Terminal equipment risk grading method under local area network in hospital
By adopting technical means of communication logic timing fingerprint recognition, behavioral offset causal chain modeling, risk evolution trajectory modeling and local network stability strategy convergence in hospital LANs, the shortcomings of terminal equipment risk grading methods in the existing technology are solved, and more efficient and accurate risk management and response are achieved.
Patent Information
- Application Number
- CN202510571161.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-06
- Publication Date
- 2025-06-24
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing risk grading method for hospital LAN terminal equipment has problems such as insufficient static identity recognition, traditional detection mechanism lags behind new threats, one-size-fits-all risk response strategies, lack of time dynamics and business scenario coupling, lack of self-interpretation capabilities, and insufficient causal chain model.
The terminal device authenticity identification with communication logic timing fingerprint, the risk-triggered backtracking mechanism of behavioral offset causal chain, the adaptive hierarchy of risk evolution trajectory modeling and the strategy scope convergence mechanism of local network stability is built to build a closed-loop hierarchical system with behavior modeling, abnormal attribution, risk evolution judgment and strategy convergence capabilities.
It improves the accuracy of terminal equipment identity identification, reduces the false alarm rate and false blocking risks, realizes dynamic perception and trend prediction of risks, improves the overall intelligence level of the system, and ensures accurate and effective security control while ensuring network business continuity.
Smart Images

Figure CN120200839A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method for grading risks of terminal devices under a hospital internal local area network. Background Art
[0002] Currently, most of the methods for grading risks of terminal devices under a hospital internal local area network originate from the security architecture design and general risk identification mechanism of traditional enterprise networks. The underlying technical logic mainly includes whitelist authentication based on static asset information, intrusion detection systems (IDS) based on signatures or rules, anti-virus response based on endpoint protection software, and access control based on fixed policies (such as ACL, VLAN isolation, etc.). Although these methods have certain effects in conventional office networks, in the medical industry, especially in the complex, high-concurrency, and high-coupling local area network environment within a hospital, these traditional technical means have obvious deficiencies and structural drawbacks, and it is difficult to meet the refined, real-time, and business continuity requirements of current medical network security.
[0003] Firstly, existing methods generally rely on static identity recognition mechanisms, such as IP addresses, MAC addresses, device registration information, etc. as the judgment basis, and cannot cope with the real scenarios of frequent replacement, mirror restoration, virtualization migration of medical terminal devices, and mixed use by multiple users and multiple roles. Especially in high-frequency handover areas such as nurse stations, doctor offices, and examination rooms, the logical consistency between device users and device behaviors is seriously diluted, resulting in the risk grading results based only on static tags being unable to truly reflect the current security status of the device. Secondly, most current risk assessment systems use rule-based or signature-based detection methods and have the ability to identify known attack models, but they show serious lag and blind spots when facing new threats (such as lateral movement, device control, internal network data escape, etc.). Attacks in a medical local area network often have the characteristics of long-term latency, covert control, and masking behavior characteristics in the form of services, making the traditional detection mechanism unable to perceive the "non-abnormal but abnormalized" behavior chain, thus missing the window period before the outbreak of key risks. Thirdly, in terms of risk response strategies, existing systems generally adopt a one-size-fits-all processing logic, that is, when a device is determined to be suspicious, it is directly taken offline, isolated, and communication is blocked. This method may be feasible in an enterprise network, but in a hospital, it is extremely likely to cause serious consequences because most medical services, such as PACS image retrieval, LIS test data interaction, HIS doctor's order issuance, etc., are extremely dependent on the real-time nature of network connections. Once the response strategy is executed too strongly or the coverage is too wide, it will either interrupt the doctor's diagnosis and treatment rhythm or lead to misdiagnosis or data delay, greatly impacting the availability of the hospital's core business system and the doctor's trust in the network system.
[0004] The risk scoring systems deployed in some hospitals currently lack temporal dynamics. They only judge the risk level of devices based on one-time scan results or static configuration status, ignoring the behavioral changes and communication relationship evolution that devices may experience during long-term operation. In particular, the usage behaviors during night shifts and day shifts are different, and the communication modes between the inpatient department and the emergency department are also different. Devices show significant context differences in terms of rhythm, frequency, path, etc. However, the static model cannot adapt, resulting in misjudgments such as "behavioral changes mean an increase in risk" often occurring in actual risk judgments. Fifth, there is currently a lack of deep coupling between the risk level and the business scenario. The business roles played by different terminals in the medical system vary greatly. From the pathology printer to the surgical navigation terminal and then to the ICU monitoring center, the importance levels of the devices are vastly different. However, many existing systems adopt a unified grading logic for all terminals, without distinguishing the business coupling degree and service priority, resulting in over-response to high-risk behaviors on low-coupling devices, while the risk response of truly core terminals is not timely. Sixth, existing systems generally lack the ability of self-explanation. After receiving a risk scoring result, administrators cannot intuitively obtain key explanatory information from the system such as "how this score is obtained", "which type of behavior is deviated", and "how much the difference is from the historical behavior", causing an understanding gap between the operation and maintenance personnel and the system, and making the final decision often rely on manual experience rather than model output. In addition, most current systems lack a causal chain model and cannot analyze whether an abnormal behavior is caused by internal changes in the device, restricted by the network environment, or the result of the behavior chain of surrounding devices, resulting in the widespread phenomenon of "identifying an abnormality but not knowing why it is abnormal", which fundamentally restricts the precision of risk determination, the stratification of responses, and the credibility of the system. Summary of the Invention
[0005] The objective of the present invention is to provide a method for risk grading of terminal devices under the local area network in a hospital, so as to solve some of the drawbacks and deficiencies pointed out in the background technology.
[0006] The following technical solutions are adopted by the present invention to solve the above technical problems: The method for risk grading of terminal devices under the local area network in a hospital includes the following steps:
[0007] S1. Authenticity identification of terminal devices using communication logic time series fingerprints:
[0008] S1.1. Generate behavior fingerprints based on the communication rhythm, protocol sequence, and startup response sequence of the device within the local area network; form a deep structure of the device communication rhythm through training with a long short-term memory network;
[0009] S1.2. If a newly launched or behaviorally abnormal device cannot fit the historical rhythm, it is marked as a terminal with uncertain identity;
[0010] S2. Risk trigger backtracking mechanism using behavior deviation causal chain:
[0011] S2.1. Micro-model the access path, request depth, and trigger resource changes of the device before and after risk triggering; construct the internal state change map of the device + the network external stimulus event stream;
[0012] S2.2. Analyze the triggering factors behind the anomaly and determine whether it is caused by environmental changes including sudden work transfers in departments, system anomalies such as task crashes and self-restarts, and suspicious guiding operations for cross-departmental horizontal jumps;
[0013] S3. Adopt an adaptive classification based on the risk evolution trajectory modeling: model the continuity of the device risk state over time; introduce a trend weighted curve method to identify the speed, stability, and direction of risk increase; including: a single risk stabilizes at a medium level for a long time without decreasing → suspicious and continuous; the risk of a single device rises rapidly → high-priority response;
[0014] S4. Adopt a strategy scope convergence mechanism for local network stability:
[0015] S4.1. Analyze the status of other devices in the subnet / department local segment where the device is located;
[0016] S4.2. If the device is the only abnormal node, it is inclined to perform a minimum closed isolation response; if there are multiple anomalies in the local segment but no attack breaks out → trigger a warning broadcast or traffic limiting, and do not directly block.
