Data transmission security monitoring method and device based on digital twinning, and storage medium

By analyzing and coupling the characteristics of database and network device information, the problems of low efficiency and insufficient accuracy in data transmission security analysis in the existing technology are solved, multi-dimensional data transmission security monitoring is achieved, and the analysis efficiency and accuracy are improved.

CN120455059BActive Publication Date: 2025-10-10BEIJING ZHONGKE MEDICAL INFORMATION TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510546477.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-28
Publication Date
2025-10-10
Estimated Expiration
2045-04-28

AI Technical Summary

Technical Problem

Existing technologies have problems of low efficiency and insufficient accuracy in data transmission security analysis, and fail to comprehensively consider user access operation characteristics, database operation data, and network device operation data.

Method used

By collecting the hospital's database access information, database device information and network device information, feature analysis is performed. Combined with user access characteristics, database load status and network device operation characteristics, coupling analysis is performed to obtain transmission security parameters and achieve multi-dimensional data transmission security monitoring.

Benefits of technology

The efficiency and accuracy of data transmission security analysis are improved, and comprehensive monitoring of data transmission security is achieved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455059B_ABST
    Figure CN120455059B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of data transmission monitoring, in particular to a data transmission security monitoring method and device based on digital twinning and a storage medium, which comprises the following steps: collecting database access information, database equipment information and network equipment information of a hospital; performing feature analysis on the database access information to obtain user access features and user operation features; analyzing a database load state based on the database equipment information; analyzing access address types, transmission rate features and network equipment operation features based on the database access information and the network equipment information; performing coupling analysis on the user access features, the access address types and the transmission rate features to obtain transmission security parameters, and improving the coupling analysis process according to the user operation features, the database load state and the network equipment operation features; and analyzing data transmission security states according to the transmission security parameters and outputting the data transmission security states. The application realizes accurate monitoring of data transmission security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data transmission monitoring, and in particular to a data transmission security monitoring method, device and storage medium based on digital twins. Background Art

[0002] Hospital data transmission security analysis primarily involves technologies such as data encryption, access control, and real-time monitoring and auditing. With the advancement of healthcare informatization, data security has become a critical factor. These technologies can ensure the security, integrity, and privacy of medical data during transmission, thereby safeguarding patient rights and the quality of healthcare services.

[0003] Chinese Patent Publication No. CN115102747A discloses an internet management platform based on digital twins, comprising a data upload module, a data center, and a data storage module. The data upload module is used by users to send data interaction requests to the data center to obtain cross-platform data. Upon receiving the data interaction request, the data center verifies the legitimacy of the data interaction request by combining the maliciousness value of the network IP and the request attraction factor, effectively controlling data interaction risks and improving information security. Upon receiving the data interaction request, the data node collects trusted data from various network platforms through a shared network channel and returns it to the data center. The data center is configured to review and filter the returned trusted data and then transmit the corresponding data to the data storage module. The data storage module is configured to select the storage block with the largest storage allocation value as the selected block and store the received trusted data in the selected block. This invention only analyzes data transmission security based on the legitimacy of user access requests and the data storage location, but does not implement a comprehensive analysis of data transmission security based on user access operation characteristics, database operation data, and network device operation data. This leads to low efficiency and inaccurate data transmission security analysis. Summary of the Invention

[0004] The object of the present invention is to provide a data transmission security monitoring method, device and storage medium based on digital twins to solve at least one of the problems existing in the prior art.

[0005] To achieve the above object, the present invention adopts the following technical solutions:

[0006] A data transmission security monitoring method based on digital twins, comprising:

[0007] Collect the hospital's database access information, database device information, and network device information;

[0008] Perform feature analysis on database access information to obtain user access features and user operation features;

[0009] Analyzing database load state based on database device information;

[0010] Analyzing access address type, transmission rate characteristic and network device running characteristic based on database access information and network device information;

[0011] Coupling analyzing user access characteristic, access address type and transmission rate characteristic to obtain transmission security parameter, and improving coupling analyzing process according to user operation characteristic, database load state and network device running characteristic;

[0012] Analyzing data transmission security state and outputting according to transmission security parameter.

[0013] Further, counting the number of times of accessing operation of each access to database as user operation times, and analyzing access username, access time length and user operation times to obtain user access characteristic Q(i);

[0014] Analyzing user permission level, user search quantity NA1(i), user upload quantity NA4(i), user compliance operation times A1(i) and user violation operation times A2(i) to obtain user operation characteristic W(i).

