mechanism is simulated, and the fine-grained medical network anomaly behavior features are subjected to mutation and tolerance operation. The purpose of the mutation operation is to make slight adjustments to the initial selected feature vectors, so as to explore the surrounding feature space and generate new features. Suppose the mutation operation is applied to a certain dimension f i of the feature vector f ik , the mutated feature f i ' can be represented as:
[0068] f ik ' = f ik + ∈ k
[0069] Where the random disturbance process can be realized by the noise parameter ∈ k ~ N(0, σ 2 ) generated by Gaussian distribution. Gaussian distribution describes the distribution of noise through its probability density function, and its formula is:
[0070]
[0071] Each dimension f ik will be added a random noise from Gaussian distribution, and since the mean of Gaussian distribution is 0, such mutation will not systematically deviate from the original feature. The amplitude of mutation is controlled by σ, if σ is small, the mutation will be relatively conservative, otherwise the disturbance amplitude of noise will be larger, and the generated features will be more diverse, exploring a wider feature space.
[0072] These new features can help the system capture new or unknown medical network anomaly behavior patterns, increasing the diversity and robustness of behavior features. After mutation operation, immune tolerance operation is performed. The Euclidean distance between the generated medical anomaly network behavior features and normal network behavior is calculated, and the anomaly feature vectors that can match the normal network behavior are eliminated to prevent them from making false judgments on the normal network behavior.
[0073] Afterwards, as the system continuously generates new abnormal behavior features of the medical network, it uses convolutional neural networks to perform fine-grained classification on these new features, and then builds an abnormal behavior feature database. n}, each eigenvector f i Its corresponding classification label y i Together they constitute a convolutional neural network training dataset, from which high-level feature representations are extracted to build a more general fine-grained classification model.
[0074] Specifically, in one embodiment of the present application, the fine-grained classification of the new network abnormal behavior features using a convolutional neural network includes:
[0075] S401: Constructing a fine-grained classification model based on a convolutional neural network, wherein the fine-grained classification model includes a feature extraction part and a fine-grained classification part.
[0076] S403: Performing model training based on the fine-grained network abnormal behavior feature set, and performing fine-grained classification on the new network abnormal behavior feature using the trained fine-grained classification model.
[0077] In one embodiment of the present application, Figure 4 As shown in Figure 1, first, a fine-grained classification model is constructed based on a convolutional neural network. The fine-grained classification model includes a feature extraction part and a fine-grained classification part. The structure of a convolutional neural network mainly includes an input layer, a convolution layer, a pooling layer, and a fully connected layer. Let the feature vector f i Is a d-dimensional vector, which will first undergo a convolution operation to extract local features through the filter. The formula for the convolution operation can be expressed as:
[0078]
[0079] in, represents the output of the i-th hidden unit in the l-th layer, σ represents the activation function ReLU, represents the weight connecting the kth input unit and the ith hidden unit in the lth layer, represents the output of the i-th unit in the l-1th layer, represents the bias term of the i-th hidden unit in the l-th layer.
[0080] This convolution operation extracts local features with high-level semantics from the original feature vector, capturing the correlations and changing trends between different dimensions. The output of the convolutional layer then passes through a pooling layer to reduce the feature dimensions, compress the data, and retain important features. The maximum pooling operation is used, and its formula is:
[0081] h i (l-1) = max(h i1 (l-1) ,h i2 (l-1) ,…,h im (l-1) )
[0082] The pooling layer further aggregates information and reduces the spatial dimension of features by selecting the maximum value within a local region. This can effectively avoid overfitting problems and speed up the calculation of the model. After multiple convolution and pooling operations, the features will be flattened into a vector and input into the fully connected layer. In the fully connected layer, the extracted high-level features are mapped to specific classification labels. The output of the fully connected layer can be represented as:
[0083] z = Wh + b
[0084] where W is the weight matrix of the fully connected layer, h is the output feature vector of the convolution and pooling layer, b is the bias vector of the fully connected layer, and z represents the final output of the network. Next, the softmax function is used to normalize the output to obtain the prediction probability of each class:
[0085]
[0086] where f i represents the given input, z c represents the score of class c, z c′ represents the score of class c', and C represents the total number of classes.