[0017] Furthermore, the method for authenticating the authenticity of the terminal device of the communication logic timing fingerprint:
[0018] Collect communication behavior data of various terminal devices in the hospital local area network to obtain the communication event stream with the medical information system. The communication event stream includes the connection time point, target address, communication protocol type and sequence, and the average delay changes among the start, request, and response phases. Construct a communication behavior rhythm feature model of the device based on the collected data, and use the model as a trusted benchmark for device identity calibration; by introducing a first-order communication behavior change integral function:
[0019]
[0020] where:
[0021] represents the cumulative trend function of the device communication behavior change within the time range t; P(τ) represents the activation frequency function of the protocol used by the device at any time τ, reflecting the periodicity and pattern characteristics of protocol calls; is the rate of change of the target host access status, that is, the degree of change of the device communication target address per unit time; S(τ) is the average delay value between the device startup and response phases at time τ, which is used to characterize the behavior rhythm of the device processing link; δ represents the short-term jitter degree of the communication behavior, which is used to adjust the nonlinear impact of abnormal jumps; coefficients α1, α2, and α3 are the weighted values of the three types of behavior factors, which are preset according to the device role type.
[0022] Furthermore, the terminal device authenticity identification method of the communication logic timing fingerprint is:
[0023] The communication behavior sequence of each terminal device within a specified period is input into the rhythm learning model based on the long short-term memory network LSTM, and the device behavior fingerprint is constructed using the nonlinear sequence dependence characteristics of the communication behavior, and the fingerprint vector Ψ is output. i (t) is defined as:
[0024]
[0025] in:
[0026] Ψ i (t) represents the behavior fingerprint vector of the i-th device at time t; φ i B is the coupling coefficient of the business scenario to which the device belongs; n (t) is the measured value of the nth communication feature at the current moment; Represents the historical mean of the feature during the training period, reflecting the typical behavior template of the device; ω n is the importance weight of each feature dimension; σ(·) represents a smooth activation function, which is used to control the influence of feature deviation on the overall fingerprint vector.
[0027] Furthermore, the terminal device authenticity identification method of the communication logic timing fingerprint is:
[0028] For newly launched devices or devices with fluctuating behaviors in the LAN, the current communication sequence of the device is used to fit and compare with the historical behavior fingerprint model. If the behavior similarity value is less than the dynamic trust threshold Θ, the uncertainty perception function is used:
[0029]
[0030] Perform identity credibility assessment, where Ω(t) is the behavioral fingerprint fitting confidence value of the device at the current moment; is the reference behavior fingerprint sequence formed by the device during training; It represents the square deviation between the current behavior and the standard behavior at any time τ; γ is the flexible control parameter of the model, which is used to adjust the sensitivity of the confidence value to the accumulation of deviations;
[0031] When Ω(t) is lower than the set threshold Θ, it indicates that the current behavior pattern significantly deviates from the standard behavior structure. Based on this, it is judged that there is a possibility of identity disguise, operating environment change or malicious manipulation of the device. It is marked as a terminal with uncertain identity, and a minimum privilege policy response mechanism matching the risk level is triggered, including network communication restriction, read-only access permission restriction, manual review intervention or behavior sandbox observation.
[0032] Furthermore, the method for constructing the risk trigger backtracking mechanism of the behavior deviation causal chain:
[0033] Perform fine-grained behavior modeling on various terminal devices within the local area network during the window period before and after potential risk behaviors occur, including access path modeling, request depth modeling, and local resource status change recording. Among them, access path modeling is used to record the jump sequence and target system chain in one or multiple communications of the device, and construct a time series path set of continuous system calls;
[0034] Request depth modeling is used to identify the hierarchical structure of business data accessed in a single session, the hierarchical difference from basic data reading to sensitive data editing or file downloading; resource change monitoring is used to obtain the resource status of process startup, system service loading, and configuration parameter changes of the device during the risk time period. The three together constitute the microscopic operation behavior space trajectory of the device, and a continuous operation trajectory integral curve is constructed:
[0035]
[0036] Where:
[0037] Represents the behavior trajectory tension of the i-th device within the time interval [t0, t], Λ p (t) is the access path transformation function, D r (t) represents the depth index of the currently accessed resource; Δ c (t) is the function of the change in the local configuration or driver loading state of the device, η(t) is the resource change frequency function, which is used to reflect the jump intensity in the behavior rhythm, and κ1, κ2, κ3 are weighted adjustment factors, which are used to describe the influence ratio of behavior changes on the overall trust level of the device.
[0038] Furthermore, the method for constructing the risk trigger backtracking mechanism of the behavior deviation causal chain:
[0039] After the behavior modeling is completed, construct the internal state change map of the device and the external stimulus event stream in the network environment where it is located. The internal map of the device includes the process restart, driver exception, and module loading failure log chain, and the external event stream includes background events such as abnormal broadcasts, horizontal scans, and adjacent device synchronization exceptions in the subnet, and calculate the coupling relationship through the event stream density perception function:
[0040]
[0041] Among them, represents the event coupling strength between the internal state sequence of the i-th device and the j-th external stimulus source at time t, represents the intensity function of the k-th internal abnormal event, represents the action function of the external event after the time delay θ k . ρ is the coupling conversion coefficient, which measures whether the internal and external events form a causal path.
[0042] Furthermore, the method for constructing the risk trigger backtracking mechanism of the behavior deviation causal chain:
[0043] Based on the joint calculation of the microscopic behavior tension curve and the coupling event intensity map, the induction type behind the current behavior is calculated, and the risk causal chain weight function is constructed according to the structure of the abnormal trigger factor:
[0044]
[0045] Among them, is the risk weight of the main trigger type matched by the current abnormal behavior, I env (t) represents the function induced by environmental changes, including the activation factors of sudden job transfer and external scheduling events of equipment rotation; I sys (t) represents the system adaptive abnormal function, which reflects the overall behavior under non-human-triggered conditions such as equipment collapse and configuration reload; Iguide(t) represents the suspicious guidance operation function, and the weight of this item increases if the behavior shows frequent cross-system, unauthorized attempts or access to unknown addresses; μ1, μ2, and μ3 are the risk level mapping weights of various inducements; according to the risk function The qualitative conclusion of the abnormal event is determined according to the maximum value result. If the value falls into the human suspicious operation interval, the device is marked as a high-risk terminal and enters the response process; if it is a behavior deviation caused by environmental changes or adaptive system fluctuations, the risk score is reduced and it enters the observation mode.
