Medical credential network security detection method and device, equipment and medium
By building a medical security corpus and a secure access management architecture, combining the linkage between security components and security platforms, the problem of low network security protection efficiency in medical information innovation environments is solved, efficient threat detection and response are achieved, and security protection efficiency is improved.
Patent Information
- Application Number
- CN202510600956.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-12
- Publication Date
- 2025-06-10
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing network security protection solutions are inefficient in the medical information innovation environment, and it is difficult to cope with the security operation needs of complex and changeable medical business systems. They also consume a large resource and have a high bandwidth proportion, which affects the normal operation of the medical information system.
The medical information innovation network security detection method is adopted, including building a medical security corpus and training a medical information innovation network security detection large language model, building a secure access management architecture, deploying security components to link with the security platform, and conducting network security detection and protection in real time.
It improves the threat detection and response efficiency of the medical information innovation network, shortens the average threat detection time and average threat response time, improves the security protection efficiency of the medical information innovation platform, and achieves all-round security protection for the medical information innovation environment.
Smart Images

Figure CN120128428A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of artificial intelligence technology, and in particular to a medical information and communication technology (ICT) network security detection method, device, equipment and medium. Background Art
[0002] Existing network security protection solutions have many deficiencies and are difficult to meet the security operation requirements of complex and changeable medical business systems.
[0003] On the one hand, traditional threat detection and response mechanisms are inefficient, with relatively long average threat detection time and average threat response time, and limited defense capabilities; on the other hand, these mechanisms often consume a large amount of resources and occupy a high bandwidth, which has a certain impact on the normal operation of medical information systems.
[0004] In view of the above problems, there is an urgent need for an efficient and intelligent network security protection solution to improve the threat detection and response efficiency in the medical ICT environment, shorten the average threat detection time and average threat response time, thereby improving the security protection efficiency of the medical ICT platform. At the same time, this solution should also be able to achieve all-round security protection for the medical ICT environment and ensure the secure operation of complex and changeable medical business systems. Summary of the Invention
[0005] In view of the above, it is necessary to provide a medical ICT network security detection method, device, equipment and medium, which can solve the problems of low efficiency and weak protection of medical ICT network security.
[0006] A medical ICT network security detection method, the medical ICT network security detection method includes: In response to a security detection instruction for the medical ICT network, constructing a medical security corpus and training a large language model for medical ICT network security detection based on the medical security corpus; Constructing a security access management architecture; Using the large language model for medical ICT network security detection and the security access management architecture to perform real-time network security detection on the medical ICT network to obtain detection data; Deploying security components, docking the security components to a security platform, and using the security components to upload the detection data to the security platform; Using the security components to receive the abnormal response strategy feedback by the security platform; Performing security protection on the medical ICT network based on the abnormal response strategy.
[0007] According to a preferred embodiment of the present invention, the constructing a medical security corpus and training a large language model for medical ICT network security detection based on the medical security corpus includes: Obtain a Transformer model architecture based on the attention mechanism as the initial network; Obtain multi-dimensional network monitoring subtasks and obtain the training set for each network monitoring subtask; Use the training set of each network monitoring subtask to perform multi-task joint pre-training on the initial network to obtain a main model that integrates various network monitoring capabilities; Collect network data in the Xinchuang cloud environment to which the medical Xinchuang network belongs to construct the medical security corpus; Perform continuous pre-training on the main model based on the medical security corpus to obtain a pre-trained model with medical scenario semantic understanding capabilities; Parse the security detection instruction to obtain a fine-tuning task, and collect data from the medical Xinchuang network to construct a training sample; Fine-tune the pre-trained model based on the fine-tuning task and the training sample to obtain the large language model for medical Xinchuang network security detection.
[0008] According to a preferred embodiment of the present invention, the construction of the security access management architecture includes: Deploy a threat detection engine based on behavior analysis and machine learning on the terminal side; wherein, the threat detection engine identifies persistent unknown threats based on abnormal behavior patterns through correlation analysis of multi-dimensional behaviors; Deploy a traffic analysis engine at the network boundary; wherein, the traffic analysis engine is used to perform in-depth parsing and correlation analysis on network session traffic, and identify various network attack behaviors in combination with machine learning algorithms and threat intelligence; Deploy a big data analysis platform in the cloud; wherein, the big data analysis platform is used to analyze and mine long-term accumulated security data to identify the change trend of the attack surface, and support security event traceability and unknown threat detection.