[0087] The cross-entropy loss function is used to measure the difference between the predicted result and the true label:
[0088]
[0089] where N represents the total number of samples, C represents the total number of classes, y ic represents the indicator variable of the true label of sample i belonging to class c, if sample i belongs to class c, then y ic = 1, otherwise y ic = 0, P(y = c | f i ) represents the probability that the model predicts it belongs to class c given the input f i .
[0090] This minimizes the difference between the predicted result and the true label, allowing the convolutional neural network to gradually learn the differences between different network behavior features and perform fine-grained classification on newly generated abnormal network behavior features.
[0091] Finally, after the new generated network anomaly behavior feature is classified by the convolutional neural network, the system will store the classification result into the anomaly behavior feature database. The database records the feature vectors of different types of network attack behaviors and their corresponding classification labels, and can be continuously updated. The core data stored in the database includes behavior feature d i , classification label y i , timestamp t i , after the new generated network anomaly behavior feature f i ' enters the convolutional neural network for fine-grained classification, the classification result y i ' is obtained, and the triplet: (f i ', y i ', t i ) is stored in the database.
[0092] When a new feature enters the system, the database can query the existing feature records and dynamically update them according to the feature similarity or timestamp. If a new feature vector f i ' has a similarity dist(f j , f i ) with the feature f j in the database less than a predetermined threshold θ, and its generation time t j is earlier, the existing record can be updated and the latest feature can be retained.
[0093] Through this mechanism, the anomaly behavior feature database can be continuously expanded as the system runs, containing more and more fine-grained network anomaly behavior features, and thus improving the recognition and response ability of the entire system to unknown attacks.
[0094] S203: dynamically adjusting the vaccine resources distributed by the central server to the sub-servers based on the anomaly behavior feature database and the Lagrange optimization method.
[0095] In the embodiments of the present application, the central server in the medical network system is responsible for managing the distribution of vaccines. Under normal circumstances, vaccines are evenly distributed to each sub-server according to the load state of the sub-server, ensuring that each sub-server has basic anomaly detection capability. When a sub-server detects an anomaly, the central server will dynamically adjust the vaccine distribution amount according to the anomaly, load status or bandwidth condition detected by the sub-server, and provide additional vaccine resources to the sub-server. On a macro scale, the Lagrange optimization method is used for global optimization to ensure that the system maximizes vaccine defense effectiveness and minimizes system resource consumption in the case of long-time operation. With the continuous update of the vaccine database, the central server will periodically redistribute the latest vaccines to all sub-servers to ensure that each sub-server can update its detection capability synchronously. This mechanism can effectively improve the defense level of the entire network system and ensure a rapid response to new attacks.
[0096] Specifically, in one embodiment of the present application, the dynamic adjustment of the vaccine resources distributed by the central server to the sub-servers based on the abnormal behavior feature database and the Lagrange optimization method includes:
[0097] S501: Perform preliminary vaccine resource distribution adjustment and update using a time delay function and an adaptive control factor.
[0098] S503: Construct a Lagrange function based on the constraint conditions, and solve the optimal vaccine distribution amount based on the Lagrange function, wherein the constraint conditions include total vaccine amount limit, sub-server load capacity, and network bandwidth limit.
[0099] In one embodiment of the present application, as shown in Figure 5 , first, a dynamic vaccine distribution model based on threat situation awareness is established. As shown in Figure 6 , the uniform distribution strategy under normal circumstances can ensure that the number of vaccines for each sub-server is relatively stable under normal conditions. At this time, the basic vaccine receiving amount of each sub-server S j can be represented as v j =v avg . That is: As shown in Figure 7 , under abnormal circumstances, dynamic adjustment is needed to ensure that the total amount of vaccines remains unchanged while providing more vaccine resources to the server that detects an anomaly. a k reflects the abnormality of the user behavior detected by the sub-server. When a k >1, it indicates that the server detects an anomaly, and the more serious the anomaly, the larger the value of a k . The new distribution amount v′ k can be represented as: v′ k =v avg ·a k .