[0046] Based on the business characteristics of the medical environment and the actual network structure, this method constructs a closed-loop hierarchical system with the capabilities of behavior modeling, abnormal attribution, risk evolution judgment, and strategy convergence through technical means such as communication logic timing fingerprint recognition, behavior deviation causal chain modeling, risk trajectory trend analysis, and local network response regulation. Compared with the traditional method based only on static features, fixed strategies, or simple behavior anomaly matching, the present invention has the following advantages:
[0047] By constructing the timing fingerprint of the communication behavior of the device, the system can accurately extract the communication mode, protocol rhythm, and operation sequence of the device in a specific business scenario, and effectively identify illegal terminals disguised by means such as MAC spoofing, system reinstallation, and image replacement in combination with the LSTM deep learning model, greatly improving the accuracy of identity recognition.
[0048] By introducing the behavior deviation causal chain model, the system not only detects "behavior anomalies", but further analyzes "why the anomalies occur", and can distinguish between normal business fluctuations such as job transfers, device restarts, and system upgrades and real potential attack behaviors, effectively reducing the false alarm rate and the risk of missealing.
[0049] By modeling the time evolution trend of the device risk status and introducing the risk trajectory and weighted curve analysis mechanism, it is possible to determine whether the risk is continuously accumulating, suddenly soaring, or occasionally abnormal, thereby dynamically adjusting the risk level and response priority, and improving the overall intelligence level of the system. Brief Description of the Drawings
[0050] Figure 1 It is a flowchart of the method for grading the risks of terminal devices in the hospital's internal local area network according to the present invention.
[0051] Figure 2 It is a flowchart of the method for identifying the authenticity of terminal devices based on the communication logic timing fingerprint according to the present invention.
[0052] Figure 3 It is a flowchart of the method for constructing the risk trigger backtracking mechanism of the behavior deviation causal chain according to the present invention. Detailed Embodiments
[0053] The following will give a detailed description of the specific embodiments of the present invention with reference to the accompanying drawings.
[0054] Combined with the appendix Figure 1, for the risk grading method of terminal devices under the hospital internal local area network of the present invention, first, in step S1, the authenticity of the terminal devices is identified by means of communication logic timing fingerprints. S1.1, based on the communication behavior data of various terminal devices within the hospital local area network during actual operation, the system collects their communication rhythms, protocol sequences, and specific sequence information during the startup-to-response process in typical business scenarios. These information not only include the interaction frequencies of the devices with specific systems (such as HIS, PACS, LIS, etc.) within a fixed time period, but also include the time intervals between their communication requests, protocol call sequences, the response order of target hosts, etc.; by inputting the above multi-dimensional time series data into a neural network model with memory capabilities, especially the long short-term memory network (LSTM) with timing learning capabilities, the system can extract the communication behavior patterns and rhythm characteristics of the devices in a stable business state, thereby forming a deep behavior structure model for device identity determination. This model can be regarded as a "behavior fingerprint" exclusive to the device; next, step S1.2 is executed. After the model is trained and a standard fingerprint library is formed, if there is a newly launched device or a significant behavior variation occurs in a certain known device, the system will immediately input its current behavior sequence into the above model for fitting comparison. If its communication rhythm characteristics cannot be successfully matched with the historical fingerprint model of the corresponding role, or its matching confidence level is significantly lower than the credible threshold set by the system, it can be determined that the communication behavior of the device in the current state does not match its declared identity, which is an abnormal situation such as MAC forgery, mirror restoration, or being implanted with abnormal services. The system marks the device as an "identity uncertain terminal" and decides whether to immediately trigger a risk level increase or enter the behavior review stage according to the network area and business coupling level where it is located, thereby effectively realizing the dynamic identification and control of the identity credibility of terminal devices in the hospital internal local area network environment.
[0055] On the basis of completing the terminal identity recognition, the system further executes step S2, that is, adopts a risk-triggering backtracking mechanism for the causal chain of behavior deviation to realize the analysis and judgment of the incentives behind the occurrence of abnormal behaviors. Among them, in step S2.1, the system first performs a fine-grained modeling of the operation behaviors of the device before and after the suspected risk behavior is triggered, mainly including the analysis of the access path, the identification of the request depth, and the monitoring of the changes in the local resource status. The access path modeling refers to tracking the operation jump trajectory of the device in the network and recording the continuous access link between it and various hospital business systems. For example, whether the device jumps from the local HIS system to the remote LIS or PACS platform, or whether it accesses multiple system nodes in a short period of time; the request depth modeling is to analyze the sensitivity and permission level of the resources requested by the device in each communication session, and quantify the request intensity step by step from read-only basic data access to write operations, uploading images, downloading reports, etc.; the resource change monitoring focuses on whether the device itself has operations such as process restart, driver loading, configuration change, or system patch application during this period of time. These internal dynamic states that cause changes in the behavior pattern are synchronously incorporated into the analysis framework; subsequently, based on this, the system constructs a graph of the internal state changes of the device, that is, records the transition relationship of the key operating states of the device on the time axis, and at the same time monitors the abnormal events of other devices in its subnet or VLAN to form an external network stimulus event stream, which includes abnormal communications, broadcast storms, scanning detections, or control signaling changes of other terminals in the local area network. These two types of graphs are uniformly abstracted as candidate causal chain paths in the system for backtracking and analyzing the inducing source of the behavior deviation of a certain device; after entering step S2.2, the system classifies and judges the abnormal motivation according to the timing relationship, event type, and behavior amplitude in the above graph, mainly divided into three categories: one is the environment change-induced type, such as the temporary drift of the behavior pattern caused by the equipment allocation between departments and the temporary change of personnel positions, manifested as multiple devices simultaneously having slight deviations but no abnormal behavior characteristics; the second is the system anomaly self-adaptive type, which means that the device's behavior pattern is temporarily disordered during the self-repair process due to internal problems such as crashes, restarts, and driver conflicts. Such behaviors are often accompanied by error events and resource loading restart records in the system logs; the third is the suspicious boot operation type, manifested as the device suddenly accessing cross-department resources, jumping to a server with inconsistent permissions, or attempting to establish an unknown communication connection without reasonable business logic support. This type of deviation is the most potentially risky, and the system usually marks it as a high-priority threat clue; finally, the system dynamically adjusts the risk score and hierarchical response strategy according to the causal determination result of the behavior deviation, combined with the aforementioned identity recognition process.
[0056] After completing the identification of device identity and the determination of the causes of abnormal behaviors, the system further executes step S3, that is, adopts an adaptive grading mechanism based on risk evolution trajectory modeling to address the problems of over-response or response lag caused by ignoring the change of the time dimension in traditional risk assessment methods. The core of this mechanism lies in continuously modeling the change of the risk state of the terminal device within a certain time span, so as to not only focus on the level of the current risk, but also attach importance to the change trend, speed and direction of the risk value. The specific approach is that the system constructs a risk trajectory for the risk scores of each device within the specified time window according to the time series, and introduces a trend weighted curve to perform fitting analysis on this series. This trend curve is not only based on the risk score itself, but also corrected in multiple dimensions by combining factors such as the rate of score change, change frequency, and score fluctuation amplitude, so as to form a function path that can be used to judge the risk evolution trend. This path can clearly distinguish the dynamic manifestations of different types of risks. Among them, when the system detects that the risk score of a certain terminal device has been in the medium level for a long time and there is no downward trend in multiple consecutive cycles, it is judged as a "suspicious continuous risk". Although this type of risk has not reached the critical alarm line, its stable abnormal characteristics often imply that the device is in a state of latent attack, passive abuse or misconfiguration. Therefore, the system marks it as a low-intensity continuous monitoring object; on the contrary, if the system identifies that the risk score of a certain device rises rapidly within a very short period of time and the change rate exceeds the preset threshold, the system immediately deems that the device is on the "edge of risk outbreak". Such rapidly growing risks are usually related to active attacks, privilege breaks or lateral movement attempts, and belong to high-priority handling objects, and it is necessary to immediately start a rapid response mechanism, such as short-term communication isolation, policy demotion or manual intervention for review; through this risk evolution trajectory modeling mechanism, the system realizes the dynamic perception and trend prediction of the risk grading state, no longer relying on a single-point threshold to judge whether to respond, but using the directionality and persistence of risk changes as the basis for grading adjustment, so as to improve the accuracy, foresight and business adaptation ability of terminal risk management in the hospital's internal local area network, and ensure effective terminal risk prevention and control on the premise of maximizing the guarantee of the continuity of the medical network.
