Network security risk processing method and device for medical equipment, equipment and medium

By constructing a mapping relationship between device security hazards and personal safety hazards, the cybersecurity risks of medical IoT devices are assessed and addressed, solving the problem that existing technologies have failed to effectively consider physical and personal safety risks, and achieving more efficient risk management and resource allocation.

CN120934819APending Publication Date: 2025-11-11HENAN ACADEMY OF MEDICAL SCIENCES
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511093970.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-06
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Existing cybersecurity risk assessments for medical IoT devices fail to effectively consider the physical security risks of high-value medical devices and the personal safety risks to patients, resulting in improper allocation of security resources and an inability to effectively respond to potential medical liability incidents.

Method used

By constructing a mapping relationship between the degree of equipment safety hazard and the degree of personal safety hazard, the degree of equipment safety hazard is assessed using a first preset information database, and the degree of personal safety hazard is assessed using a second preset information database, thereby determining targeted response strategies and handling operations.

Benefits of technology

It improves the comprehensiveness, accuracy, and interpretability of cybersecurity risk handling in the healthcare industry, ensuring that security operations personnel can focus on urgent and important cybersecurity risks, improving the efficiency of security risk handling, and reducing the occurrence of secondary security incidents.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120934819A_ABST
    Figure CN120934819A_ABST
Patent Text Reader

Abstract

The invention discloses a network security risk processing method and device for medical equipment, equipment and a medium, and relates to the technical field of computers, and the method comprises the steps: monitoring a target network security risk event of current target medical equipment; determining a target equipment safety hazard degree caused by the target network safety risk event to the target medical equipment based on a first preset information base; the first preset information base is an information base constructed based on a mapping relation between different network security risk events and different equipment security hazard degrees; determining a target personal safety hazard degree caused by the target equipment safety hazard degree to the patient based on a second preset information base; the second preset information base is an information base constructed based on a mapping relation between different equipment safety hazard degrees and different personal safety hazard degrees; and determining a response strategy based on the target equipment safety hazard degree and the target personal safety hazard degree to complete network safety protection. According to the invention, the comprehensiveness of risk processing in the medical industry is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer technology, and in particular to methods, apparatus, equipment and media for handling network security risks of medical devices. Background Technology

[0002] With the increasing penetration of the Internet into the healthcare industry, many medical IoT (Internet of Things) devices are gradually being connected to hospital networks, enabling various types of information sharing and efficient utilization. However, this also increases the network attack exposure surface and potential attack paths of these devices.

[0003] Current risk assessments for healthcare IoT devices often employ traditional cybersecurity risk assessment schemes. These schemes assess risk solely based on two dimensions: the likelihood and severity of attacks on hospital network information systems. The likelihood considers factors such as the probability of an attack, the complexity of its execution, and the conditions under which it can be carried out. The severity primarily considers damage to the confidentiality, integrity, and availability of the information system. However, this approach fails to consider the specific characteristics of the healthcare industry. It neglects not only the physical security risks posed by cyberattacks to high-value medical equipment but also the risks to the personal safety of service personnel and patients. This leads to biases in the assessment and handling of security incidents by cybersecurity operations managers, preventing them from focusing security resources on resolving security incidents that could result in medical malpractice. Summary of the Invention

[0004] In view of this, the purpose of this invention is to provide a method, apparatus, device, and medium for handling cybersecurity risks in medical devices, which can effectively improve the comprehensiveness, accuracy, and interpretability of cybersecurity risk handling in the medical industry, and enable security operations personnel to focus more on urgent and more important cybersecurity risks when handling security risks, thereby improving the efficiency of security risk handling and reducing secondary security disasters caused by cybersecurity risks. The specific solution is as follows:

[0005] Firstly, this application provides a method for handling cybersecurity risks of medical devices, including:

[0006] Monitor whether the target medical device has experienced a cybersecurity risk incident;

[0007] If a network security risk event is detected in the target medical device, the degree of security harm caused by the network security risk event to the target medical device is determined based on a first preset information database, thereby obtaining the degree of security harm to the target device; the first preset information database is an information database constructed based on the mapping relationship between different network security risk events and the degree of security harm to different devices;

[0008] Based on the second preset information database, the degree of safety hazard posed by the target device to the patient is determined, thereby obtaining the degree of personal safety hazard; the second preset information database is an information database constructed based on the mapping relationship between different degrees of safety hazard of devices and different degrees of personal safety hazard.

[0009] Based on the degree of security risk to the target device and the degree of security risk to the target person, a response strategy for the network security risk event of the target is determined, and corresponding security processing operations are performed based on the response strategy to complete the network security protection of the target medical device.