[0100] To keep the total amount of vaccine distribution unchanged, the amount of vaccine distribution of other servers S j (j≠k) also needs to be adjusted according to a k new distribution amount v′ j is:
[0101]
[0102] A vaccine updating and synchronization mechanism based on time delay model is proposed. A time delay function T j (t) is introduced to represent the time distribution of the sub-server S j receiving new feature vaccines. The time delay function T j (t) is associated with the network environment of the sub-server, and the function is expressed as:
[0103]
[0104] Where λ j represents the load coefficient of the sub-server, γ represents the adjustment parameter, which controls the sensitivity of the time delay, load j represents the current load of the sub-server, distance j represents the network distance between the sub-server and the central server. As Figure 8 shown, the central server distributes new abnormal behavior features according to different time windows according to the time delay function results of each sub-server.
[0105] A dynamic distribution amount of updating vaccine is introduced to control the dynamic increase or decrease of the amount of vaccine distribution under certain conditions. A control factor β j (t) is defined:
[0106]
[0107] Where α j represents the abnormal detection sensitivity coefficient of the sub-server, anomaly j (t) represents the number of anomalies detected by the sub-server at time t, bandwidth j (t) represents the current bandwidth of the sub-server.
[0108] v′ j (t) = v j (t) · (1 + β j (t))
[0109] Through this formula, when the number of anomalies detected by a certain sub-server increases, the amount of vaccine distribution v j (t) will automatically increase to v′ j(t), and vice versa. A synchronization mechanism is established for the vaccine database and the vaccine set of the sub-server, and T j combined with the results of β j (t), the vaccine distribution time window and the distribution quantity of the sub-server are calculated to ensure that the sub-server can maintain the latest detection capability after the feature library is updated. The update mechanism can be represented by the following formula:
[0110] V j (t) = V j (t-1) U AV(t)
[0111] where V j (t) represents the vaccine set of the sub-server S j at time t, and AV(t) is the newly added vaccine set of the feature library at time t.
[0112] Then, a global optimization strategy for vaccine distribution based on the Lagrange multiplier method is proposed. Assuming that at time t, the number of anomalies detected by the sub-server S j is anomaly j (t), and the corresponding vaccine distribution quantity is v′ j (t). The optimization objective function can be represented as:
[0113]
[0114] M is the total number of sub-servers, and log(v′ j (t)) ensures that the objective function increases when the vaccine distribution quantity increases, while avoiding numerical instability caused by maximum or minimum values.
[0115] The constraint conditions include total vaccine quantity limit, sub-server load capacity, network bandwidth limit, etc. The Lagrange function is constructed combined with the constraint conditions to ensure global optimization during the optimization process. Combined with the objective function and the constraint conditions in actual operation, the Lagrange function L is constructed as:
[0116]
[0117] where λ is the Lagrange multiplier, representing the influence of the constraint condition on the objective function. The partial derivative of the constraint condition is solved as:
[0118]
[0119] Solving the two equations together can obtain the optimal vaccine distribution quantity v′ j (t) and the Lagrange multiplier λ. v′ j(t) can be used for rational distribution of vaccines, maximizing anomaly detection capability; while lambda can be used to evaluate the degree of influence of the constraints, providing the basis for subsequent adjustment.
[0120] S205: Based on the vaccine resources, the attack detection rules of the firewall are optimized by combining the artificial immune algorithm, and the network attack defense is performed by using the attack detection rules.
[0121] In the embodiments of the present application, by combining the artificial immune algorithm, the attack detection rules of the firewall are optimized based on the vaccine distribution mechanism, so that the firewall can generate, optimize and distribute rules in real time, so as to effectively detect known and unknown attacks.
[0122] Specifically, in one embodiment of the present application, the optimization of the attack detection rules of the firewall based on the vaccine resources by combining the artificial immune algorithm comprises:
[0123] S601: Generating preliminary attack detection rules based on the clone selection algorithm.
[0124] S603: Further optimizing the rule base based on the preliminary attack detection rules by using the negative selection algorithm.