[0057] In order to achieve accurate and effective security control while ensuring the continuity of network services, the system enters the S4 step after completing risk identification and evolution analysis, that is, adopting a policy range convergence mechanism for local network stability. The core idea of this mechanism is to avoid excessive defense or full network response of the entire network segment due to single-point risk triggering, thereby improving the accuracy and flexibility of policy execution. Among them, in step S4.1, the system will perform topological identification and environmental analysis on the network location of the terminal device currently in an abnormal state, focusing on the operating status of other terminal devices in the subnet where it is located or the department local segment designated within the hospital. The system will perform a multi-dimensional comparison of the risk scores, behavior fluctuations, and business coupling relationships with the target device of all devices in the subnet to determine whether the current abnormal behavior has network diffusion characteristics or is just an isolated incident. In step S4.2, the system dynamically adjusts the policy response range according to the above analysis results. If the current device is the only abnormal node in the local segment and no other devices have synchronous fluctuations or communication anomalies, the system tends to adopt a "minimum closed isolation response", that is, only local communication restrictions, policy downgrades, or behavior sandbox observations are performed on the device, without extensively blocking the network segment where it is located to avoid affecting normal business flow; and when the system finds that the same subnet or local segment If multiple anomalies occur at the same time, such as increased risk scores of multiple terminals, changes in communication modes, or abnormal access targets, although the conditions for determining a clear attack outbreak have not been met, the system will consider the area to be potentially threatened. Instead of directly blocking the network, targeted strategies will be triggered, including sending security warning broadcasts to all devices in the area, initiating link access rate limits, or increasing monitoring frequency and other preventive protection measures, thereby effectively reducing the potential risk spread before an attack is confirmed, while not affecting the normal operation of key business processes. This mechanism dynamically binds the response strategy to the stability of the local network to form a range determination and response convergence mechanism before the strategy is implemented, thereby maximizing the accuracy, hierarchy, and controllability of the hospital's network defense behavior, effectively avoiding the risk of business interruption caused by the "one-size-fits-all" misblocking in traditional security systems, and reflecting the organic combination of high sensitivity and high fault tolerance in the network security defense scenario of the medical industry.
[0058] Embodiment 1:
[0059] Combination Figure 2, in this embodiment, within the local area network of the cardiology department of a certain Class III Grade A hospital, a nurse workstation device numbered NWS-203 is routinely used to communicate with the hospital information system (HIS), laboratory information system (LIS), and electrocardiogram management system (ECG). The system administrator hopes to use the method of the present invention to identify whether the device has been replaced, cloned, or has an abnormal operating environment in the recent days. For this purpose, the system first collects the communication behavior streams between the device and different business systems based on the communication behavior logs of the device in the past 14 consecutive days. This behavior data includes the connection time points (an average of 5 times per day) for sending doctor's order query requests to the HIS system via the TCP protocol during the early shift (07:30 - 08:30) every day. The response delay after each request is stable at 180 - 200 milliseconds, and the protocol sequence is mainly HTTP over TCP, HL7 message encapsulation, simple data encryption transmission, etc. The device initiates interactions with the LIS system mainly for sample data queries around 11:00, with an average of 1 - 2 times, while the interactions with the ECG system are concentrated before getting off work at 17:30 for PDF report downloads, and the response delay is slightly higher, about 350 - 400 milliseconds. Based on the stable rhythm demonstrated by the device in communication behavior, the system constructs its communication behavior fingerprint model using the above interaction frequency, protocol call order, and response delay as benchmark behavior characteristics.
[0060] To quantify its behavior consistency, the system models the device communication behavior with an integral function, and the first-order communication behavior change integral function proposed by the present invention is adopted:
[0061]
[0062] Set the role coefficients as follows: Since NWS-203 is a nurse terminal with a medium coupling level, its protocol activity is not as high as that of server devices, but it has stability requirements. Therefore, the parameter values are: α1 = 0.3, α2 = 0.5, α3 = 0.2; in actual observations, the protocol activation frequency function Pτ is on average 0.8 (normalized value, indicating frequent access during the early shift every day) during the period from 07:30 to 08:30, and the target address change rate is about 0.1 under normal circumstances (because it fixedly accesses HIS and LIS), while the system response time Sτ is 0.2 seconds, and the communication jitter degree δ = 0.05 (indicating that the device is stable during operation and has small jumps).
[0063] Substitute into the calculation. If within one hour of the early shift on a certain day (i.e., t = 1 hour = 3600 seconds), the device operates according to its benchmark behavior, the integral expression is as follows:
[0064]
[0065] First, solve the inner component:
[0066] 0.3 · 0.8 = 0.24;
[0067] 0.5 · 0.1 = 0.05;
[0068] 0.2 · 0.2 · log(1.05) ≈ 0.04 · 0.0488 = 0.00195;
[0069] Therefore, the cumulative value per second is approximately: 0.24 + 0.05 + 0.00195 = 0.29195
[0070] The integral value for the entire time period is:
[0071] This value, as the "rhythm cumulative score" of the device's communication behavior during this time period, is stored as the reference value for the morning shift segment of the standard behavior fingerprint.
[0072] Subsequently, during the detection on the 15th day, the administrator found that although NWS - 203 was started as usual during 07:30 - 08:00, its protocol call frequency Pτ decreased to 0.4 (due to a decrease in the number of requests), the target address change rate increased to 0.5 (frequently switching to off - campus IP addresses), the response time increased to 0.35 seconds, and the communication jitter increased to δ = 0.2 (there were frequent request failures and reconnection behaviors). Substituting these values into the calculation in the same way:
[0073] 0.3 · 0.4 = 0.12;
[0074] 0.5 · 0.5 = 0.25;
[0075] 0.2 · 0.35 · log(1.2) ≈ 0.07 · 0.182 = 0.01274;
[0076] The integral value per second: 0.12 + 0.25 + 0.01274 = 0.38274;
[0077] The total integral value is:
[0078] Compared with the reference value of 1050.99, the deviation of the current behavior cumulative score has reached 326.87, and the deviation rate exceeds 31%, reaching the credible fluctuation threshold set by the system (usually set at 20 - 25%). Therefore, the system infers that the behavior rhythm of this device seriously deviates from the historical model, and the deviation types are: the access target jumps, the protocol activity decreases, the response becomes slower, and the connection jitter intensifies, which conforms to the identification characteristics of "doubt about identity authenticity". The system temporarily marks it as an "uncertain identity terminal" and makes policy decisions in combination with subsequent behaviors.