[0009] According to a preferred embodiment of the present invention, the deployment of security components includes: Deploy mobile security components, terminal security components, secure access service edge components, network access security components, application security components, big data security components, cloud security components and workload security components as the security components; Among them, the mobile security component includes a zero-trust client, unified user terminal management, and SDK application security reinforcement; the terminal security component includes unified terminal security, integrated terminal data leakage prevention, integrated zero-trust client, and integrated terminal injection control; the secure access service edge component includes Internet application access security, data center application access security, and branch secure access; the network access security component includes integrated comprehensive Internet behavior management, next-generation firewall, NDR advanced threat monitoring, SDP trusted access gateway, and SD-WAN security gateway; the application security component includes Web application firewall, RSAP application adaptive security, and API security gateway; the big data security component is used to protect the security of big data throughout its life cycle; the cloud security component includes CSPM multi-cloud security management and CSSP security resource pool; the workload security component includes CWPP cloud workload protection and container security protection.
[0010] According to a preferred embodiment of the present invention, after docking the security components to the security platform, the method further includes: Using the security components to upload the collected telemetry data to the security platform, and uploading the data reported by the cloud security service platform to the security platform, so that the security platform can analyze the received data and generate the abnormal response strategy.
[0011] According to a preferred embodiment of the present invention, after deploying the security components, the method further includes: Docking the security components to the cloud security service platform, so that the cloud security service platform reports data to the security components; Among them, the cloud security service platform is used to collect and analyze the latest threat intelligence, optimize the protection strategy of the security components according to the latest attack means and protection strategies, and update the detection rule library of the security components according to the latest vulnerability information and attack characteristics.
[0012] According to a preferred embodiment of the present invention, after performing security protection on the medical IT network based on the abnormal response strategy, the method further includes: Obtaining the security protection result and the feedback data on the security protection result; Optimizing the medical IT network security detection large language model according to the security protection result and the feedback data.
[0013] A medical IT network security detection device, the medical IT network security detection device includes: A training unit, configured to respond to a security detection instruction for a medical IT network, construct a medical security corpus, and train a medical IT network security detection large language model based on the medical security corpus; A building unit for building a secure access management architecture; A detection unit for performing real-time network security detection on the medical IT network by using the medical IT network security detection large language model and the secure access management architecture to obtain detection data; A deployment unit for deploying security components, docking the security components to a security platform, and uploading the detection data to the security platform by using the security components; A receiving unit for receiving an exception response policy feedback by the security platform by using the security components; A protection unit for performing security protection on the medical IT network based on the exception response policy.
[0014] A computer device, which includes: A memory storing at least one instruction; and A processor for executing the instruction stored in the memory to implement the medical IT network security detection method.
[0015] A computer-readable storage medium storing at least one instruction, and the at least one instruction is executed by a processor in a computer device to implement the medical IT network security detection method.
[0016] It can be seen from the above technical solutions that the present invention can perform real-time network security detection on the medical IT network by using the medical IT network security detection large language model and the secure access management architecture. Based on the large language model, it can improve the in-depth understanding and professional judgment ability of medical security sub-scenarios. Based on the secure access management architecture, it can improve the accuracy of attack judgment, and achieve a high detection rate and a low false alarm rate for various types of scenario threats; use security components to upload detection data to the security platform, and use security components to receive the exception response policy feedback by the security platform to perform security protection on the medical IT network, and can achieve a security protection effect of 1+1>2 through the linkage between the security components and the security platform. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 is a flowchart of a preferred embodiment of the medical IT network security detection method of the present invention; Figure 2 is a functional module diagram of a preferred embodiment of the medical IT network security detection device of the present invention; Figure 3 is a schematic structural diagram of a computer device of a preferred embodiment for implementing the medical IT network security detection method of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0018] To make the objectives, technical solutions, and advantages of the present invention more clear, the present invention will be described in detail below with reference to the accompanying drawings and specific embodiments.
[0019] As Figure 1 shown, it is a flowchart of a preferred embodiment of the medical information and communication technology (ICT) network security detection method of the present invention. According to different requirements, the order of steps in this flowchart can be changed, and some steps can be omitted.
[0020] The medical ICT network security detection method is applied to one or more computer devices. The computer device is a device that can automatically perform numerical calculations and / or information processing according to pre-set or stored instructions. Its hardware includes, but is not limited to, a microprocessor, an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), a digital signal processor (DSP), an embedded device, etc.
[0021] The computer device can be any electronic product that can interact with a user, such as a personal computer, a tablet computer, a smart phone, a personal digital assistant (PDA), a game console, an Internet protocol television (IPTV), a smart wearable device, etc.