[0125] In one embodiment of the present application, first, the firewall generates preliminary attack detection rules by the clone selection algorithm. In the clone selection algorithm, each feature vector of network traffic is regarded as an "antibody". These feature vectors generate rules through fitness evaluation. The fitness evaluation is usually based on the difference between the traffic features and the normal traffic, and is calculated by using a fitness function in the form of:
[0126]
[0127] Where y is the feature vector of the rule, x normal is the feature vector of the normal traffic, ‖y-x normal ‖ 2 is the Euclidean distance, which measures the difference between the rule and the normal behavior. The fitness function measures the effectiveness of the rule, and the rule with higher fitness can better distinguish between normal traffic and attack behavior. The clone selection algorithm generates copies of rules with high fitness through the cloning process, and explores new attack patterns through mutation operations. The mutated rules are generated by the following formula:
[0128] y clone = y + δy
[0129] Where δy represents the change generated by random variation. In this way, the firewall can generate multiple potential rules through cloning and mutation, thereby enhancing the attack detection capability.
[0130] After that, the rule base is further optimized using the negative selection algorithm. The negative selection algorithm is used to exclude rules similar to normal traffic to avoid false positives. The negative selection algorithm identifies attack patterns by calculating a difference metric between attack behavior and normal traffic. If the characteristics of the attack sample are similar to the characteristics of normal traffic, the generated rule will be excluded. The difference metric formula is:
[0131] D(x attack ,x normal ) = ‖x attack -x normal ‖
[0132] If the distance D(x attack ,x normal ) is less than a certain threshold ∈, it is considered that the attack pattern is too similar to normal behavior, and the rule will be excluded. Through this mechanism, the negative selection algorithm ensures the simplicity and efficiency of the rule base, reducing redundant rules.
[0133] Once the rules are generated and optimized, the firewall distributes the new rules to all firewall nodes through the vaccine distribution mechanism. Whenever the firewall generates new rules, these rules are pushed as "vaccines" to each firewall node in the distributed system. These newly generated rules are integrated into the node's rule base, enabling each firewall node to perform efficient attack detection locally. Through this vaccine distribution mechanism, the firewall can ensure that each node always maintains the latest rule set, maintaining consistent defense capabilities. Assuming the new rule set is R new = {r1, r2, …, r k}, the local rule base R N of node N will be updated to:
[0134] R N,new = R N ∪R new
[0135] To cope with the continuous evolution of network attack patterns, the firewall must have the ability of adaptive optimization. Whenever a new attack pattern appears, the firewall generates new rules through the incremental learning mechanism and adds them to the rule base. In addition, the firewall will also periodically optimize and de-duplicate existing rules to ensure that the rule base always remains optimal. The update of the rule base is optimized through the following objective function:
[0136]
[0137] where α and β are the weighted coefficients of false positive rate and false negative rate, and R is the rule base. The firewall continuously updates and optimizes the rule base to ensure that it can quickly identify and defend against new attack types.
[0138] By combining the clone selection algorithm, the negative selection algorithm and the vaccine distribution mechanism, the firewall designed by the application can not only intelligently generate and optimize attack detection rules, but also maintain efficient protection against new attacks through dynamic updating and real-time synchronization of rules. Through the coordinated work of these technologies, the firewall can flexibly cope with various network attacks in the distributed environment of the medical network, ensuring the security and stability of the medical network system.
[0139] In an embodiment of the present application, the network attack defense using the attack detection rules comprises:
[0140] Calculating the similarity between the traffic and the attack detection rules to determine whether the traffic conforms to the attack characteristics.
[0141] In an embodiment of the present application, when new traffic arrives at the firewall, the firewall will perform real-time matching according to the rules in the rule library to determine whether the traffic conforms to the attack characteristics. The similarity between the traffic and the rules is calculated by the Euclidean distance:
[0142] D(x flow ,r i )=‖x flow -r i ‖
[0143] Where x flow represents the feature vector of network traffic, and r i represents the feature vector of the i-th rule. If the traffic characteristics match a certain rule, the firewall will execute the corresponding protection measures, such as discarding data packets, recording logs or sending alarms. This process relies on an efficient rule matching algorithm to ensure that the firewall can respond in real time in a high-concurrency and high-traffic network environment.