[0079] After the integrated result of its communication rhythm is judged to deviate from the historical model, the system does not immediately perform a hard isolation operation. Instead, it enters the second stage, further performing more refined verification through a behavioral rhythm learning model constructed by a long short-term memory network (LSTM) to enhance the robustness and dynamic adaptation ability of the judgment. In this stage, the system inputs the complete time series of the device's daily communication behavior in the past 14 days into the rhythm learning network constructed based on LSTM. The model extracts multiple time series features such as the protocol call pattern, target switching rhythm, response time trend, connection attempt times, and abnormal retry times of the device in different time periods and different communication contexts, and forms a long-term communication structure memory in combination with its department business scenario label. After the model training is completed, the behavior of each device at each time point will be mapped to a multi-dimensional behavior fingerprint vector Ψ i (t), and its calculation expression is:
[0080]
[0081] In the application, the NWS-203 device is defined as a "general work terminal at the middle level in the department", and its business coupling coefficient φ i takes a value of 0.7 (the value range of this coefficient is generally set to [0.2, 1.0]. The more critical the device and the deeper the business coupling, the higher φ i is); the communication behavior of this device is quantified into 5 main feature dimensions (N = 5), including:
[0082] B1t: Communication request frequency (times / minute),
[0083] B2t: Number of protocol switches (types / hour),
[0084] B3t: Average response delay (seconds),
[0085] B4t: Number of types of accessed target IPs (pieces),
[0086] B5t: Number of abnormal reconnections (times).
[0087] According to the historical data obtained during the system training period, the mean value of the standard behavior template of NWS-203 is:
[0088]
[0089] During the behavior monitoring period suspected of being abnormal on the 15th day, the measured values are as follows:
[0090] B1(t) = 2.5, B2(t) = 2.3, B3(t) = 0.41, B4(t) = 5.0, B5(t) = 3.2;
[0091] The weight coefficient ω of each feature nIt is adaptively learned and generated according to the contribution degree of this feature to the behavior pattern fitting in the historical model, and its setting range is usually [0.1, 1.0]. In this case, the system weight distribution is as follows:
[0092] ω1 = 0.3, ω2 = 0.2, ω3 = 0.15, ω4 = 0.2, ω5 = 0.15;
[0093] At the same time, the smoothing activation function σ(x) used by the system is a hyperbolic tangent inhibition function with a threshold to ensure that extreme offset values do not cause the overall score to tilt extremely, and it is set as:
[0094] σ(x) = tanh(x), and it decays and compresses when |x| > 2.
[0095] Substitute all values into the formula to obtain the deviation degree of each item and activate the processing as follows:
[0096] The first item: σ(2.5 - 3.8) = σ(-1.3) ≈ -0.86, and the score is 0.3 · -0.86 = -0.258;
[0097] The second item: σ(2.3 - 1.2) = σ(1.1) ≈ 0.80, and the score is 0.2 · 0.80 = 0.16;
[0098] The third item: σ(0.41 - 0.22) = σ(0.19) ≈ 0.19, and the score is 0.15 · 0.19 = 0.0285;
[0099] The fourth item: σ(5.0 - 2.0) = σ(3.0) exceeds the compression threshold, and after compression, it is about 0.96, and the score is 0.2 · 0.96 = 0.192;
[0100] The fifth item: σ(3.2 - 0.5) = σ(2.7) is about 0.93 after compression, and the score is 0.15 · 0.93 = 0.1395;
[0101] Multiply the sum of all the above feature scores by φ i = 0.7:
[0102] Sum: -0.258 + 0.16 + 0.0285 + 0.192 + 0.1395 = 0.262
[0103] The value of the behavior fingerprint vector is: Ψ i (t) = 0.7 · 0.262 ≈ 0.1834
[0104] And the fluctuation range of the typical fingerprint value of this device obtained by the system during the model training stage is [0.35, 0.45]. When Ψ iWhen (t) is more than 20% lower than this interval, it is determined that there is behavioral distortion or abnormal operating environment in the device. The current value is only 0.1834, deviating from the mean by more than 48%, indicating that the device behavior sequence does not match the model well. Based on this, the system further confirms that the behavior rhythm of this device not only deviates from the original features statistically (obtained through integral function analysis), but is also difficult to be accepted by the LSTM model in terms of structural timing features. Therefore, it can be preliminarily inferred that its operating state has been changed, the environment has changed, or there is interference from human manipulation signals. Subsequently, the system marks the behavior state of this device with an "abnormality suspected label", and according to the hospital risk strategy setting, only retains its read-only permission to access the local HIS system. At the same time, it activates the device behavior sandbox observation mechanism and pushes a security notice to the network administrator and the head of the cardiology department's medical technology for manual review.
[0105] The nurse workstation numbered NWS-203 has been preliminarily marked as a "behaviorally abnormal terminal" by the system due to the integral deviation of the communication behavior rhythm and the significant decrease of the LSTM behavior fingerprint vector from the normal interval. However, to ensure the system has fault tolerance and reduce false alarms, the final judgment on whether to list it as an "identity uncertain terminal" needs to enter the third stage proposed in the present invention, that is, to calculate the behavior fitting confidence value of this device within a specific time period through the uncertainty perception function Ω(t), so as to conduct a quantitative assessment of the identity credibility and ensure that the system will not trigger false blocking due to short-term fluctuations. In this stage, the system will use the device behavior fingerprint sequence Ψ i (τ) within the current detection period and compare it dynamically with the standard reference behavior fingerprint sequence established during its training period, and calculate through the following uncertainty function:
[0106]
[0107] Set the behavior evaluation time window of this device as the early shift time period t0 = 0 seconds to t = 3600 seconds (i.e., 1 hour), and take one sampling point per minute, a total of 60 behavior fingerprint points are collected. After the construction of the previous LSTM model, it is obtained that the mean value of the reference behavior fingerprint sequence of this device during the training period fluctuates roughly in the interval [0.38, 0.42], while the actual behavior fingerprint points Ψ i (τ) on the abnormal monitoring day are mostly concentrated in [0.16, 0.22]. The system calculates the squared deviation of the two at each sampling point For example, one group of sample points: Ψ i (1200) = 0.19, The corresponding deviation is (0.19 - 0.40) 2 = 0.0441. If the squared deviation of each point on average is 0.037, the integral result is approximately The model flexibility control parameter γ of this system is used to adjust the sensitivity of the uncertainty function. For the nurse terminal, the range of this parameter is usually set to [0.8, 2.0]. The current strategy sets γ = 1.5. Substituting it into the function, we get:
[0108]
[0109] During the training phase of the system, the dynamic trust threshold Θ set for the NWS-203 device is 0.35. This value is comprehensively generated by factors such as its historical behavior volatility and business role fault tolerance requirements. The current uncertainty value is significantly lower than this threshold, indicating that the current behavior sequence has a significant deviation from the reference model at the time structure level. Based on this, the system confirms that there is a very high possibility of identity inconsistency for this device. Combining the integral anomaly and fingerprint deviation results in the previous stage, its status is finally upgraded to "identity uncertain terminal", and the response strategy matching its risk level is immediately activated. The system applies the minimum privilege access mode, only retaining its basic read-only access right to the HIS system, and at the same time preventing it from connecting to the LIS and ECG subsystems to prevent potential cross-system information diffusion. In addition, this device is incorporated into the behavior sandbox monitoring module, and all its communication events are monitored within 24 hours. If there are still continuous deviation behaviors, it will enter the isolation candidate list. In addition, the system pushes an anomaly notice to the network security management platform and the person in charge of the cardiology department, prompting them to complete the manual identity verification operation. This complete process fully reflects the three-stage closed-loop design of the communication logic timing fingerprint authenticity recognition mechanism in the present invention: integral deviation → structural fitting deviation → behavior confidence mismatch, ultimately driving the risk level to increase and the strategy to dynamically converge, with extremely strong discrimination ability, business adaptability and computability, ensuring accurate identification and response control of terminal identity disguise or operating environment change in a highly coupled and low-fault-tolerant network environment such as the hospital internal local area network.