[0015] Further, counting the number of different access user IP addresses of the same user as user IP quantity, and judging access address type according to user IP quantity and access user IP address, if user IP quantity is less than or equal to address quantity threshold and all access user IP addresses belong to intranet, determining that the access address type is type one; if user IP quantity is greater than address quantity threshold and all access user IP addresses belong to intranet, determining that the access address type is type two; if there is access user IP address belonging to public network, determining that the access address type is type three.

[0016] Further, analyzing planned transmission rate, actual transmission rate and data packet size to obtain transmission rate characteristic D(t);

[0017] Analyzing network device power consumption and network device temperature to obtain network device running characteristic S(t).

[0018] Further, coupling analyzing user access characteristic, access address type and transmission rate characteristic to obtain transmission security parameter, the expression of the transmission security parameter is: In the formula, F(i,j) represents a transmission security parameter, U(i,j) represents a set of time numbers corresponding to user access time, K(i) represents an access address type parameter, K(i)=k1×e when the access address type is type one, K(i)=k2×e when the access address type is type two, and K(i)=k3×e when the access address type is type three, k1 represents a first address parameter, k2 represents a second address parameter, and k3 represents a third address parameter.

[0019] Further, the user operation safety is judged according to the user operation characteristic, if the user operation characteristic is less than the operation safety threshold value, it is determined that the user operation safety is low, and the analysis process of the transmission security parameter is improved, and the expression of the improved transmission security parameter is: On the contrary, it is determined that the user operation safety is high; in the formula, NP(i) represents the number of user IPs;

[0020] The load matching parameter is analyzed according to the database load state and the network equipment running characteristic, and the load matching type is judged according to the load matching parameter, if the database load state is high load and the network equipment running characteristic is greater than the running characteristic threshold value, it is determined that the load matching type is type one, and the analysis process of the transmission security parameter is further improved, and the expression of the improved transmission security parameter is On the contrary, it is determined that the load matching type is type two; in the formula, G(i,j) represents a load matching parameter,

[0021] Further, the equipment stability parameter is analyzed based on the network equipment running characteristic, and the expression of the equipment stability parameter is: And the equipment stability is judged according to the equipment stability parameter, if the equipment stability parameter is less than or equal to the stability threshold value, it is determined that the equipment stability is running stable, and the analysis process of the load matching parameter is improved, and the expression of the improved load matching parameter is: On the contrary, it is determined that the equipment stability is running unstable.

[0022] Further, the data transmission safety state is analyzed according to the transmission security parameter, if the transmission security parameter is less than the safety state threshold value, it is determined that the data transmission safety state is transmission safety; on the contrary, it is determined that the data transmission safety state is transmission insecurity.

[0023] On the other hand, the application also provides a data transmission safety monitoring device based on digital twinning, comprising:

[0024] The data acquisition module is used to collect the database access information, the database equipment information and the network equipment information of the hospital;

[0025] The database analysis module is used to perform characteristic analysis on the database access information to obtain user access characteristics and user operation characteristics;

[0026] a load analysis module configured to analyze a database load state based on database device information;

[0027] a device analysis module configured to analyze an access address type, a transmission rate feature and a network device operation feature based on database access information and network device information;

[0028] a coupling analysis module configured to perform coupling analysis on user access features, access address types and transmission rate features to obtain transmission security parameters, and improve the coupling analysis process according to user operation features, database load states and network device operation features;

[0029] a state output module configured to analyze data transmission security states and output according to the transmission security parameters.

[0030] In another aspect, the present application also provides a storage medium, characterized in that it stores instructions that, when executed on a computer, cause the computer to perform the data transmission security monitoring method based on digital twinning according to any one of the above.

[0031] The present application has the following advantages: by collecting database access information, database device information and network device information, and comprehensively analyzing the collected data, the user access operation features, database operation data and network device operation data are comprehensively analyzed to analyze the data transmission security, the data transmission security is monitored from multiple dimensions of hardware operation data and user data, and thus the analysis efficiency of the data transmission security is improved, and the accuracy of the data transmission security analysis is improved. BRIEF DESCRIPTION OF DRAWINGS

[0032] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0033] Figure 1 The flowchart of the data transmission security monitoring method based on digital twinning of the present embodiment.