[0144] In the above-mentioned zero-trust medical network security immune defense method, first, an abnormal behavior feature database is constructed based on an artificial immune system; then, the vaccine resources distributed by the central server to the sub-servers are dynamically adjusted based on the abnormal behavior feature database combined with the Lagrange optimization method; finally, the attack detection rules of the firewall are optimized based on the vaccine resources combined with the artificial immune algorithm, and the network attack defense is performed using the attack detection rules. That is, by constructing a fine-grained network abnormal behavior feature database, introducing a dynamic vaccine distribution mechanism to distribute detectors to all terminal nodes in the medical internal network, and using an artificial immune algorithm for anomaly detection, strict behavior monitoring is realized for each access, attack behavior is discovered, blocked and traced in a timely manner, and the above-mentioned technologies can cope with the network security problems in the current medical network environment, make up for the disadvantages of traditional medical network security boundary protection, and maximize the protection of the safe storage of patient data and the safe operation of medical equipment and systems.
[0145] It should be understood that although each step in the flowchart involved in each embodiment as described above is shown in sequence according to the direction of the arrow, these steps are not necessarily executed in the order indicated by the arrow. Unless explicitly stated herein, there is no strict order limitation for the execution of these steps, and these steps can be executed in other orders. Moreover, at least part of the steps in the flowchart involved in each embodiment as described above can include multiple steps or multiple stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily sequential, but can be alternately executed with at least part of other steps or steps or stages in other steps.
[0146] Based on the same inventive concept, the embodiments of the present application also provide a zero-trust medical network security immune defense system for implementing the above-mentioned zero-trust medical network security immune defense method. The problem-solving implementation scheme provided by the system is similar to the implementation scheme described in the above method, so the specific limitations in one or more zero-trust medical network security immune defense system embodiments provided below can refer to the limitations of the zero-trust medical network security immune defense method described above, which will not be repeated here.
[0147] In one embodiment, as shown in Figure 9 a zero-trust medical network security immune defense system is provided, comprising: a database construction module, a software initialization module, a data acquisition and preprocessing module, a vaccine distribution and synchronization module, an abnormality tracing and processing module, and a visualization display module, wherein:
[0148] The database construction module is configured to generate a set of medical network attack behavior characteristics and construct a behavior characteristic database.
[0149] The software initialization module is configured to use the existing integrated network management system of the hospital to read the network topology structure and real-time device status of the hospital.
[0150] The data acquisition and preprocessing module is configured to import a real-time device status database and continuously monitor and update the device status in combination with the distributed vaccine.
[0151] The vaccine distribution and synchronization module is configured to dynamically adjust and distribute the vaccine.
[0152] The abnormality tracing and processing module is configured to analyze abnormal behavior, find the source of the abnormality, and block related connections.
[0153] The visualization display module is configured to visually display the system status and security risks.
[0154] In an embodiment of the present application, the system architecture is divided into a core data construction layer, a data transmission layer, a data processing layer, a core algorithm application layer, and a human-computer interaction layer, and the functions of each layer are as shown in Figure 10 The system is based on a zero trust architecture, selects Python as the system development language, pytorch as the selected algorithm training framework, and calls multiple auxiliary development libraries such as Numpy and MySQLdb. The system design architecture is divided into the following modules:
[0155] (1) Database construction module: This module generates a medical network attack behavior feature set through the basic steps of the core data construction layer, uses a convolutional neural network for fine-grained division, and further constructs a behavior feature database for subsequent detection comparison.
[0156] (2) Software initialization module: This module uses the existing integrated network management system of the hospital to read the network topology structure and real-time device status of the hospital, and stores them in the local database after refinement, so as to be displayed on the human-computer interaction interface for subsequent centralized display.
[0157] (3) Data acquisition and preprocessing module: This module continuously monitors and updates the device status by importing the real-time device status database in combination with the distributed vaccines, wherein the detector comes from the vaccine distribution and synchronization block, and the detection result will also be retransmitted to this block.