[0022] The computer device can also include a network device and / or a user device. Among them, the network device includes, but is not limited to, a single network server, a server group composed of multiple network servers, or a cloud composed of a large number of hosts or network servers based on cloud computing.
[0023] The server can be an independent server or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms.
[0024] Among them, artificial intelligence (AI) is a theory, method, technology, and application system that uses a digital computer or a machine controlled by a digital computer to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use knowledge to obtain the best results.
[0025] The basic technologies of artificial intelligence generally include technologies such as sensors, dedicated artificial intelligence chips, cloud computing, distributed storage, big data processing technologies, operation / interaction systems, and mechatronics. The software technologies of artificial intelligence mainly include several major directions such as computer vision technology, robotics, biometric technology, speech processing technology, natural language processing technology, and machine learning / deep learning.
[0026] The network where the computer device is located includes but is not limited to the Internet, wide area network, metropolitan area network, local area network, virtual private network (VPN), etc.
[0027] S10, in response to a security detection instruction for the medical information technology innovation network, construct a medical security corpus, and train a large language model for medical information technology innovation network security detection based on the medical security corpus.
[0028] In this embodiment, the medical information technology innovation network refers to a network system that applies the concepts and technologies of information technology innovation (IT innovation) to the medical industry. Its purpose is to build a secure, reliable, and efficient medical network environment through self-developed information technology products and solutions to meet the informatization needs of the medical industry, while ensuring the security of medical data and the stable operation of medical services.
[0029] In this embodiment, the security detection instruction can be automatically triggered when the medical information technology innovation network is put into use to achieve comprehensive protection of the medical information technology innovation network.
[0030] In this embodiment, the constructing a medical security corpus and training a large language model for medical information technology innovation network security detection based on the medical security corpus includes: Obtain a Transformer model architecture based on the attention mechanism as the initial network; Obtain multi-dimensional network monitoring subtasks, and obtain the training set for each network monitoring subtask; Use the training set of each network monitoring subtask to perform multi-task joint pre-training on the initial network to obtain a main model that integrates various network monitoring capabilities; Collect network data in the IT innovation cloud environment to which the medical information technology innovation network belongs to construct the medical security corpus; Perform continuous pre-training on the main model based on the medical security corpus to obtain a pre-trained model with the ability to understand medical scenario semantics; Parse the security detection instruction to obtain a fine-tuning task, and collect data from the medical information technology innovation network to construct a training sample; Perform fine-tuning on the pre-trained model based on the fine-tuning task and the training sample to obtain the large language model for medical information technology innovation network security detection.
[0031] Among them, the multi-dimensional network monitoring subtasks may include, but are not limited to: network detection subtasks, security judgment subtasks, threat hunting subtasks, threat response subtasks, etc.
[0032] In the above embodiment, joint pre-training can be first performed according to the training sets corresponding to each subtask to obtain a main model integrating various security task capabilities; then, a high-quality medical security corpus can be constructed using data such as security logs, threat intelligence, and security incident reports in the Xinchuang cloud environment, and the security main model can be continuously pre-trained based on this corpus to enable it to have semantic understanding capabilities in medical scenarios, expanding the context understanding capabilities of medical scenarios based on natural language interaction; finally, corresponding fine-tuning tasks and data sets can be designed for different medical security scenarios to fine-tune the medical security large model, thereby endowing it with professional capabilities in specific scenarios, and thus creating in-depth understanding and professional judgment capabilities for medical security sub-scenarios such as attack sample detection, vulnerability judgment, analysis and disposal, etc.
[0033] S11. Construct a security access management architecture.
[0034] In this embodiment, the construction of the security access management architecture includes: (1) Deploy a threat detection engine based on behavior analysis and machine learning on the terminal side; among them, the threat detection engine identifies persistent unknown threats based on abnormal behavior patterns through correlative analysis of multi-dimensional behaviors; For example: the threat detection engine identifies abnormal behavior patterns through correlative analysis of multi-dimensional behaviors such as processes, files, and networks on the terminal side, thereby discovering unknown threats such as Advanced Persistent Threat (APT); Through the above embodiment, it is possible to improve the accuracy of attack judgment and effectively resist known and unknown advanced threat attacks based on the terminal-side advanced threat detection and response technology with strong correlative analysis of the real medical Xinchuang environment context; (2) Deploy a traffic analysis engine at the network boundary; among them, the traffic analysis engine is used to deeply analyze and correlate network session traffic, and identify various network attack behaviors in combination with machine learning algorithms and threat intelligence; Through the above embodiment, it is possible to achieve a high detection rate and a low false alarm rate for threats in multiple scenarios based on the network-side deep threat detection technology of global analysis and backtracking correlation of network session traffic; (3) Deploy a big data analysis platform in the cloud; among them, the big data analysis platform is used to analyze and mine the long-term accumulated security data to identify the changing trend of the attack surface, and support security event tracing and unknown threat detection; Through the above embodiments, it is possible to realize the review of security incidents and the APT custom detection ability based on the cloud attack surface judgment technology with a wide time dimension.