[0110] Example 2:
[0111] Combined with Figure 3, in this embodiment, in the network environment of the cardiology department of the aforementioned hospital, after the nurse workstation numbered NWS-203 was detected with a serious deviation in communication behavior fingerprints, the system entered the behavior deviation causal chain analysis stage proposed in the present invention to determine whether the abnormal behavior of the device was caused by external incentives, system fluctuations, or potential attack behaviors. In this stage, a risk traceability analysis is carried out through the behavior trajectory tension model. The method is to micro-model the operation trajectory of the device within the "pre- and post-risk behavior window period" and substitute it into the continuous operation trajectory integral function designed in the present invention for quantitative analysis. This modeling covers three core dimensions: one is the access path modeling, which is used to record the system jump sequence in device communication. For example, under normal circumstances, the access path of NWS-203 from 07:30 to 08:30 every day should be "terminal → HIS server → LIS interface service", while on the day of the abnormal behavior, the path is recorded as "terminal → off-campus IP address A → LIS server", and the new path jump segment indicates the existence of an unauthorized intermediate node; the second is the request depth modeling, that is, the system quantitatively scores the sensitivity level of the resources accessed by a single communication behavior. Among them, the basic data reading is defined as depth 1, the medical record modification is depth 2, the download of imaging data is depth 3, and the access to the telemedicine document platform is depth 4. NWS-203 accessed the ECG imaging original file download module during the abnormal behavior, and the actual request depth rose to 4; the third is the local resource status change modeling. The system found that the device had a driver loading fluctuation and restarted the electrocardiogram transmission module at 06:55 on that day, and at the same time the log recorded that its communication service component had a hot loading behavior, which never occurred under standard operating conditions, indicating that there was a structural change in the device environment. Based on this, the system extracted a complete sequence of behavior events for a total of 2 hours from time period t0 = 06:30 to t = 08:30 and substituted it into the operation trajectory integral curve:
[0112]
[0113] In this function, the access path transformation function Λ p (t) is normalized to the range [0, 1], and the degree of deviation from the existing communication path in the abnormal access path is 0.8; the average value of the access resource depth index D r (t) in this cycle is 3.2 (much higher than the conventional depth average value of 1.8 for this device); the device configuration change function Δ c(t) takes the value of 1 (indicating that a drive thermal load occurs once), and the resource change frequency function η(t) fluctuates 4 times within 2 hours and takes the value of 4. According to the system, the behavior impact weighting coefficients set for the devices of the general workstation type at the nurse station are: κ1 = 0.4, κ2 = 0.35, κ3 = 0.25, and the ranges of these coefficients are set as κ1 ∈ [0.2, 0.6], κ2 ∈ [0.2, 0.5], κ3 ∈ [0.1, 0.4] respectively, which are used to regulate the influence intensity of different characteristics on the behavior trust degree.
[0114] Substitute the instantaneous function average value in the integral expression for estimation:
[0115] κ1·Λ p (t) = 0.4·0.8 = 0.32;
[0116] κ2·D r (t) 2 = 0.35·3.2 2 = 0.35·10.24 = 3.584;
[0117] κ3·Δ c (t)·η(t) = 0.25·1·4 = 1.0;
[0118] Then the cumulative value of the behavior tension per minute is: 0.32 + 3.584 + 1.0 = 4.904
[0119] There are 120 minutes in 2 hours, and the behavior trajectory tension value is obtained as:
[0120] During the system training period, the standard behavior tension reference interval for NWS - 203 is [140, 240]. The current value of 588.48 significantly exceeds the upper limit of the normal interval by about 145%. Therefore, the behavior evolution tension is determined to be "highly deviated". Combining factors such as obvious path jumps, atypical request depth, and unstable resource behavior, the system locates this anomaly as a composite trigger - type deviation in the risk causal chain map. It is initially judged that there has been a major change in the device operating environment, and there are signs that the communication behavior has been guided. It cannot be excluded that there is a possibility of artificially injecting an external proxy program or tunneling behavior. The system immediately classifies this anomaly type as a "high - confidence artificial manipulation or system tampering" risk behavior, and in combination with the previous judgment of extremely low communication fingerprint deviation and fitting confidence, finally upgrades this device from a "behavior - abnormal terminal" to a "high - risk disguised terminal", and executes a three - level response strategy: close its access permissions to all service ports except the local DNS and identity authentication services, enter the strong sandbox state, and at the same time require the information department to manually verify the complete hardware sequence, system image, and suspicious components of this terminal, providing an accurate and controllable risk - grading closed - loop processing mechanism for the hospital local area network.