[0010] Optionally, before determining the degree of security harm caused by the target cybersecurity risk event to the target medical device based on the first preset information database, the method further includes:

[0011] Information is collected from various basic and medical devices connected to the hospital network to obtain equipment asset information corresponding to the hospital.

[0012] Based on the hospital's medical equipment operation and maintenance information, the safety hazard levels of multiple devices and the scores corresponding to each safety hazard level are determined to obtain the first hazard level information;

[0013] Based on the first degree of harm information and the equipment asset information, the mapping relationship between different network security risk events and different degrees of equipment security harm is sorted out for each type of medical equipment to obtain the first target mapping relationship;

[0014] The first target mapping relationship is analyzed by rules to construct the first preset information database.

[0015] Optionally, the step of mapping different cybersecurity risk events to different security risk levels of different devices based on the first severity information and the device asset information includes:

[0016] For any type of medical device, based on the first severity information and the device asset information corresponding to the current type of medical device, including device name, device category, attack event name, attack event type, number of attack events, vulnerability name, vulnerability type, vulnerability risk, number of vulnerabilities, recovery time, and recovery action, a mapping relationship between different network security risk events and different device security severity is sorted out to obtain the first target mapping relationship.

[0017] Optionally, before determining the degree of safety hazard posed to the patient by the target device based on the second preset information database, the method further includes:

[0018] Based on the hospital's safety management regulations, multiple degrees of personal safety hazard and corresponding scores for each degree of personal safety hazard are determined to obtain second degree of hazard information;

[0019] Based on the second degree of hazard information, the equipment hazard risk assessment information in the equipment asset information, and the equipment usage scenario information, the mapping relationship between different equipment safety hazard levels and different personal safety hazard levels is sorted out for each type of medical equipment to obtain the second target mapping relationship;

[0020] The second target mapping relationship is analyzed by rules to construct the second preset information database.

[0021] Optionally, based on the second hazard level information, the equipment hazard risk assessment information in the equipment asset information, and the equipment usage scenario information, the mapping relationship between different equipment safety hazard levels and different personal safety hazard levels is sorted out for each type of medical equipment, including:

[0022] For any type of medical device, based on the second degree of hazard information, the equipment hazard risk assessment results corresponding to the current type of medical device in the equipment asset information, the equipment name, equipment category, department of use, and usage status, a mapping relationship from the degree of equipment safety hazard to the degree of personal safety hazard is sorted out to obtain the second target mapping relationship.

[0023] Optionally, the step of performing rule analysis on the first target mapping relationship to construct the first preset information database includes:

[0024] By performing rule-based parsing on the determined first target mapping relationship, the corresponding first rule parsing result is obtained;

[0025] The first preset information base is constructed based on the parsing results of the first rule; wherein, the rule categories in the first preset information base include single rules, compound rules, and nested rules;

[0026] Accordingly, the step of performing rule analysis on the second target mapping relationship to construct the second preset information database includes:

[0027] By performing rule-based parsing on the determined second target mapping relationship, the corresponding second rule parsing results are obtained;

[0028] The second preset information base is constructed based on the parsing results of the second rule; wherein, the rule categories in the second preset information base include single rules, compound rules and nested rules.

[0029] Optionally, determining the response strategy for the target network security risk event based on the degree of security threat to the target device and the degree of security threat to the target person includes:

[0030] By analyzing the attack probability and severity of the target network security risk events on the hospital's network information system, the severity of the corresponding target events is determined, and a first target score and a first weight corresponding to the severity of the target events are determined.

[0031] Based on the first preset information database, a second target score and a second weight are determined corresponding to the degree of safety hazard of the target medical device.

[0032] Based on the second preset information database, a third target score and a third weight are determined corresponding to the degree of personal safety hazard posed by the target medical device.

[0033] The target risk value corresponding to the current target medical device is determined based on the first target score, the first weight, the second target score, the second weight, the third target score, and the third weight.

[0034] Based on the target risk value and the preset response measure library, a response strategy is determined for the target network security risk event.

[0035] Secondly, this application provides a cybersecurity risk handling device for medical devices, comprising:

[0036] The event monitoring module is used to monitor whether the target medical device has experienced a network security risk event.

[0037] The first hazard degree determination module is used to determine the degree of security hazard caused to the target medical device by the target network security risk event based on a first preset information database if the target medical device is detected to have experienced the target network security risk event, thereby obtaining the degree of security hazard of the target device; the first preset information database is an information database constructed based on the mapping relationship between different network security risk events and different degrees of security hazard of different devices;

[0038] The second hazard degree determination module is used to determine the degree of safety hazard posed by the target device to the patient based on a second preset information database, thereby obtaining the target personal safety hazard degree; the second preset information database is an information database constructed based on the mapping relationship between different device safety hazard degrees and different personal safety hazard degrees;

[0039] The event response module is used to determine a response strategy for the target network security risk event based on the degree of security threat to the target device and the degree of personal safety threat to the target, and to execute corresponding security processing operations based on the response strategy to complete the network security protection of the target medical device.