[0034] Figure 2 The flowchart of the database feature analysis method of the present embodiment.

[0035] Figure 3 The flowchart of the feature analysis method of the network device information of the present embodiment.

[0036] Figure 4 The flowchart of the analysis method of the transmission security parameters of the present embodiment.

[0037] Figure 5 This is a structural diagram of the data transmission security monitoring device based on digital twins in this embodiment. DETAILED DESCRIPTION

[0038] In order to more clearly illustrate the present invention, the present invention is further described below in conjunction with preferred embodiments and accompanying drawings. Similar components in the accompanying drawings are represented by the same reference numerals. It should be understood by those skilled in the art that the following detailed description is illustrative rather than restrictive and should not be used to limit the scope of protection of the present invention.

[0039] It should be noted that, although the terms "first," "second," and "third" may be used to describe the embodiments of the present application, the description should not be limited to these terms. These terms are merely used to distinguish the descriptions. For example, without departing from the scope of the embodiments of the present application, "first" may also be referred to as "second," and similarly, "second" may also be referred to as "first."

[0040] See also Figure 1 As shown in FIG, the data transmission security monitoring method based on digital twins of this embodiment includes:

[0041] Step S1, collect the database access information, database device information and network device information of the hospital, the database access information includes the access user name, user authority level, access duration, access operation type, the access duration is the duration of each user access to the database, the user authority level includes level one, level two and level three, the user authority level one means that the user is an administrator user, who has the highest authority to access the database, including retrieval, modification, deletion and upload, the user authority level two means that the user is a senior user, who has partial authority to access the database, including retrieval and upload, the user authority level three means that the user is an ordinary user, who only has the authority to retrieve database data, the access operation type includes retrieval, modification, deletion and upload, the database device The information includes storage space occupancy and CPU occupancy. The network device information includes network device operation information and network transmission information. The network transmission information includes message information and actual transmission rate. The message information includes database IP address, access user IP address, data packet size and planned transmission rate. The message information is message information for network transmission using the TCP protocol. The network device operation information includes network device power consumption and network device temperature. The network device is a router, gateway and other equipment installed in the hospital for network transmission of data. The database access information and database device information are collected by importing data through the background of the hospital database management platform. The network device information is collected by importing data through the background of the hospital network device data management platform.

[0042] Specifically, this embodiment is applied to the cloud of the hospital data management system, and collects and analyzes data from the database and network equipment in the hospital to achieve analysis of data transmission security based on comprehensive user access operation data and hardware equipment operation data.

[0043] Please continue reading Figure 1 As shown, the data transmission security monitoring method based on digital twins also includes:

[0044] Step S2: performing feature analysis on the database access information to obtain user access features and user operation features.

[0045] See also Figure 2 As shown, it is a database feature analysis method, including:

[0046] Step S21: Perform feature analysis on database access information to obtain user access features.

[0047] Specifically, in step S21 of this embodiment, the number of times a user accesses the database and performs access operations is counted as the number of user operations, and a feature analysis is performed on the access username, access duration, and number of user operations to obtain a user access feature. The expression of the user access feature is: Where Q(i) represents the user access feature, T(i,j) represents the access duration, NC(i,j) represents the number of user operations, i represents the access user name, j represents the user access number, and j∈N + where j ≤ Nj(i), where Nj(i) represents the number of times a user has accessed the database. The user access count is defined as the number that identifies the user's first database access, and the user operation count is defined as the total number of various operations performed by the user during a single database access. For example, if a user performs two retrieval operations and one upload operation during a single database access, the user operation count is 3.

[0048] Specifically, in step S21 described in this embodiment, the number of user operations and user access characteristics are analyzed by analyzing the database access information, and the user access characteristics are used to represent the characteristic relationship between the user's access time and access operation when the user accesses the database, thereby realizing the analysis of the user access data characteristics, thereby improving the efficiency of the analysis of data transmission security and improving the accuracy of the analysis of data transmission security.

[0049] Please continue reading Figure 2 As shown, the database feature analysis method further includes:

[0050] Step S22: performing feature analysis on the database access information to obtain user operation features.