[0158] (4) Vaccine distribution and synchronization module: This module uniformly distributes vaccines under normal circumstances, performs real-time detection on the sub-servers, dynamically adjusts if abnormal behavior is found, and transmits the detected abnormal behavior to the abnormal source tracing and processing block for further processing. In addition, this module also continuously updates and synchronizes the feature set of the central server and the sub-servers.
[0159] (5) Abnormal source tracing and processing module: This module further analyzes the abnormal behavior transmitted by the vaccine distribution module, finds the abnormal source, and filters the source with this behavior feature by the firewall, and blocks all related connections.
[0160] (6) Visual display module: This module visually displays the system status and security risks in the form of text and charts, dynamically displays attack behavior data, draws a source tracing diagram through the abnormal source tracing block, displays abnormal behavior and its source, and forms a visual result, as shown in Figure 11
[0161] In an embodiment, a computer device is provided, which can be a terminal, and the internal structure diagram thereof can be as shown in Figure 12 As shown in the figure. The computer device includes a processor, a memory, a communication interface, a display screen and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used for wired or wireless communication with external terminals. Wireless communication can be achieved through WIFI, mobile cellular network, NFC (near field communication) or other technologies. The computer program is executed by the processor to implement a zero-trust medical network security immune defense method. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer overlaid on the display screen, or a key, trackball or touchpad arranged on the shell of the computer device, or an external keyboard, touchpad or mouse, etc.
[0162] Those skilled in the art can understand that, Figure 12 The structure shown in the figure is only a block diagram of part of the structure related to the scheme of the present application, and does not constitute a limitation on the computer device to which the scheme of the present application is applied. A specific computer device can include more or fewer components than those shown in the figure, or combine certain components, or have a different component arrangement.
[0163] In one embodiment, a computer device is provided, including a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the steps in the above method embodiments.
[0164] In one embodiment, a computer readable storage medium is provided, which stores a computer program, and the computer program is executed by a processor to implement the steps in the above method embodiments.
[0165] In one embodiment, a computer program product is provided, including a computer program, and the computer program is executed by a processor to implement the steps in the above method embodiments.
[0166] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties.
[0167] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer readable storage medium, and when the computer program is executed, the processes of the above-mentioned embodiments of the methods can be included. Any reference to memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (Read-Only Memory, ROM), magnetic tape, floppy disk, flash memory, optical storage, high-density embedded non-volatile memory, resistive memory (ReRAM), magnetoresistive random access memory (Magnetoresistive Random Access Memory, MRAM), ferroelectric memory (Ferroelectric Random Access Memory, FRAM), phase change memory (Phase Change Memory, PCM), graphene memory, etc. Volatile memory can include random access memory (Random Access Memory, RAM) or external cache memory, etc. As an illustration but not limitation, RAM can be in various forms, such as static random access memory (Static Random Access Memory, SRAM) or dynamic random access memory (Dynamic Random Access Memory, DRAM), etc. The database involved in the embodiments provided in the present application can include at least one of a relational database and a non-relational database. The non-relational database can include a distributed database based on a block chain, etc., without being limited thereto. The processor involved in the embodiments provided in the present application can be a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., without being limited thereto.
[0168] Any combination of the technical features of the above embodiments can be made. In order to make the description simple, all possible combinations of the technical features in the above embodiments are not described, however, as long as the combination of the technical features does not exist contradictory, it should be considered as the scope of the present application.