[0040] Thirdly, this application provides an electronic device, comprising:

[0041] Memory, used to store computer programs;

[0042] A processor is used to execute the computer program to implement the steps of the aforementioned method for handling cybersecurity risks of medical devices.

[0043] Fourthly, this application provides a computer-readable storage medium for storing a computer program, which, when executed by a processor, implements the steps of the aforementioned method for handling cybersecurity risks of medical devices.

[0044] As can be seen, in this application, the system monitors whether a target cybersecurity risk event has occurred on the current target medical device. If such an event is detected, the system determines the degree of security harm caused to the target medical device by the cybersecurity risk event based on a first preset information database, thus obtaining the degree of security harm to the target device. The first preset information database is a database constructed based on the mapping relationship between different cybersecurity risk events and different degrees of security harm to different devices. Based on a second preset information database, the system determines the degree of security harm caused to the patient by the degree of security harm to the patient, thus obtaining the degree of personal safety harm to the patient. The second preset information database is a database constructed based on the mapping relationship between different degrees of security harm to different degrees of personal safety harm to different devices. Based on the degree of security harm to the target device and the degree of personal safety harm to the patient, the system determines a response strategy for the target cybersecurity risk event and executes corresponding security processing operations based on the response strategy to complete the cybersecurity protection of the current target medical device. In other words, this application first monitors whether a target cybersecurity risk event has occurred on the target medical device. If so, it uses a first preset information database to determine the degree of security harm caused to the target medical device by the cybersecurity risk event. Then, it uses a second preset information database to determine the degree of security harm caused to the patient by the degree of security harm caused by the target device. Finally, it combines the degree of security harm caused by the target device and the degree of personal safety harm caused to the patient to determine a response strategy and execute corresponding security processing operations. This effectively improves the comprehensiveness, accuracy, and interpretability of cybersecurity risk handling in the medical industry, and allows security operations personnel to focus more on urgent and more important cybersecurity risks when handling security risks, thereby improving the efficiency of security risk handling and reducing secondary security disasters caused by cybersecurity risks. Attached Figure Description

[0045] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0046] Figure 1 A flowchart of a method for handling cybersecurity risks of medical devices provided in this application;

[0047] Figure 2 A schematic diagram of a network security risk handling device for medical devices provided in this application;

[0048] Figure 3 This application provides a structural diagram of an electronic device. Detailed Implementation

[0049] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0050] Current risk assessments for medical IoT devices often employ traditional cybersecurity risk assessment schemes. These schemes assess risk solely based on two dimensions: the likelihood and severity of attacks on hospital network information systems. The likelihood considers factors such as the probability of an attack, the complexity of the attack, and the conditions under which it can be carried out. The severity primarily considers damage to the confidentiality, integrity, and availability of the information system. However, this approach fails to consider the specific characteristics of the healthcare industry. It neglects not only the physical security risks posed by cyberattacks to high-value medical equipment but also the personal safety risks to service personnel and patients, resulting in a poor user experience. Therefore, this application provides a cybersecurity risk management solution for medical devices that effectively improves the comprehensiveness, accuracy, and interpretability of cybersecurity risk management in the healthcare industry.

[0051] See Figure 1 As shown in the figure, an embodiment of the present invention discloses a method for handling network security risks of medical devices, including:

[0052] Step S11: Monitor whether the target medical device has experienced a network security risk event.

[0053] In this embodiment, it is understood that the target medical device is a medical IoT device, including but not limited to medical imaging equipment, disease monitoring equipment, medical testing equipment, and medical treatment equipment. Target cybersecurity risk events include network attack events and vulnerabilities. That is, this embodiment monitors different types of medical IoT devices in hospitals and other medical institutions to detect whether network attack events or vulnerabilities have occurred.

[0054] Step S12: If a network security risk event is detected in the target medical device, the degree of security harm caused by the network security risk event to the target medical device is determined based on the first preset information database, and the degree of security harm of the target device is obtained; the first preset information database is an information database constructed based on the mapping relationship between different network security risk events and different degrees of security harm of devices.