[0051] Specifically, in step S22 of this embodiment, the total number of times the user access operation type is retrieval is counted as the user retrieval number, the total number of times the user access operation type is modification is counted as the user modification number, the total number of times the user access operation type is deletion is counted as the user deletion number, and the total number of times the user access operation type is upload is counted as the user upload number. The number of user compliance operations and the number of user violation operations are analyzed according to the user authority level, the number of user retrievals, the number of user modifications, the number of user deletions, and the number of user uploads. If the user authority level is level one, the user operation analysis unit sets the number of user compliance operations A1(i)=NA1(i)+NA2(i)+NA3(i)+NA4(i). Set the number of user violation operations A2(i) = 0; if the user authority level is level two, the user operation analysis unit sets the number of user compliance operations A1(i) = NA1(i) + NA4(i), and sets the number of user violation operations A2(i) = NA2(i) + NA3(i); if the user authority level is level three, the user operation analysis unit sets the number of user compliance operations A1(i) = NA1(i), and sets the number of user violation operations A2(i) = NA2(i) + NA3(i) + NA4(i); wherein NA1(i) represents the number of user searches, NA2(i) represents the number of user modifications, NA3(i) represents the number of user deletions, and NA4(i) represents the number of user uploads.

[0052] Specifically, in step S22 of this embodiment, a feature analysis is performed on the user authority level, the number of user searches, the number of user uploads, the number of user compliance operations, and the number of user violation operations to obtain the user operation feature. The expression of the user operation feature is: W(i) = [A2(i) + 1] × [NA1(i) - NA4(i)] / A1(i) 2 , where W(i) represents the user operation characteristics.

[0053] Specifically, in step S22 described in this embodiment, by counting different access operations of users, the number of different user operations is counted, and the number of compliant and illegal user operations is divided according to user permissions, so as to analyze the user operation characteristics, and use the user operation characteristics to represent the characteristic relationship between different user operations, to achieve analysis of user operation preferences, thereby improving the efficiency of data transmission security analysis and improving the accuracy of data transmission security analysis.

[0054] Please continue reading Figure 1 As shown, the data transmission security monitoring method based on digital twins also includes:

[0055] Step S3: Analyze the database load status based on the database device information.

[0056] Specifically, in step S3 of this embodiment, the database load parameter is analyzed based on the storage space occupancy rate and the CPU occupancy rate. The expression of the database load parameter is: P(t)=R2(t) 1-R1(t) , where P(t) represents the database load parameter, R1(t) represents the storage space occupancy, R2(t) represents the CPU occupancy, and t represents the time number. The time number is defined as the number that distinguishes database device information at different times.

[0057] Specifically, in step S3 of this embodiment, the database load parameters are compared and analyzed. If the database load parameter is less than the load threshold, the database load state is determined to be low; otherwise, the database load state is determined to be high. In this embodiment, the load threshold is set to 0.85. It will be understood that this embodiment does not impose a specific limit on the value of the load threshold, and those skilled in the art can freely set it, as long as it satisfies the analysis of the database load state. The load threshold value should be within the range [0.8, 0.9].

[0058] Specifically, in step S3 described in this embodiment, the database load parameters are analyzed by analyzing the database device information, and the database load parameters are used to represent the correlation characteristics between the database resource occupancy rates, thereby analyzing the database load status and realizing the analysis of the load conditions during the operation of the database, thereby improving the efficiency of the analysis of data transmission security and improving the accuracy of the analysis of data transmission security.

[0059] Please continue reading Figure 1 As shown, the data transmission security monitoring method based on digital twins also includes:

[0060] Step S4: analyzing the access address type, transmission rate characteristics, and network device operation characteristics based on the database access information and the network device information.

[0061] See also Figure 3 As shown, it is a feature analysis method for network device information, including:

[0062] Step S41: store the access user name and access user IP address as historical verification information.

[0063] Step S42: Determine the access address type based on the historical verification information.

[0064] Specifically, in step S42 of this embodiment, the number of different access user IP addresses of the same user is counted as the user IP number, and the access address type is determined based on the user IP number and the access user IP address. If the user IP number is less than or equal to the address number threshold and the access user IP addresses all belong to the intranet, the access address type is determined to be Class 1; if the user IP number is greater than the address number threshold and the access user IP addresses all belong to the intranet, the access address type is determined to be Class 2; if there is an access user IP address belonging to the public network, the access address type is determined to be Class 3. In this embodiment, the address number threshold is set to 2. It is understandable that this embodiment does not specifically limit the value of the address number threshold. Those skilled in the art can freely set it as long as it meets the analysis of the access address type. The value of the address number threshold should meet the requirements of [1,3].