[0121] In the aforementioned hospital's cardiology department network, the nurse station terminal numbered NWS-203 has been marked as a high-deviation terminal by the system after communication behavior fingerprint recognition and behavioral trajectory tension integral analysis. To further confirm the root cause behind its abnormal behavior and avoid misjudgment, the system enters the "causal inference stage" formally after the behavior modeling according to the behavior deviation causal chain risk trigger backtracking mechanism of the present invention. By constructing the internal state change map of the device and the external stimulus event stream in the network environment where it is located, the system uses the event stream density perception function to calculate whether there is a clear inducing source and form a causal chain closed loop. In this scenario, NWS-203 had an abnormal restart at 07:43 on April 10. The system log shows that its communication service component registryd was abnormally terminated, and the network card driver reload was triggered after the restart, which is a typical abnormal behavior of internal module loading. During the same period, another terminal ECG-WK-05 in the subnet VLAN-ICU where it is located also had a sudden communication request with an off-campus server, triggering an IDS system alarm of "suspicious SSL outbound jump". At the same time, the hospital network boundary device captured ARP broadcast conflicts among multiple devices in this subnet between 7:40 and 7:50, forming a horizontal scanning feature. Such behaviors constitute the external stimulus event stream. To determine whether there is an inducing relationship between these internal and external events, the system calls the event stream density perception function proposed in the present invention:
[0122]
[0123] In this scenario, i represents the NWS-203 device, j represents the set of external events in its subnet (i.e., VLAN-ICU), M is the total number of event types (set to 3 in this example: driver reload, abnormal connection, broadcast conflict). The system first scores the intensity function of each event, and the scoring range is 0, 1. The value logic is based on the abnormal level and confidence scoring:
[0124] The abnormal score of the driver is 0.85 (severe level)
[0125] The process restart score is 0.65 (medium-level abnormality)
[0126] The hot reload trigger score is 0.70 (above medium)
[0127] The action function of the external event represents the propagation impact of the event after the delayed action. The system controls θ k within 0, 300 seconds, where:
[0128] The action after 120 seconds of the ARP broadcast burst, and the propagation intensity is 0.72
[0129] 90 seconds after the horizontal scan is triggered, the propagation intensity is 0.68
[0130] 60 seconds after the suspected remote connection is established, the propagation intensity is 0.88
[0131] Substitute the above data into the function for summation:
[0132] The first term: 0.85 · 0.72 = 0.612
[0133] The second term: 0.65 · 0.68 = 0.442
[0134] The third term: 0.70 · 0.88 = 0.616
[0135] The sum of the three terms is: 0.612 + 0.442 + 0.616 = 1.67
[0136] The coupling conversion coefficient ρ is a system-predefined parameter used to control the sensitivity of causal chain determination. The value range is [0.5, 2.0]. The higher the value, the more sensitive it is to potential incentives. In the nurse station terminal type, the system defaults ρ = 1.2. Therefore, we get:
[0137]
[0138] The system pairs Set the judgment interval as:
[0139] Less than 1.0: No obvious external incentive
[0140] 1.0 - 1.5: There is a weak causal association, it is recommended to observe
[0141] Above 1.5: There is a clear causal chain, execute level promotion
[0142] Therefore, the current value is 2.004, belonging to the strong coupling region. The system determines that the abnormal behavior of NWS-203 is not isolated, but is extremely induced by abnormal broadcasts, scan propagations, and multi-point abnormal connection behaviors in the subnet it belongs to, forming a complete induction chain starting from ARP disruption, with drive faults as the channel and communication fingerprint deviation as the external manifestation, and having the characteristics of a "lateral attack propagation node". Based on this judgment, the system further raises the risk level of this device to "propagation-type high-risk terminal", marks the entire VLAN-ICU as a high-risk domain, and immediately issues a local response strategy: Except for specific whitelists, restrict the access rights of this subnet to the HIS main cluster, enable two-way communication behavior capture for all devices, and visualize the behavior heat map; at the same time, push the event chain to the hospital network security situation awareness platform for secondary confirmation and reporting by security operation personnel.
[0143] The nurse station terminal numbered NWS-203 showed significant deviation during the communication fingerprint recognition stage, and was subsequently identified as a suspicious node affected by multiple external disturbances in the analysis of behavioral trajectory integration and event coupling. In order to further clarify the main inducing type behind the abnormal behavior of this device and accordingly determine the final risk grading and response intensity, the system executes the inducing factor determination mechanism of the behavioral deviation causal chain described in the present invention, by constructing a risk causal chain weight function to evaluate the weights and locate the main causes of three types of triggering factors (environmental changes, system self-adaptation, suspicious guiding operations). The function form is as follows:
[0144]
[0145] In this instance, the system has detected a relatively high behavioral trajectory tension value in the behavioral tension curve and the event coupling intensity function belongs to the high-intensity causal chain interval. At this stage, the corresponding relationship between behavioral deviation and three types of inducing factors is further quantified. First, three activation factors are quantified:
[0146] 1. Environmental inducing factor function I env (t): The administrator retrieves the network shift schedule and device allocation logs of the day, and confirms that there has been no job transfer, department rotation or physical movement for NWS-203, nor any device label change or logged-in user switch. Therefore, this item is in a low activation state, and the system assigns a value of 0.15 (the value range is [0,1], where 0 means no activation and 1 means strong activation);
[0147] 2. System anomaly function I sys (t): The system log shows that the device triggered an unexpected termination of the communication module registryd at 07:43 and was accompanied by driver reloading, which is a medium-level system self-adaptation behavior. The system assigns a value of 0.58 to this activation factor, belonging to the medium-high interval;
[0148] 3. Suspicious guiding operation function I guide (t): NWS-203 tried to access three unauthorized external addresses (public network IP segments 192.168.205.1, 112.45.6.91, and unknown device 192.168.3.240 respectively) during the period from 07:45 to 07:50, and the access method was a non-standard port TLS connection, which was seriously inconsistent with its normal business path. Such behavior highly conforms to the feature of "behavior being remotely controlled or disguised". Therefore, the activation factor is set to 0.88.
[0149] Next, the system combines the mapping weights μ1 = 0.6, μ2 = 1.0, and μ3 = 1.3 configured for the three types of incentives in the hospital risk strategy. These weights are from the attribution scores of the actual business risks brought by different abnormal types in the historical risk handling strategy. Among them, the risk of the human-guided type has the most serious consequences, so the highest value is assigned. Substituting into the function, we get:
[0150] μ1·I env (t) = 0.6·0.15 = 0.09;
[0151] μ2·I sys (t) = 1.0·0.58 = 0.58;
[0152] μ3·I guide (t) = 1.3·0.88 = 1.144;
[0153] Thus, we obtain:
[0154]
[0155] The risk mapping threshold interval of the main incentive for the behavior set by the system is:
[0156] [0.0, 0.4): The behavior is acceptable, enter the observation mode
[0157] [0.4, 0.9): Medium risk, trigger a semi-response
[0158] [0.9, 1.5): High risk, immediately upgrade to a "high-risk terminal"
[0159] The current value of 1.144 is in the high-risk interval, and the leading factor is "suspicious guiding operation". Therefore, the system determines that the abnormal behavior of NWS-203 is not caused by accidental configuration problems or hospital internal process changes, but has clear malicious control or disguise characteristics. Immediately, it executes the "three-level response strategy" for it, that is, immediately disconnect the device from the network for all interaction interfaces of the HIS, LIS, and PACS systems, only retain the local authentication service connection, and at the same time force the push of the hardware identity verification module for underlying authentication. The connection cannot be restored until the manual review is completed, and the complete event chain of it is reported to the hospital SOC center, classified as a "suspected remotely controlled terminal", and enters the in-depth forensics process. This example demonstrates how the risk causal chain weight function proposed by the present invention accurately identifies the main inducing cause based on the correlation analysis of structured behavior data and abnormal sources in the actual hospital scenario, thereby avoiding mis-blocking while accurately positioning the real threat, and triggering a hierarchical response strategy matching the inducing cause, realizing the risk closed-loop process of "behavior recognition - causal positioning - precise decision-making", and effectively serving the intelligent risk classification control goal of terminal device abnormal behavior in the hospital local area network.
Claims
1. The terminal equipment risk classification method in the hospital local area network is characterized by The following steps are involved: S1. Authenticity identification of terminal equipment using communication logic timing fingerprint: S1.