[0035] S12. Use the medical information technology innovation network security detection large language model and the security access management architecture to perform real-time network security detection on the medical information technology innovation network, and obtain detection data.
[0036] In the above embodiments, simultaneously using the medical information technology innovation network security detection large language model and the security access management architecture to perform real-time network security detection on the medical information technology innovation network can effectively improve the network security detection performance.
[0037] S13. Deploy security components, dock the security components to a security platform, and use the security components to upload the detection data to the security platform.
[0038] In this embodiment, the deployment of security components includes: Deploy mobile security components, terminal security components, secure access service edge components, network access security components, application security components, big data security components, cloud security components, and workload security components as the security components; Among them, the mobile security component includes a zero-trust client, unified user terminal management, and SDK (Software Development Kit) application security reinforcement; among them, the zero-trust client is used to perform identity authentication of mobile terminals and context-based dynamic access control; the unified user terminal management is used to perform unified management, policy distribution, and compliance check on mobile terminals; the SDK application security reinforcement is used to enhance the security of mobile applications; Among them, the terminal security component includes unified terminal security, integrated terminal data leakage prevention, integrated zero-trust client, and integrated terminal injection control; among them, the unified terminal security is used to perform host anti-virus, vulnerability management, and baseline check; the integrated terminal data leakage prevention is used to prevent sensitive data leakage; the integrated zero-trust client is used to perform identity authentication of terminals and context-based dynamic access control; the integrated terminal injection control is used to detect and prevent malicious code injection attacks; Among them, the secure access service edge component includes Internet application access security, data center application access security, and branch secure access; among them, the Internet application access security is used to provide a secure and reliable access path for Internet applications; the data center application access security is used to provide a secure and reliable access path for data center applications; the branch secure access is used to provide a secure and reliable network access capability for branches; Among them, the network access security components include integrated comprehensive Internet behavior management, next-generation firewall, NDR (Network Detection and Response) advanced threat monitoring, SDP (Software-Defined Perimeter) trusted access gateway, and SD-WAN (Software-Defined Wide Area Network) security gateway; among them, the integrated comprehensive Internet behavior management is used to control Internet behavior; the next-generation firewall is used to perform intrusion prevention, virus prevention, and application identification; the NDR advanced threat monitoring is used to detect advanced persistent threats; the SDP trusted access gateway is used to perform identity authentication and access control on access devices; the SD-WAN security gateway is used to provide a secure and reliable network access for branch offices; Among them, the application security components include Web application firewall, RSAP (Runtime Application Self-Protection) application adaptive security, and API (Application Programming Interface) security gateway; among them, the Web application firewall is used to protect the security of Web applications; the RSAP application adaptive security is used to provide application layer protection capabilities; the API security gateway is used to protect the security of API interfaces; Among them, the big data security component is used to protect the security of big data throughout its life cycle; Among them, the cloud security components include CSPM (Cloud Security Posture Management) multi-cloud security management and CSSP (Cloud Security Service Platform) security resource pool; among them, the CSPM multi-cloud security management is used to manage and monitor the security status of multi-cloud environments; the CSSP security resource pool is used to provide security capabilities for cloud-based services; Among them, the workload security components include CWPP (Cloud Workload Protection Platform) cloud workload protection and container security protection; among them, the CWPP cloud workload protection is used to provide security protection for cloud hosts; the container security protection is used to provide security capabilities for container workloads.
[0039] Through the above embodiments, a full range of security components can be deployed to achieve comprehensive protection of the medical IT network.
[0040] In this embodiment, the security component is connected to the security platform to achieve linkage protection between the two.
[0041] In this embodiment, after the security component is connected to the security platform, the method further includes: The security component is used to upload the collected telemetry data to the security platform, and the data reported by the cloud security service platform is uploaded to the security platform, so that the security platform can analyze the received data and generate the abnormal response strategy.
[0042] The telemetry data may include, but is not limited to, a combination of one or more of the following data: Security events, threat intelligence, log data, etc. collected by each security component.
[0043] Among them, the security platform can analyze and judge based on the received telemetry data to formulate a response and disposal strategy, and send the strategy to the corresponding security components for execution.