[0065] Specifically, in step S42 described in this embodiment, when judging the ownership of the visiting user's IP address, the ownership of the visiting user's IP address is judged based on whether the visiting user's IP address belongs to the range of intranet addresses. If the visiting user's IP address belongs to 10.xxx or 172.16.xx to 172.31.xx or 192.168.xx, the visiting user's IP address belongs to the intranet; otherwise, the visiting user's IP address belongs to the public network, and x represents any number between 0 and 255.

[0066] Specifically, in step S42 described in this embodiment, the access address type is analyzed by analyzing historical verification information, and the access address type is divided into three categories according to the changes in user access IP and internal and external network access, so as to realize the analysis of user access address changes, thereby improving the efficiency of data transmission security analysis and improving the accuracy of data transmission security analysis.

[0067] See also Figure 3 As shown, the feature analysis method of the network device information further includes:

[0068] Step S43: Perform feature analysis on the network transmission information to obtain transmission rate features.

[0069] Specifically, in step S43 of this embodiment, a characteristic analysis is performed on the planned transmission rate, the actual transmission rate, and the data packet size to obtain a transmission rate characteristic. The expression of the transmission rate characteristic is: Where D(t) represents the transmission rate characteristic, V1(t) represents the actual transmission rate, V2(t) represents the planned transmission rate, M represents the packet size, z represents the characteristic analysis parameter, y∈N and y≤Y, and Y represents the characteristic analysis threshold, 5≤Y≤10. It will be understood that the value of the characteristic analysis threshold is not specifically limited in this embodiment, and those skilled in the art can freely set it as long as it satisfies the analysis of the transmission rate characteristic. The optimal value of the characteristic analysis threshold is: Y=7.

[0070] Specifically, in step S43 described in this embodiment, the network transmission information is analyzed to analyze the transmission rate characteristics, and the transmission rate characteristics are used to represent the difference between the planned data and the actual transmission situation during network transmission, thereby achieving a comprehensive analysis of the network transmission plan, thereby improving the efficiency of the analysis of data transmission security and improving the accuracy of the analysis of data transmission security.

[0071] See also Figure 3 As shown, the feature analysis method of the network device information further includes:

[0072] Step S44: performing feature analysis on the network device operation information to obtain network device operation features.

[0073] Specifically, in step S44 of this embodiment, the network device power consumption and the network device temperature are analyzed to obtain the network device operation characteristics. The expression of the network device operation characteristics is: S(t)=[h1(t)+h2(t)] / 2, where S(t) represents the network device operation characteristics, h1(t) represents the power consumption fluctuation parameter, h2(t) represents the temperature fluctuation parameter, H1(t) represents the power consumption of the network device, and H2(t) represents the temperature of the network device.

[0074] Specifically, in step S44 described in this embodiment, the network device operation information is analyzed to analyze the network device operation characteristics, and the network device operation characteristics are used to represent the characteristic relationship between the power consumption of the network device during operation and the device temperature, thereby achieving a comprehensive analysis of the network device operation status, thereby improving the analysis efficiency of data transmission security and improving the accuracy of data transmission security analysis.

[0075] Please continue reading Figure 1 As shown, the data transmission security monitoring method based on digital twins also includes:

[0076] Step S5: performing coupling analysis on user access characteristics, access address type and transmission rate characteristics to obtain transmission security parameters, and improving the coupling analysis process according to user operation characteristics, database load status and network equipment operation characteristics.

[0077] See also Figure 4 As shown, it is a method for analyzing transmission security parameters, including:

[0078] Step S51 : performing coupling analysis on user access characteristics, access address type and transmission rate characteristics to obtain transmission security parameters.

[0079] Specifically, in step S51 of this embodiment, a coupling analysis is performed on the user access characteristics, the access address type, and the transmission rate characteristics to obtain a transmission security parameter. The expression of the transmission security parameter is: Where, F(i,j) represents the transmission security parameter, U(i,j) represents the set of time numbers corresponding to the user access time, K(i) represents the access address type parameter. When the access address type is Class 1, K(i) = k1 × e, when the access address type is Class 2, K(i) = k2 × e, and when the access address type is Class 3, K(i) = k3 × e. k1 represents the first address parameter, 0.9≤k1≤1.1, k2 represents the second address parameter, 1.1<k2≤1.3, and k3 represents the third address parameter, 1.3<k3≤1.5. It is understood that the values ​​of the address parameters are not specifically limited in this embodiment. Those skilled in the art can freely set them as long as they meet the analysis of the transmission security parameters. The optimal values ​​of the address parameters are: k1 = 1, k2 = 1.2, and k3 = 1.4.