[0055] In this embodiment, if a network attack or vulnerability is detected in the target medical device, a first preset information database is first used to determine the degree of security harm caused to the target medical device by the network security risk event. Regarding the first preset information database, taking a hospital as an example, information needs to be collected on various basic devices and medical devices connected to the hospital's network to obtain equipment asset information corresponding to the hospital; based on the hospital's medical device operation and maintenance information, multiple degrees of security harm for each device and their corresponding scores are determined to obtain first degree of harm information; based on the first degree of harm information and the equipment asset information, mapping relationships between different network security risk events and different degrees of security harm for each type of medical device are analyzed to obtain a first target mapping relationship; rule analysis is performed on the first target mapping relationship to construct the first preset information database. Furthermore, when sorting out the mapping relationship, for any type of medical device, based on the first degree of harm information and the device name, device category, attack event name, attack event type, number of attack events, vulnerability name, vulnerability type, vulnerability risk, number of vulnerabilities, recovery time, and recovery action corresponding to the current type of medical device in the device asset information, the mapping relationship between different network security risk events and different device security harm levels is sorted out to obtain the first target mapping relationship.

[0056] It is further important to understand that, in the process of constructing the first preset information database, the collection of equipment asset information mainly involves collecting asset information of various networked devices. This includes asset information of traditional information infrastructure equipment (i.e., basic equipment) such as office terminals, servers, and network devices, as well as asset information of IoT devices connected to the hospital's network, including medical imaging equipment, patient monitoring equipment, medical testing equipment, and medical treatment equipment. The asset information registered during the collection process needs to include: equipment purpose, department using the equipment, usage status, asset value, and asset use value. The asset value can include the original value at the time of purchase and the present value formed according to the corresponding depreciation criteria. The asset use value is the value generated by the daily operation of the medical equipment. Regarding the first level of danger information determined based on the hospital's medical equipment operation and maintenance information, an implementable method for determining the level of danger information is shown in Table 1 below. In Table 1, different equipment safety hazard levels (1, 2, 3, 4) refer to different levels of equipment safety hazard.

[0057] Table 1

[0058]

[0059] As shown in Table 1, the higher the equipment security hazard level, the greater the degree of equipment security hazard, the greater the impact, and the higher the score. Next, it is necessary to further establish a mapping relationship between network attacks and equipment security hazards to build a rule base for equipment security hazard risk assessment, i.e., the first preset information base. Specifically, based on the types of network attack events and existing vulnerabilities occurring with various medical devices, and combined with the equipment's own security defense measures and their impact on equipment performance and functionality, a mapping relationship between equipment hazards and personal safety hazards is established item by item. This mapping relationship consists of mapping rules, and all rules form a rule set and rule base, i.e., the first preset information base.

[0060] It's important to understand that a mapping rule R = {A (equipment asset), C (mapping conditions), S (assessment level)} consists of three elements: equipment asset information, mapping conditions, and assessment level. If an equipment asset meets specific mapping conditions, it can be mapped to the corresponding level. Here, equipment asset (A) refers to the medical equipment on the hospital's intranet and its attribute descriptions, including: equipment name, equipment category, attack event name, attack event type, number of attack events, vulnerability name, vulnerability type, vulnerability risk level, number of vulnerabilities, recovery time, recovery action, recovery time, and recovery personnel; mapping conditions (C) refer to the equipment asset's attribute values ​​meeting specific conditions or a set of specific conditions; and assessment level (S) refers to the equipment security hazard level in Table 1.

[0061] Regarding this mapping rule, taking medical-grade CT (Computed Tomography) equipment as an example, the following mapping rule can be established based on the number of high-risk vulnerabilities:

[0062] Rule C1: Vulnerability risk level equals high risk;

[0063] Rule C2: The number of vulnerabilities is greater than one;

[0064] Rule C3: Restore action equals automatic restore;

[0065] Rule C4: Recovery time is less than 30 minutes;

[0066] Set the relationship between rules C1, C2, C3, and C4 as AND;

[0067] The configuration mapping result evaluation level (S) is: the evaluation level (S) is equipment safety hazard level 2. Then, when the CT equipment meets the above rules C1, C2, C3 and C4 at the same time, it will be mapped to equipment safety hazard level 2.

[0068] Following the mapping rules described above, a mapping relationship can also be established for a specific new vulnerability. Taking medical CT equipment as an example, the following mapping rules can be established for a specific high-risk vulnerability:

[0069] Rule C1: The vulnerability name equals **;

[0070] Rule C2: Vulnerability risk level equals high risk;

[0071] Set the relationship between rule C1 and rule C2 as AND;

[0072] The configuration mapping result evaluation level (S) is: evaluation level (S) is equipment safety hazard level 4; then when the CT equipment meets both rule C1 and rule C2 above, it will be mapped to equipment safety hazard level 4.

[0073] Following the mapping rules described above, we can also establish mapping relationships for specific network attacks. Taking medical CT equipment as an example, we can establish the following mapping rules for a specific network attack:

[0074] Rule C1: Attack name equals **;

[0075] Rule C2: Attack event type equals ransomware;

[0076] Set the relationship between rule C1 and rule C2 as AND;

[0077] The configuration mapping result evaluation level (S) is: evaluation level (S) is equipment safety hazard level 4; then when the CT equipment meets both rule C1 and rule C2 above, it will be mapped to equipment safety hazard level 4.