1. Generate behavioral fingerprints based on the communication rhythm, protocol sequence, and startup response sequence of the device in the local area network; form the deep structure of the device communication rhythm through long short-term memory network training; S1.
2. If a newly launched device or a device with abnormal behavior cannot fit the historical rhythm, it will be marked as an identity-uncertain terminal; S2. Use the risk-triggered backtracking mechanism of the behavior deviation causal chain: S2.
1. Micro-modeling of the access path, request depth, and trigger resource changes of the device before and after the risk is triggered; constructing a graph of the internal state changes of the device + the external stimulus event flow of the network; S2.
2. Analyze the triggering factors behind the anomaly and judge whether it is caused by: environmental changes caused by sudden work transfers in departments, system anomalies caused by task crashes and self-restarts, and suspicious boot operations attempted by horizontal jumps across departments; S3, Adaptive classification using risk evolution trajectory modeling: Modeling the continuity of the equipment risk status evolution over time; Introduction The trend weighted curve method identifies the speed, stability and direction of risk increase; including: a single risk is stable at a medium level for a long time and does not decrease → suspicious continues; a single device risk increases rapidly → high priority response; S4, using the local network stability strategy range convergence mechanism: S4.
1. Analyze the status of other devices in the subnet / department local area segment where the device is located; S4.
2. If the device is the only abnormal node, it tends to respond with minimum closed isolation. If multiple abnormalities occur in the local segment but no attack occurs, trigger an early warning broadcast or current limiting instead of blocking directly.
2. The terminal device risk classification method in a hospital local area network according to claim 1 is characterized in that The terminal device authenticity identification method of the communication logic timing fingerprint: Communication behavior data of various terminal devices in the hospital local area network are collected to obtain the communication event flow between the terminal devices and the medical information system. The communication event flow includes the connection time point, target address, communication protocol type and sequence, and the average delay change between the three stages of startup, request, and response. The communication behavior rhythm feature model of the equipment is constructed based on the collected data.
3. The terminal device risk classification method in a hospital local area network according to claim 2 is characterized in that The terminal device authenticity identification method of the communication logic timing fingerprint: The communication behavior sequence of each terminal device within a specified period is input into the rhythm learning model based on the long short-term memory network LSTM, and the device behavior fingerprint is constructed using the nonlinear sequence dependence characteristics of the communication behavior, and the fingerprint vector Ψ is output. i (t) is defined as: in: Ψ i (t) represents the behavior fingerprint vector of the i-th device at time t; φ i B is the coupling coefficient of the business scenario to which the device belongs; n (t) is the measured value of the nth communication feature at the current moment; Represents the historical mean of the feature during the training period, reflecting the typical behavior template of the device; ω n is the importance weight of each feature dimension; σ(·) represents a smooth activation function, which is used to control the influence of feature deviation on the overall fingerprint vector.
4. The terminal device risk classification method in a hospital local area network according to claim 3 is characterized in that The terminal device authenticity identification method of the communication logic timing fingerprint: For newly launched devices or devices with fluctuating behaviors in the LAN, the current communication sequence of the device is used to fit and compare with the historical behavior fingerprint model. If the behavior similarity value is less than the dynamic trust threshold Θ, the uncertainty perception function is used: Perform identity credibility assessment, where Ω(t) is the behavioral fingerprint fitting confidence value of the device at the current moment; is the reference behavior fingerprint sequence formed by the device during training; It represents the square deviation between the current behavior and the standard behavior at any time τ; γ is the flexible control parameter of the model, which is used to adjust the sensitivity of the confidence value to the accumulation of deviations; When Ω(t) is lower than the set threshold Θ, it means that the current behavior pattern deviates significantly from the standard behavior structure. Based on this, it is judged that the device has the possibility of identity disguise, operating environment change or malicious manipulation. It is marked as an identity uncertain terminal and triggers the least privilege policy response mechanism matching the risk level, including network communication restrictions, read-only access permission restrictions, manual review intervention or behavior sandbox observation.
5. The terminal device risk classification method in a hospital local area network according to claim 1 is characterized in that The risk triggering backtracking mechanism construction method of the behavior deviation causal chain is as follows: Fine-grained behavior modeling is performed on various terminal devices in the LAN during the window period before and after potential risk behaviors occur, including access path modeling, request depth modeling, and local resource status change records. Access path modeling is used to record the jump sequence and target system chain of the device in one or more communications, and to build a sequential path set of continuous system calls. Request deep modeling is used to identify the hierarchical structure of business data accessed in a single session, from the hierarchical difference between basic data reading and sensitive data editing or file downloading; resource change monitoring is used to obtain the resource status of process startup, system service loading and configuration parameter changes of the device during the risk time period. The three together constitute the spatial trajectory of the device's micro-operation behavior.
6. The terminal device risk classification method in a hospital local area network according to claim 5 is characterized in that The risk triggering backtracking mechanism construction method of the behavior deviation causal chain is as follows: After the behavior modeling is completed, the internal state change map of the device and the external stimulus event flow in the network environment are constructed. The internal map of the device includes the process restart, driver exception, and module loading failure log chain. The external event flow includes abnormal broadcasts, lateral scanning, and abnormal background events of synchronization of adjacent devices in the subnet.
7. The terminal device risk classification method in a hospital local area network according to claim 6 is characterized in that The risk triggering backtracking mechanism construction method of the behavior deviation causal chain is as follows: Based on the micro-behavior tension curve and the coupled event intensity map, the induction type behind the current behavior is jointly calculated, and the risk causal chain weight function is constructed according to the structure of the abnormal trigger factor: in, The risk weight of the main trigger type matched by the current abnormal behavior, I env (t) represents the function induced by environmental changes, including the activation factor of external scheduling events such as sudden job transfer and equipment rotation; I sys (t) represents the system adaptive abnormal function, reflecting the overall behavior under non-human triggering, including device crash and configuration reload; I guide (t) represents a suspicious boot operation function. If the behavior is characterized by frequent cross-system, unauthorized attempts, or access to unknown addresses, the weight of this item increases; μ1, μ2, and μ3 are the risk level mapping weights of various inducements; According to the risk function The maximum value result of the abnormal event is used to determine the qualitative conclusion of the abnormal event. If the value falls into the range of suspicious human operations, the device is marked as a high-risk terminal and enters the response process. If it is a behavioral deviation caused by environmental changes or adaptive system fluctuations, the risk score is reduced and the observation mode is entered.
Citation Information
Patent Citations
Equipment access authentication method and device, equipment and storage medium
CN119182599A
Internet space security test method and system based on network equipment microscopic data
CN119232497A
Network attack detection system and method based on deep learning
CN119520106A
Internet of Things control method and platform based on OpenHarmony
CN119814596A
Method for anomaly classification of industrial control system communication network
US20220269258A1
Cited By
Multi-terminal cooperative communication monitoring alarm system for 5G new call
CN120957172A
Management method and system for custom private network asset fingerprints
CN121283738A
A method and system for managing custom private network asset fingerprints
CN121283738B
Network information security access control system based on dynamic trust evaluation
CN121486049A