[0080] Specifically, in step S51 described in this embodiment, the transmission security parameters are analyzed by coupling analysis of user access characteristics, access address type and transmission rate characteristics, and the transmission security parameters are used to represent the characteristic relationship between user access conditions and network transmission conditions, so as to realize the analysis of transmission security by integrating user data and network transmission data, thereby improving the analysis efficiency of data transmission security and improving the accuracy of data transmission security analysis.

[0081] Please continue reading Figure 4 As shown, the method for analyzing the transmission security parameters further includes:

[0082] Step S52: Determine the safety of the user operation based on the user operation characteristics.

[0083] Specifically, in step S52 of this embodiment, the user operation security is determined based on the user operation characteristics. If the user operation characteristics are less than the operation security threshold, the user operation security is determined to be low, and the analysis process of the transmission security parameter is improved. The expression of the improved transmission security parameter is: Conversely, it is determined that the user operation safety is high; in the formula, NP(i) represents the number of user IPs. In this embodiment, the operation safety threshold is set to 0.3, and it can be understood that the value of the operation safety threshold is not specifically limited in this embodiment, and a person skilled in the art can freely set it, as long as the analysis of the user operation safety is met. The value of the operation safety threshold should satisfy that it belongs to [0.2, 0.4].

[0084] Specifically, in step S52, the user operation safety is analyzed by analyzing the user operation characteristics, the safety analysis of the user operation data is realized, and the analysis process of the transmission safety parameter is improved. The improved transmission safety parameter is related to the data characteristics of the user operation, so as to improve the analysis efficiency of the data transmission safety and improve the accuracy of the analysis of the data transmission safety.

[0085] Please continue to refer to Figure 4 As shown in the figure, the analysis method of the transmission safety parameter further includes:

[0086] In step S53, the load matching type is determined according to the database load state and the network device running characteristics.

[0087] Specifically, in step S53, the load matching parameter is analyzed according to the database load state and the network device running characteristics, and the load matching type is determined according to the load matching parameter. If the database load state is high load and the network device running characteristics are greater than the running characteristics threshold, it is determined that the load matching type is type one, and the analysis process of the transmission safety parameter is further improved. The expression of the improved transmission safety parameter is Conversely, it is determined that the load matching type is type two; in the formula, G(i, j) represents the load matching parameter, In this embodiment, the running characteristics threshold is set to 0.15, and it can be understood that the value of the running characteristics threshold is not specifically limited in this embodiment, and a person skilled in the art can freely set it, as long as the analysis of the load matching type is met. The value of the running characteristics threshold should satisfy that it belongs to [0.1, 0.2].

[0088] Specifically, in step S53, the load matching type is analyzed by analyzing the database load state and the network device running characteristics. The load matching type is divided into two types according to the running load of the database and the network device during user access, and the transmission safety parameter is further improved in the case of similar load conditions. The improved transmission safety parameter is related to the load conditions of the hardware device, so as to improve the analysis efficiency of the data transmission safety and improve the accuracy of the analysis of the data transmission safety.

[0089] Please continue to refer to Figure 4 As shown in the figure, the analysis method of the transmission safety parameter further includes:

[0090] Step S54: determining the operation stability of the device according to the operation characteristics of the network device.

[0091] Specifically, in step S54 of this embodiment, the device stability parameter is analyzed based on the network device operation characteristics. The expression of the device stability parameter is: The device stability is determined based on the device stability parameter. If the device stability parameter is less than or equal to the stability threshold, the device stability is determined to be stable. The analysis process of the load matching parameter is improved. The expression of the improved load matching parameter is: Otherwise, the device stability is determined to be unstable. In this embodiment, the stability threshold is set to 0.2. It is understandable that the value of the stability threshold is not specifically limited in this embodiment and can be freely set by those skilled in the art as long as it satisfies the analysis of device stability. The value of the stability threshold should be within the range of [0.1, 0.3].