[0169] The above embodiments only express several implementation manners of the present application, and the description is more specific and detailed, but it should not be understood as a limitation on the scope of the patent of the present application. It should be pointed out that for ordinary skilled in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are within the scope of protection of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. A zero-trust medical network security immune defense method, characterized in that, The method comprises: constructing an abnormal behavior feature database based on an artificial immune system; dynamically adjusting vaccine resources distributed by a central server to a sub-server based on the abnormal behavior feature database and a Lagrange optimization method; optimizing attack detection rules of a firewall based on the vaccine resources and an artificial immune algorithm, and performing network attack defense using the attack detection rules; the method comprises: randomly generating network abnormal behavior features, and screening known network attack behavior data sets to obtain a fine-grained network abnormal behavior feature set; performing mutation tolerance operation based on the fine-grained network abnormal behavior features to generate new network abnormal behavior features and expand the fine-grained network abnormal behavior feature set; performing fine-grained classification on the new network abnormal behavior features using a convolutional neural network to obtain an abnormal behavior feature database; the method comprises: performing preliminary vaccine resource distribution adjustment and update using a time delay function and an adaptive control factor; constructing a Lagrange function based on constraint conditions, solving an optimal vaccine distribution amount based on the Lagrange function, and the constraint conditions include total vaccine amount limit, sub-server load capacity, and network bandwidth limit; defining a time delay function sub-server time distribution of receipt of new feature vaccines; time delay function associated with the network environment of the sub-server, the function is represented as: in, Indicates the load factor of the sub-server, Indicates the adjustment parameters to control the sensitivity of time delay, Indicates the current load of the sub-server, Represents the network distance between the sub-server and the central server; the central server distributes new abnormal behavior features according to different time windows based on the time delay function results of each sub-server; Defining a control factor : wherein, represents the anomaly detection sensitivity coefficient of the sub-server, represents the number of anomalies detected by the sub-server at the current time, represents the current bandwidth of the sub-server; The amount of vaccine distribution of a sub-server when the number of detected anomalies increases Will be automatically increased to ; Establish a synchronization mechanism for the vaccine database and the sub-server vaccine set, and Combined with the results of , the vaccine distribution time window and the distribution amount of the sub-server are calculated to ensure that the sub-server can maintain the latest detection capability after the feature library is updated; The update mechanism can be represented by the following formula: wherein, representing a sub-server at a time a set of vaccines at a time, is a set of new vaccines added to the feature library at a time; is a set of new vaccines added to the feature library at a time; After that, a global optimization strategy of vaccine distribution based on Lagrange multiplier method is proposed. It is assumed that the number of abnormality detected by the sub-server is at time , and the corresponding vaccine distribution is . The optimization objective function can be expressed as: is the total number of sub-servers, It ensures that the objective function exhibits an increasing property when the vaccine distribution amount increases, while avoiding numerical instability caused by maximum or minimum values. A Lagrange function is constructed combining the objective function and the constraints in actual operation is: wherein, is a Lagrange multiplier representing the effect of the constraint on the objective function; is the total vaccine quantity; the method comprises: generating preliminary attack detection rules based on a clone selection algorithm; further optimizing the rule base using a negative selection algorithm based on the preliminary attack detection rules.
2. The zero trust cyber security immune defense method for a medical network according to claim 1, wherein, the method comprises: constructing a fine-grained classification model based on a convolutional neural network, the fine-grained classification model includes a feature extraction part and a fine-grained classification part; training the model based on the fine-grained network abnormal behavior feature set, and performing fine-grained classification on the new network abnormal behavior features using the trained fine-grained classification model.
3. The zero trust cyber security immune defense method for a medical network of claim 1, wherein, the method comprises: calculating the similarity between traffic and the attack detection rules to determine whether the traffic meets the attack characteristics.
4. A system for implementing the zero-trust medical network security immune defense method according to claim 1, characterized in that: It comprises: a database construction module for generating a medical network attack behavior feature set and constructing a behavior feature database; a software initialization module for reading the network topology structure and real-time device status of a hospital using an existing integrated network management system of the hospital; a data acquisition and preprocessing module for importing a real-time device status database and continuously monitoring and updating the device status in combination with distributed vaccines; a vaccine distribution and synchronization module for dynamically adjusting and distributing vaccines; an abnormal source tracing and processing module for analyzing abnormal behavior, finding abnormal sources, and blocking related connections; a visual display module for visually displaying system status and security risks. 5.A computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the computer device is configured to perform the method according to any one of claims 1-4 when the computer program is executed by the processor. The processor executes the computer program to realize the steps of the method of any one of claims 1 to 3.
6. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to realize the steps of the method of any one of claims 1 to 3.
Citation Information
Patent Citations
Mobile sensor network clustering method based on immune algorithm
CN102244892A
Method for dynamically detecting network anomaly in real time based on immunization
CN102638466A