[0078] Furthermore, it should be noted that in this embodiment, the construction of the first preset information base first involves parsing the determined first target mapping relationship to obtain the corresponding first rule parsing result; then, the first preset information base is constructed based on the first rule parsing result. The rule categories in the first preset information base include single rules, composite rules, and nested rules. That is, the information base contains not only single rules (such as rule C1 in the example above), but also composite rules and nested rules. Specifically, several rules can be combined to define a composite rule, which is composed of several simple rules, and the relationships between the simple rules are defined, such as whether the simple rules are ANDed (simultaneously satisfied) or ORed (partially satisfied). In addition to the composite rules mentioned above, nested rules can also be defined. Each rule in a composite rule may be a simple rule, a composite rule, or a combination of simple and composite rules; that is, a composite rule can participate in the construction of other composite rules. Based on the above principles, mapping rules for assessing the security hazard level of various network attacks and vulnerabilities are established to obtain the first preset information base.

[0079] Step S13: Based on the second preset information database, determine the degree of safety hazard posed by the target device to the patient, and obtain the degree of personal safety hazard posed by the target device; the second preset information database is an information database constructed based on the mapping relationship between different degrees of safety hazard posed by different devices and different degrees of personal safety hazard posed by different devices.

[0080] Specifically, in this embodiment, if a network attack or vulnerability is detected in the target medical device, it is necessary not only to use a first preset information database to determine the degree of security hazard posed by the target device, but also to use a second preset information database to determine the degree of personal safety hazard posed to patients (and / or service personnel, including but not limited to doctors and nurses). Regarding the second preset information database, taking a hospital as an example, it is necessary to determine multiple degrees of personal safety hazard and their corresponding scores based on the hospital's security management regulations to obtain second hazard level information; based on the second hazard level information, the equipment hazard risk assessment information in the equipment asset information, and the equipment usage scenario information, a mapping relationship between different equipment security hazard levels and different personal safety hazard levels is established for each type of medical device to obtain a second target mapping relationship; rule analysis is performed on the second target mapping relationship to construct the second preset information database. Furthermore, when sorting out the mapping relationship, for any type of medical device, based on the second degree of hazard information, the equipment hazard risk assessment results corresponding to the current type of medical device in the equipment asset information, the equipment name, equipment category, department of use, and usage status, the mapping relationship from the degree of equipment safety hazard to the degree of personal safety hazard is sorted out to obtain the second target mapping relationship.

[0081] It is further important to understand that, in the process of constructing the second preset information database, regarding the second degree of danger information determined based on the hospital's safety management regulations, an implementable method for determining the degree of danger information is shown in Table 2 below. In Table 2, different levels of personal safety hazard (1, 2, 3, 4) refer to different degrees of equipment safety hazard.

[0082] Table 2

[0083]

[0084] As shown in Table 2, the higher the level of personal safety hazard, the greater the degree of equipment safety hazard, the greater the impact, and the higher the score. Following the same approach as establishing the equipment safety hazard level classification mapping relationship above, a further mapping relationship between equipment safety hazards and personal safety hazards is established, along with a rule base for conducting personal safety risk assessments, i.e., the second pre-set information base. Specifically, based on the equipment hazard assessment results of medical equipment assets, combined with usage scenario information such as equipment purpose, department of use, and usage status, the mapping relationship between equipment hazards and personal safety hazards is established item by item. This mapping relationship consists of mapping rules, and all rules form a rule set and rule base, i.e., the second pre-set information base.

[0085] It's important to understand that a mapping rule R = {A (equipment asset), C (mapping conditions), S (assessment level)} consists of three elements: equipment asset information, mapping conditions, and assessment level. If an equipment asset meets specific mapping conditions, it can be mapped to the corresponding level. Equipment asset (A): refers to the medical equipment on the hospital's intranet and its attribute descriptions, including: equipment name, equipment category, department (i.e., the department using it), purpose, usage status (i.e., condition), equipment hazard assessment results, etc.; Mapping conditions (C): refers to the attribute values ​​of the equipment asset meeting specific conditions or a set of specific conditions; Assessment level (S): refers to the personal safety hazard level in Table 2 above.

[0086] Regarding this mapping rule, taking medical imaging CT equipment as an example, the following mapping rule can be established:

[0087] Rule C1: The purpose of equipment assets is equivalent to a physical examination;

[0088] Rule C2: The department responsible for the equipment assets is the medical examination center;

[0089] Rule C3: The status of the equipment asset is "in use";

[0090] Rule C4: The hazard assessment results of equipment assets are classified into levels 1, 2, 3, and 4;

[0091] Set the relationship between rules C1, C2, C3, and C4 as AND;

[0092] The assessment level (S) of the mapping result is configured as follows: The assessment level (S) is the personal safety hazard level 1, that is, the impact on personal safety is negligible. So when a CT device meets the above rules C1, C2, C3 and C4 at the same time, it will be mapped to the personal hazard level 1.