[0092] Specifically, in step S54 described in this embodiment, the operating characteristics of the network device are analyzed to analyze the device stability parameters, and the device stability parameters are used to represent the relationship between the analysis accuracy of the network device operating characteristics and the change characteristics of the user access time. When the operating characteristics of the network device vary greatly during the user access time, the analysis process of the load matching parameters is improved so that the improved load matching parameters are related to the changes in the operating data of the network device during the user access period, thereby improving the analysis efficiency of the data transmission security and improving the accuracy of the data transmission security analysis.

[0093] Please continue reading Figure 1 As shown, the data transmission security monitoring method based on digital twins also includes:

[0094] Step S6: Analyze the data transmission security status according to the transmission security parameter and output it.

[0095] Specifically, in step S6 of this embodiment, the data transmission security status is analyzed based on the transmission security parameter. If the transmission security parameter is less than the security status threshold, the data transmission security status is determined to be secure; otherwise, the data transmission security status is determined to be unsecure. In this embodiment, the security status threshold is set to 0.7. It will be understood that this embodiment does not impose a specific limit on the value of the security status threshold, and those skilled in the art can freely set it, as long as it satisfies the analysis of the data transmission security status. The value of the security status threshold should fall within the range [0.6, 0.9].

[0096] See also Figure 5 As shown in FIG, it is a data transmission security monitoring device based on digital twins in this embodiment, including:

[0097] Data collection module, used to collect the hospital's database access information, database equipment information and network equipment information;

[0098] A database analysis module, used for performing feature analysis on database access information to obtain user access features and user operation features, the database analysis module being connected to the data acquisition module;

[0099] A load analysis module, used for analyzing the database load status based on the database device information, the load analysis module being connected to the data acquisition module;

[0100] A device analysis module, configured to analyze access address types, transmission rate characteristics, and network device operation characteristics based on database access information and network device information, the device analysis module being connected to the data acquisition module;

[0101] A coupling analysis module is used to perform coupling analysis on user access characteristics, access address type, and transmission rate characteristics to obtain transmission security parameters, and improve the coupling analysis process based on user operation characteristics, database load status, and network device operation characteristics. The coupling analysis module is connected to the database analysis module, load analysis module, and device analysis module;

[0102] The status output module is used to analyze the data transmission security status according to the transmission security parameters and output the status. The status output module is connected to the coupling analysis module.

[0103] An embodiment of the present application also provides a computer-readable storage medium storing instructions, which, when executed on a computer, enables the computer to execute the data transmission security monitoring method based on digital twins as described in the above method embodiment.

[0104] Those skilled in the art will appreciate that all or some of the steps and systems in the method disclosed above can be implemented as software, firmware, hardware, and appropriate combinations thereof. Some physical components or all physical components can be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or implemented as hardware, or implemented as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, and the computer-readable medium can include computer storage media (or non-transitory media) and communication media (or temporary media). As known to those skilled in the art, the term computer storage media is included in any method or technology for storing information (such as a computer-readable program, a data structure, a program module, or other data) and is volatile and non-volatile, removable, and non-removable. Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory, or other memory technology, CD-ROM, digital versatile disks (DVD), or other optical disk storage, magnetic cassettes, magnetic tapes, disk storage, or other magnetic storage devices, or any other medium that can be used to store desired information and can be accessed by a computer. Furthermore, as is well known to those skilled in the art, communication media typically embodies computer-readable programs, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.

[0105] Obviously, the above embodiments of the present invention are merely examples for clearly illustrating the present invention, and are not limitations on the implementation methods of the present invention. For ordinary technicians in this field, other different forms of changes or modifications can be made based on the above description. It is impossible to list all the implementation methods here. All obvious changes or modifications derived from the technical solution of the present invention are still within the scope of protection of the present invention.