[0044] Through the above embodiments, the security component and the security platform achieve a "1+1>2" security protection effect through linkage. The security component and the security platform achieve end-network-cloud comprehensive collaborative protection through data sharing and policy linkage, thereby improving the overall security protection capability.
[0045] In this embodiment, after the security component is deployed, the method further includes: Connecting the security component to the cloud security service platform so that the cloud security service platform reports data to the security component; Among them, the cloud security service platform is used to collect and analyze the latest threat intelligence, optimize the protection strategy of the security component according to the latest attack methods and protection strategies, and update the detection rule library of the security component according to the latest vulnerability information and attack characteristics.
[0046] In the above embodiment, the cloud security service platform reports the latest threat intelligence collected and analyzed to the security component, so that the security component can promptly discover and defend against new threats and continuously improve security capabilities; the cloud security service platform optimizes the protection strategy of the security component according to the latest attack methods and protection strategies, and pushes it to each security component, which can further improve security capabilities; the cloud security service platform updates the detection rule library of the security component according to the latest vulnerability information and attack characteristics, and pushes it to each security component, further improving security capabilities.
[0047] S14, using the security component to receive the abnormal response strategy fed back by the security platform.
[0048] In the above embodiments, after the security component pushes the corresponding data to the security platform, the security platform can analyze the received data to generate a reasonable abnormal response strategy.
[0049] S15, perform security protection on the medical IT network based on the abnormal response strategy.
[0050] In this embodiment, after performing security protection on the medical IT network based on the abnormal response strategy, the method further includes: Obtain the security protection result and the feedback data on the security protection result; Optimize the medical IT network security detection large language model according to the security protection result and the feedback data.
[0051] Through the above embodiments, it is possible to backfeed and optimize the training of the medical IT network security detection large language model according to the real-time protection effect, so as to ensure the real-time availability of the model and the accuracy of security detection.
[0052] It can be seen from the above technical solutions that the present invention can use the medical IT network security detection large language model and the security access management architecture to perform real-time network security detection on the medical IT network. Based on the large language model, it can improve the in-depth understanding and professional judgment ability of medical security sub-scenarios. Based on the security access management architecture, it can improve the accuracy of attack judgment, and achieve a high detection rate and a low false alarm rate for various types of scenario threats; use the security component to upload the detection data to the security platform, and use the security component to receive the abnormal response strategy feedback by the security platform to perform security protection on the medical IT network, and can achieve a security protection effect of 1+1>2 through the linkage between the security component and the security platform.
[0053] As Figure 2 shown, it is a functional module diagram of a preferred embodiment of the medical IT network security detection device of the present invention. The medical IT network security detection device 11 includes a training unit 110, a construction unit 111, a detection unit 112, a deployment unit 113, a receiving unit 114, and a protection unit 115. The modules / units referred to in the present invention refer to a series of computer program segments that can be executed by a processor and can complete fixed functions, and are stored in a memory. In this embodiment, the functions of each module / unit will be described in detail in subsequent embodiments.
[0054] Among them, the training unit 110 is used to respond to a security detection instruction for the medical IT network, construct a medical security corpus, and train a medical IT network security detection large language model based on the medical security corpus; The building unit 111 is used to build a secure access management architecture; The detection unit 112 is used to perform real-time network security detection on the medical IT network by using the medical IT network security detection large language model and the secure access management architecture, and obtain detection data; The deployment unit 113 is used to deploy security components, dock the security components to a security platform, and upload the detection data to the security platform by using the security components; The receiving unit 114 is used to receive the exception response policy feedback by the security platform by using the security components; The protection unit 115 is used to perform security protection on the medical IT network based on the exception response policy.
[0055] It can be seen from the above technical solutions that the present invention can perform real-time network security detection on the medical IT network by using the medical IT network security detection large language model and the secure access management architecture. Based on the large language model, it can improve the in-depth understanding and professional judgment ability of medical security sub-scenarios. Based on the secure access management architecture, it can improve the accuracy of attack judgment, and achieve a high detection rate and a low false alarm rate for various types of scenario threats; use security components to upload detection data to the security platform, and use security components to receive the exception response policy feedback by the security platform to perform security protection on the medical IT network, and can achieve a security protection effect of 1+1>2 through the linkage between the security components and the security platform.
[0056] As Figure 3 shown, it is a schematic structural diagram of a computer device of a preferred embodiment for implementing the medical IT network security detection method of the present invention.
[0057] The computer device 1 may include a memory 12, a processor 13, and a bus (the arrow in the figure is the bus), and may also include a computer program stored in the memory 12 and executable on the processor 13, such as a medical IT network security detection program.