[0093] Based on the mapping rules described above, taking ECG monitoring equipment as an example, the following mapping rules can be established:

[0094] Rule C1: The purpose of equipment assets is equivalent to emergency rescue;

[0095] Rule C2: The department responsible for the equipment assets is the emergency center;

[0096] Rule C3: The status of the equipment asset is "in use";

[0097] Rule C4: The hazard assessment results for equipment assets are classified as level 2, 3, or 4;

[0098] Set the relationship between rules C1, C2, C3, and C4 as AND;

[0099] The assessment level (S) of the configuration mapping result is: the assessment level (S) is a personal safety hazard level 4, which means that it will lead to serious personal injury or medical accident. When an ECG monitoring device meets the above rules C1, C2, C3 and C4 at the same time, it will be mapped to a personal hazard level 4.

[0100] Similarly, taking electrocardiogram (ECG) monitoring equipment as an example, the following mapping rules can also be established:

[0101] Rule C1: The purpose of equipment assets is equivalent to routine monitoring;

[0102] Rule C2: The department responsible for the equipment asset is the Department of Obstetrics and Gynecology;

[0103] Rule C3: The status of the equipment asset is "in use";

[0104] Rule C4: The hazard assessment results for equipment assets are classified as level 2, 3, or 4;

[0105] Set the relationship between rules C1, C2, C3, and C4 as AND;

[0106] The configuration mapping result evaluation level (S) is: the evaluation level (S) is a personal safety hazard level 3, which means that it will cause personal injury or medical accident, but will not cause serious events such as death or major disability. When the ECG monitoring meets the above rules C1, C2, C3 and C4 at the same time, it will be mapped to a personal hazard level 3.

[0107] Furthermore, it should be noted that in this embodiment, the construction of the second preset information database first involves parsing the determined second target mapping relationship to obtain the corresponding second rule parsing results; then, the second preset information database is constructed based on the second rule parsing results. The rule categories in the second preset information database include single rules, composite rules, and nested rules. That is, the information database contains not only single rules (such as rule C1 in the example above), but also composite and nested rules. Specifically, several rules can be combined to define a composite rule, which is composed of several simple rules, and the relationships between the simple rules are defined, such as whether the simple rules are ANDed (simultaneously satisfied) or ORed (partially satisfied). In addition to the composite rules mentioned above, nested rules can also be defined. Each rule in a composite rule may be a simple rule, a composite rule, or a combination of simple and composite rules; that is, a composite rule can participate in the construction of other composite rules. Based on the above principles, all equipment assets within the hospital's intranet can be reviewed, and mapping rules for risk mapping assessment from equipment safety to personal safety can be established to obtain the second preset information database.

[0108] Step S14: Based on the degree of security risk to the target device and the degree of security risk to the target person, determine the response strategy for the network security risk event of the target, and perform corresponding security processing operations based on the response strategy to complete the network security protection of the target medical device.

[0109] In this embodiment, after obtaining the degree of security risk to the target device and the degree of personal safety risk to the target person, a corresponding response strategy can be determined to complete the network security protection of the device. Specifically, by analyzing the attack probability and degree of harm of the target network security risk event to the hospital's network information system, the corresponding degree of harm of the target event is determined, and a first target score and a first weight corresponding to the degree of harm of the target event are determined; based on the first preset information database, a second target score and a second weight corresponding to the degree of security risk to the target medical device are determined; based on the second preset information database, a third target score and a third weight corresponding to the degree of personal safety risk to the target medical device are determined; based on the first target score, the first weight, the second target score, the second weight, the third target score, and the third weight, a target risk value corresponding to the current target medical device is determined; based on the target risk value and a preset response measure database, a response strategy for the target network security risk event is determined. In other words, the response strategy in this embodiment adopts a comprehensive quantitative assessment method. It utilizes not only the derived hazard assessment indicators of the target equipment security risk level and the target personal safety risk level, but also basic event hazard assessment indicators. This involves analyzing the attack probability and severity of the target network security risk event on the hospital's network information system to determine the severity of the target event. Each indicator has a corresponding weight and score. As shown in Tables 3-5 below, all weights are values ​​between 0 and 1, and then their weighted average is calculated. The selection of each weight needs to be comprehensively considered to ensure that the comprehensive quantitative assessment range remains within the 0-10 score range.