Claims

1. A data transmission security monitoring method based on digital twins, characterized in that: include: Collect the hospital's database access information, database device information, and network device information; Perform feature analysis on database access information to obtain user access features and user operation features; Analyze database load status based on database device information; Analyze access address types, transmission rate characteristics, and network device operation characteristics based on database access information and network device information; Conduct coupling analysis on user access characteristics, access address type, and transmission rate characteristics to obtain transmission security parameters, and improve the coupling analysis process based on user operation characteristics, database load status, and network equipment operation characteristics; Analyze the data transmission security status according to the transmission security parameters and output; The number of times a user accesses the database each time is counted as the number of user operations, and feature analysis is performed on the access username, access duration, and number of user operations to obtain the user access feature Q(i); Perform feature analysis on user authority level, user search quantity NA1(i), user upload quantity NA4(i), user compliance operation number A1(i), and user violation operation number A2(i) to obtain user operation feature W(i); The number of different access user IP addresses of the same user is counted as the user IP number, and the access address type is determined based on the user IP number and the access user IP address. If the user IP number is less than or equal to the address number threshold and the access user IP addresses all belong to the intranet, the access address type is determined to be Class 1; if the user IP number is greater than the address number threshold and the access user IP addresses all belong to the intranet, the access address type is determined to be Class 2; if there is an access user IP address belonging to the public network, the access address type is determined to be Class 3; Perform feature analysis on the planned transmission rate, actual transmission rate, and packet size to obtain the transmission rate feature D(t), where t represents the time number. Perform characteristic analysis on the power consumption and temperature of network devices to obtain the network device operation characteristics S(t); A coupled analysis is performed on user access characteristics, access address type, and transmission rate characteristics to obtain a transmission security parameter. The expression of the transmission security parameter is: , where F(i,j) represents the transmission security parameter, U(i,j) represents the set of time numbers corresponding to the user access time, K(i) represents the access address type parameter, when the access address type is type one, K(i)=k1×e, when the access address type is type two, K(i)=k2×e, when the access address type is type three, K(i)=k3×e, k1 represents the first address parameter, k2 represents the second address parameter, k3 represents the third address parameter, T(i,j) represents the access duration, NP(i) represents the number of user IP addresses, and j represents the number of user access times; The user operation security is judged based on the user operation characteristics. If the user operation characteristics are less than the operation security threshold, the user operation security is judged to be low, and the analysis process of the transmission security parameter is improved. The expression of the improved transmission security parameter is: ; On the contrary, it is determined that the user operation is highly secure; The load matching parameters are analyzed according to the database load status and the network equipment operation characteristics, and the load matching type is determined based on the load matching parameters. If the database load status is high and the network equipment operation characteristics are greater than the operation characteristic threshold, the load matching type is determined to be Class I. The analysis process of the transmission security parameters is further improved. The expression of the improved transmission security parameters is: ; Otherwise, the load matching type is determined to be Class II; where G(i,j) represents the load matching parameter, , P(t) represents the database load parameter, P(t)=R2(t) 1-R1(t) , R1(t) represents the storage space occupancy, R2(t) represents the CPU occupancy; The data transmission security status is analyzed based on the transmission security parameter. If the transmission security parameter is less than the security status threshold, the data transmission security status is determined to be transmission secure; otherwise, the data transmission security status is determined to be transmission unsafe.

2. The data transmission security monitoring method based on digital twins according to claim 1 is characterized in that: The device stability parameter is analyzed based on the network device operation characteristics. The expression of the device stability parameter is: , Y represents the characteristic analysis threshold, and the device stability is judged based on the device stability parameter. If the device stability parameter is less than or equal to the stability threshold, the device stability is determined to be stable, and the analysis process of the load matching parameter is improved. The expression of the improved load matching parameter is: ; Otherwise, the equipment stability is judged as unstable operation.

3. A data transmission security monitoring device based on digital twins, applied to the data transmission security monitoring method based on digital twins according to any one of claims 1-2, characterized in that: include: Data collection module, used to collect the hospital's database access information, database equipment information and network equipment information; Database analysis module, used to perform feature analysis on database access information to obtain user access features and user operation features; A load analysis module is used to analyze the database load status based on database device information; Device analysis module, used to analyze access address type, transmission rate characteristics and network device operation characteristics based on database access information and network device information; A coupling analysis module is used to perform coupling analysis on user access characteristics, access address type, and transmission rate characteristics to obtain transmission security parameters, and to improve the coupling analysis process based on user operation characteristics, database load status, and network device operation characteristics; The status output module is used to analyze the data transmission security status according to the transmission security parameters and output it.

4. A storage medium, characterized in that Instructions are stored, which, when executed on a computer, enable the computer to execute the digital twin-based data transmission security monitoring method as described in any one of claims 1 to 3.

Citation Information

Patent Citations

  • Internet management platform based on digital twinning

    CN115102747A

  • Building data information security access control method, device, equipment and medium

    CN118250048A

  • Data link service processing system and method for networked encrypted transmission

    WO2023216424A1