[0058] Those skilled in the art can understand that the schematic diagram is only an example of the computer device 1, and does not constitute a limitation on the computer device 1. The computer device 1 can be either a bus structure or a star structure. The computer device 1 may also include more or fewer other hardware or software than shown in the figure, or different component arrangements. For example, the computer device 1 may also include input / output devices, network access devices, etc.
[0059] It should be noted that the computer device 1 is only an example, and other existing or future possible electronic products that can be adapted to the present invention should also be included in the protection scope of the present invention and are included herein by reference.
[0060] Among them, the memory 12 includes at least one type of readable storage medium, and the readable storage medium includes flash memory, mobile hard disk, multimedia card, card-type memory (such as SD or DX memory, etc.), magnetic memory, magnetic disk, optical disc, etc. In some embodiments, the memory 12 can be an internal storage unit of the computer device 1, such as the mobile hard disk of the computer device 1. In some other embodiments, the memory 12 can also be an external storage device of the computer device 1, such as a plug-in mobile hard disk, Smart Media Card (SMC), Secure Digital (SD) card, Flash Card, etc. equipped on the computer device 1. Further, the memory 12 can also include both the internal storage unit and the external storage device of the computer device 1. The memory 12 can be used not only to store application software installed in the computer device 1 and various types of data, such as the code of the medical information and communication technology network security detection program, etc., but also to temporarily store the data that has been output or will be output.
[0061] In some embodiments, the processor 13 can be composed of integrated circuits. For example, it can be composed of a single packaged integrated circuit, or can be composed of multiple integrated circuits with the same or different functions packaged together, including the combination of one or more Central Processing Units (CPUs), microprocessors, digital processing chips, graphics processors, and various control chips, etc. The processor 13 is the control core (Control Unit) of the computer device 1, connecting all components of the entire computer device 1 through various interfaces and lines, and by running or executing programs or modules stored in the memory 12 (such as executing the medical information and communication technology network security detection program, etc.), and calling the data stored in the memory 12, to execute various functions of the computer device 1 and process data.
[0062] The processor 13 executes the operating system of the computer device 1 and various installed application programs. The processor 13 executes the application programs to implement the steps in the above-mentioned various embodiments of the medical information and communication technology network security detection method, such as Figure 1 the steps shown.
[0063] Exemplarily, the computer program can be divided into one or more modules / units, and the one or more modules / units are stored in the memory 12 and executed by the processor 13 to implement the present invention. The one or more modules / units can be a series of computer-readable instruction segments capable of performing specific functions, and these instruction segments are used to describe the execution process of the computer program in the computer device 1. For example, the computer program can be divided into a training unit 110, a construction unit 111, a detection unit 112, a deployment unit 113, a receiving unit 114, and a protection unit 115.
[0064] The integrated units implemented in the form of software function modules can be stored in a computer-readable storage medium. The above-mentioned software function modules stored in a storage medium include several instructions for causing a computer device (which can be a personal computer, a computer device, or a network device, etc.) or a processor to execute part of the medical information and communication technology network security detection methods described in various embodiments of the present invention.
[0065] If the modules / units integrated in the computer device 1 are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, to implement all or part of the processes in the above-mentioned embodiment methods of the present invention, it can also be completed by a computer program instructing relevant hardware devices. The computer program can be stored in a computer-readable storage medium, and when the computer program is executed by a processor, the steps of the above-mentioned various method embodiments can be implemented.
[0066] Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory, read-only memory (ROM, Read-Only Memory), random access memory, etc.
[0067] Furthermore, the computer-readable storage medium mainly includes a storage program area and a storage data area. Among them, the storage program area can store an operating system, application programs required for at least one function, etc.; the storage data area can store data created according to the use of the blockchain node, etc.
[0068] The blockchain referred to in the present invention is a new application mode of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, and encryption algorithm. Blockchain, in essence, is a decentralized database, a series of data blocks generated by using cryptographic methods. Each data block contains information about a batch of network transactions, which is used to verify the validity of the information (anti-counterfeiting) and generate the next block. The blockchain can include a blockchain underlying platform, a platform product service layer, an application service layer, etc.
[0069] The bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, in Figure 3 it is only represented by a straight line, but it does not mean that there is only one bus or one type of bus. The bus is arranged to realize the connection and communication between the memory 12 and at least one processor 13, etc.