[0110] Table 3

[0111]

[0112] Table 4

[0113]

[0114] Table 5

[0115]

[0116] In one specific implementation, regarding a certain security vulnerability, referring to Table 3, the first target score corresponding to the severity of the target event (i.e., the network security threat level in Table 3) is 7.2 points, with a first weight of C4. Referring to Table 4, the second target score corresponding to the severity of the target device security threat is 3.2 points, with a second weight of B2. Referring to Table 5, the third target score corresponding to the severity of the target personal safety threat is 3.5 points, with a third weight of A2. Therefore, the comprehensive quantitative assessment result M, i.e., the target risk value, is:

[0117] .

[0118] Therefore, this application first monitors whether a target cybersecurity risk event has occurred on the target medical device. If so, it uses a first preset information database to determine the degree of security harm caused to the target medical device by the cybersecurity risk event. Then, it uses a second preset information database to determine the degree of security harm caused to the patient by the degree of security harm caused by the target device. Finally, it combines the degree of security harm caused by the target device and the degree of personal safety harm caused to the patient to determine a response strategy and execute corresponding security processing operations. In this way, the comprehensiveness, accuracy, and interpretability of cybersecurity risk handling in the medical industry can be effectively improved. It also enables security operations personnel to focus more on urgent and more important cybersecurity risks when handling security risks, thereby improving the efficiency of security risk handling and reducing secondary security disasters caused by cybersecurity risks.

[0119] See Figure 2 As shown in the figure, this application also discloses a network security risk handling device, including:

[0120] Event monitoring module 11 is used to monitor whether a network security risk event has occurred on the current target medical device;

[0121] The first hazard degree determination module 12 is used to determine the degree of security hazard caused to the target medical device by the target network security risk event based on a first preset information database if the target medical device is detected to have experienced the target network security risk event, thereby obtaining the degree of security hazard of the target device; the first preset information database is an information database constructed based on the mapping relationship between different network security risk events and different degrees of security hazard of different devices;

[0122] The second hazard degree determination module 13 is used to determine the degree of safety hazard caused to the patient by the safety hazard degree of the target device based on the second preset information database, thereby obtaining the target personal safety hazard degree; the second preset information database is an information database constructed based on the mapping relationship between different device safety hazard degrees and different personal safety hazard degrees;

[0123] The event response module 14 is used to determine a response strategy for the target network security risk event based on the degree of security hazard to the target device and the degree of personal safety hazard to the target, and to perform corresponding security processing operations based on the response strategy to complete the network security protection of the target medical device.

[0124] Therefore, this application first monitors whether a target cybersecurity risk event has occurred on the target medical device. If so, it uses a first preset information database to determine the degree of security harm caused to the target medical device by the cybersecurity risk event. Then, it uses a second preset information database to determine the degree of security harm caused to the patient by the degree of security harm caused by the target device. Finally, it combines the degree of security harm caused by the target device and the degree of personal safety harm caused to the patient to determine a response strategy and execute corresponding security processing operations. In this way, the comprehensiveness, accuracy, and interpretability of cybersecurity risk handling in the medical industry can be effectively improved. It also enables security operations personnel to focus more on urgent and more important cybersecurity risks when handling security risks, thereby improving the efficiency of security risk handling and reducing secondary security disasters caused by cybersecurity risks.

[0125] In some specific embodiments, the network security risk handling device may further include:

[0126] The information collection unit is used to collect information from various basic devices and medical devices connected to the hospital network in order to obtain equipment asset information corresponding to the hospital.

[0127] The first hazard level information acquisition unit is used to determine the safety hazard levels of multiple devices and the scores corresponding to each safety hazard level of the devices based on the hospital's medical equipment operation and maintenance information, so as to obtain the first hazard level information.

[0128] The first mapping relationship sorting unit is used to sort out the mapping relationship between different network security risk events and different security risk levels of different devices for each type of medical device based on the first hazard level information and the device asset information, so as to obtain the first target mapping relationship;

[0129] The first preset information database construction unit is used to perform rule analysis on the first target mapping relationship in order to construct the first preset information database.

[0130] In some specific embodiments, the first mapping relationship sorting unit may specifically include:

[0131] The first mapping relationship sorting subunit is used to sort out the mapping relationship between different network security risk events and different device security hazard levels for any type of medical device, based on the first hazard level information and the device asset information corresponding to the current type of medical device, including device name, device category, attack event name, attack event type, number of attack events, vulnerability name, vulnerability type, vulnerability risk, number of vulnerabilities, recovery time, and recovery action, so as to obtain the first target mapping relationship.

[0132] In some specific embodiments, the network security risk handling device may further include:

[0133] The second hazard level information acquisition unit is used to determine multiple personal safety hazard levels and corresponding scores for each personal safety hazard level based on the hospital's safety management regulations, so as to obtain the second hazard level information.