[0070] Although not shown, the computer device 1 may further include a power source (such as a battery) for supplying power to each component. Preferably, the power source can be logically connected to the at least one processor 13 through a power management device, so as to realize functions such as charging management, discharging management, and power consumption management through the power management device. The power source may further include any components such as one or more DC or AC power sources, a recharge device, a power failure detection circuit, a power converter or inverter, a power status indicator, etc. The computer device 1 may further include a variety of sensors, a Bluetooth module, a Wi-Fi module, etc., which will not be elaborated here.
[0071] Furthermore, the computer device 1 may further include a network interface. Optionally, the network interface may include a wired interface and / or a wireless interface (such as a WI-FI interface, a Bluetooth interface, etc.), which is usually used to establish a communication connection between the computer device 1 and other computer devices.
[0072] Optionally, the computer device 1 may further include a user interface, which may be a display, an input unit (such as a keyboard), and optionally, the user interface may also be a standard wired interface or a wireless interface. Optionally, in some embodiments, the display may be an LED display, a liquid crystal display, a touch liquid crystal display, and an OLED (Organic Light-Emitting Diode) toucher, etc. Among them, the display may also be appropriately referred to as a display screen or a display unit, which is used to display the information processed in the computer device 1 and to display a visual user interface.
[0073] It should be understood that the above embodiments are only for illustration purposes and are not limited by this structure in the scope of the patent application.
[0074] Those skilled in the art can understand that Figure 3 the structure shown does not constitute a limitation on the computer device 1, and it may include fewer or more components than shown in the figure, or combine some components, or have a different component layout.
[0075] In combination with Figure 1 , the memory 12 in the computer device 1 stores a plurality of instructions to implement a medical information and communication technology (ICT) network security detection method, and the processor 13 can execute the plurality of instructions to implement: In response to a security detection instruction for the medical ICT network, construct a medical security corpus, and train a large language model for medical ICT network security detection based on the medical security corpus; Construct a security access management architecture; Use the large language model for medical ICT network security detection and the security access management architecture to perform real-time network security detection on the medical ICT network to obtain detection data; Deploy security components, dock the security components to a security platform, and use the security components to upload the detection data to the security platform; Use the security components to receive the abnormal response strategy feedback by the security platform; Based on the abnormal response strategy, perform security protection on the medical ICT network.
[0076] Specifically, the specific implementation method of the above instructions by the processor 13 can refer to Figure 1 the description of the relevant steps in the corresponding embodiments, which will not be elaborated here.
[0077] It should be noted that all the data involved in this case are legally obtained. The non-company software tools or components appearing in the embodiments of this application are only for illustrative introduction and do not represent actual use.
[0078] In several embodiments provided by the present invention, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules is only a logical function division, and there may be other division methods in actual implementation.
[0079] The present invention can be used in numerous general-purpose or special-purpose computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronic devices, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and so on. The present invention can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present invention can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.
[0080] The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical units, that is, they can be located in one place, or can be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0081] In addition, in each embodiment of the present invention, the functional modules can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated unit can be implemented in the form of hardware, or in the form of a combination of hardware and software functional modules.
[0082] For those skilled in the art, it is obvious that the present invention is not limited to the details of the above exemplary embodiments, and without departing from the spirit or basic characteristics of the present invention, the present invention can be implemented in other specific forms.
[0083] Therefore, from any point of view, the embodiments should be regarded as exemplary and non-restrictive. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, all changes falling within the meaning and scope of the equivalent elements of the claims are intended to be included in the present invention. Any reference signs in the claims should not be regarded as limiting the claims involved.
[0084] In addition, it is obvious that the term "comprising" does not exclude other units or steps, and the singular does not exclude the plural. A plurality of units or devices described in the present invention can also be implemented by one unit or device through software or hardware. Terms such as first, second, etc. are used to denote names and do not denote any particular order.
[0085] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention.
Claims
1. A medical information network security detection method, characterized in that: The medical information innovation network security detection method comprises: In response to a security detection instruction for a medical information innovation network, a medical security corpus is constructed, and a medical information innovation network security detection large language model is trained based on the medical security corpus; Build a secure access management architecture; Using the medical information innovation network security detection large language model and the security access management architecture to perform real-time network security detection on the medical information innovation network to obtain detection data; Deploy a security component, connect the security component to a security platform, and use the security component to upload the detection data to the security platform; Utilizing the security component to receive the abnormal response strategy fed back by the security platform; The medical information innovation network is securely protected based on the abnormal response strategy.
2. The medical information network security detection method according to claim 1, characterized in that: The construction of a medical safety corpus and training of a medical information security network security detection large language model based on the medical safety corpus include: Get the attention-based Transformer model architecture as the initial network; Obtain multi-dimensional network monitoring subtasks and obtain a training set for each network monitoring subtask; Using the training set of each network monitoring subtask to perform multi-task joint pre-training on the initial network, a main model integrating multiple network monitoring capabilities is obtained; Collect network data in the credible cloud environment to which the medical credible innovation network belongs to build the medical security corpus; Continuously pre-training the main model based on the medical safety corpus to obtain a pre-trained model with medical scenario semantic understanding capability; Parse the security detection instructions to obtain fine-tuning tasks, and collect data from the medical information innovation network to construct training samples; The pre-trained model is fine-tuned based on the fine-tuning task and the training samples to obtain the large language model for medical information technology network security detection.
3. The medical information network security detection method according to claim 1, characterized in that: The construction of a secure access management architecture includes: Deploy a threat detection engine based on behavior analysis and machine learning on the terminal side; wherein the threat detection engine identifies persistent unknown threats based on abnormal behavior patterns by performing correlation analysis on multi-dimensional behaviors; Deploy a traffic analysis engine at the network edge; wherein the traffic analysis engine is used to perform in-depth analysis and correlation analysis of network session traffic, and identify various types of network attack behaviors in combination with machine learning algorithms and threat intelligence; A big data analysis platform is deployed in the cloud. The big data analysis platform is used to analyze and mine long-term accumulated security data to identify changing trends in the attack surface, and supports security incident tracing and unknown threat detection.
4. The medical information network security detection method according to claim 1, characterized in that: The deployment security component includes: Deploy mobile security components, terminal security components, secure access service edge components, network access security components, application security components, big data security components, cloud security components, and workload security components as the security components; Among them, the mobile security components include zero-trust client, unified user terminal management and SDK application security reinforcement; the terminal security components include unified terminal security, integrated terminal leakage prevention, integrated zero-trust client, and integrated terminal injection control; the secure access service edge components include Internet application access security, data center application access security and branch security access; the network access security components include integrated comprehensive Internet behavior management, next-generation firewall, NDR advanced threat monitoring, SDP trusted access gateway, SD-WAN security gateway; the application security components include Web application firewall, RSAP application adaptive security and API security gateway; the big data security components are used to protect the security of big data throughout its life cycle; the cloud security components include CSPM multi-cloud security management and CSSP security resource pool; the workload security components include CWPP cloud workload protection and container security protection.
5. The medical information network security detection method according to claim 1, characterized in that: After the security component is connected to the security platform, the method further includes: The security component is used to upload the collected telemetry data to the security platform, and the data reported by the cloud security service platform is uploaded to the security platform, so that the security platform can analyze the received data and generate the abnormal response strategy.
6. The medical information network security detection method according to claim 5, characterized in that: After the security component is deployed, the method further includes: Connecting the security component to the cloud security service platform so that the cloud security service platform reports data to the security component; Among them, the cloud security service platform is used to collect and analyze the latest threat intelligence, optimize the protection strategy of the security component according to the latest attack methods and protection strategies, and update the detection rule library of the security component according to the latest vulnerability information and attack characteristics.
7. The medical information network security detection method according to claim 1, characterized in that: After the medical information innovation network is protected based on the abnormal response strategy, the method further includes: Obtaining safety protection results and feedback data on the safety protection results; The medical information technology network security detection large language model is optimized according to the security protection results and the feedback data.
8. A medical information network security detection device, characterized in that: The medical information innovation network security detection device comprises: A training unit, for responding to a security detection instruction for a medical ICT network, constructing a medical security corpus, and training a medical ICT network security detection large language model based on the medical security corpus; Building blocks for constructing secure access management architecture; A detection unit, used to perform real-time network security detection on the medical information innovation network by using the medical information innovation network security detection large language model and the security access management architecture to obtain detection data; A deployment unit, used to deploy security components, connect the security components to a security platform, and upload the detection data to the security platform using the security components; A receiving unit, configured to use the security component to receive an abnormal response strategy fed back by the security platform; A protection unit is used to provide security protection for the medical information innovation network based on the abnormal response strategy.
9. A computer device, characterized in that: The computer device comprises: a memory storing at least one instruction; and A processor executes instructions stored in the memory to implement the medical information innovation network security detection method as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: At least one instruction is stored in the computer-readable storage medium, and the at least one instruction is executed by a processor in a computer device to implement the medical information network security detection method as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Network security protection method and system
CN117879970A
Network threat active defense system and method based on large model
CN118316736A
LLM-driven industrial network intrusion detection method and response system
CN118381627A