[0134] The second mapping relationship sorting unit is used to sort out the mapping relationship between different equipment safety hazard levels and different personal safety hazard levels for each type of medical equipment based on the second hazard level information, the equipment hazard risk assessment information in the equipment asset information and the equipment usage scenario information, so as to obtain the second target mapping relationship.

[0135] The second preset information database construction unit is used to perform rule analysis on the second target mapping relationship in order to construct the second preset information database.

[0136] In some specific embodiments, the second mapping relationship sorting unit may specifically include:

[0137] The second mapping relationship sorting subunit is used to sort out the mapping relationship from the degree of equipment safety hazard to the degree of personal safety hazard for any type of medical equipment, based on the second degree of hazard information, the equipment hazard risk assessment result corresponding to the current type of medical equipment in the equipment asset information, the equipment name, equipment category, department of use and usage status, so as to obtain the second target mapping relationship.

[0138] In some specific embodiments, the first preset information database construction unit may specifically include:

[0139] The first rule constitutes the parsing subunit, which is used to perform rule constitutes parsing on the determined first target mapping relationship in order to obtain the corresponding first rule parsing result;

[0140] The first preset information base construction subunit is used to construct the first preset information base based on the first rule parsing result; wherein, the rule categories in the first preset information base include single rules, compound rules and nested rules.

[0141] In some specific embodiments, the second preset information database construction unit may specifically include:

[0142] The second rule constitutes the parsing subunit, which is used to parse the rule constitutes the determined second target mapping relationship to obtain the corresponding second rule parsing result;

[0143] The second preset information base construction subunit is used to construct the second preset information base based on the second rule parsing result; wherein, the rule categories in the second preset information base include single rules, compound rules and nested rules.

[0144] In some specific embodiments, the event response module 14 may specifically include:

[0145] The first score acquisition unit is used to determine the corresponding target event harm level by analyzing the attack probability and harm level of the target network security risk event on the hospital network information system, and to determine the first target score and first weight corresponding to the harm level of the target event;

[0146] The second score acquisition unit is used to determine, based on the first preset information database, a second target score and a second weight corresponding to the degree of safety hazard of the target medical device;

[0147] The third score acquisition unit is used to determine, based on the second preset information database, a third target score and a third weight corresponding to the degree of personal safety hazard of the target medical device.

[0148] A risk value determination unit is used to determine a target risk value corresponding to the current target medical device based on the first target score, the first weight, the second target score, the second weight, the third target score, and the third weight.

[0149] The response strategy determination unit is used to determine the response strategy for the target network security risk event based on the target risk value and a preset response measure library.

[0150] Furthermore, embodiments of this application also disclose an electronic device, Figure 3 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content of the diagram should not be construed as limiting the scope of this application.

[0151] Figure 3This is a schematic diagram of the structure of an electronic device 20 provided in an embodiment of this application. Specifically, the electronic device 20 may include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 stores a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the network security risk handling method for medical devices disclosed in any of the foregoing embodiments. Alternatively, the electronic device 20 in this embodiment may specifically be an electronic computer.

[0152] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and is not specifically limited here; the input / output interface 25 is used to acquire external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs, and is not specifically limited here.

[0153] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or optical disk, etc. The resources stored thereon can include operating system 221, computer program 222, etc., and the storage method can be temporary storage or permanent storage.

[0154] The operating system 221 is used to manage and control the various hardware devices on the electronic device 20 and the computer program 222, which may be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program capable of performing the network security risk handling method for a medical device executed by the electronic device 20 as disclosed in any of the foregoing embodiments, the computer program 222 may further include computer programs capable of performing other specific tasks.

[0155] Furthermore, this application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the aforementioned method for handling network security risks of medical devices. Specific steps of this method can be found in the corresponding content disclosed in the foregoing embodiments, and will not be repeated here.

[0156] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts of the embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to the method section.

[0157] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0158] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0159] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0160] The technical solutions provided in this application have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A method for handling cybersecurity risks of medical devices, characterized in that, include: Monitor whether the target medical device has experienced a cybersecurity risk incident; If a network security risk event is detected in the target medical device, the degree of security harm caused by the network security risk event to the target medical device is determined based on the first preset information database, and the degree of security harm to the target device is obtained. The first preset information database is an information database constructed based on the mapping relationship between different network security risk events and the degree of security threat of different devices; Based on the second preset information database, the degree of safety hazard posed by the target device to the patient is determined, thereby obtaining the degree of personal safety hazard to the target device. The second preset information database is a database constructed based on the mapping relationship between the safety hazard level of different equipment and the personal safety hazard level of different equipment. Based on the degree of security risk to the target device and the degree of security risk to the target person, a response strategy for the network security risk event of the target is determined, and corresponding security processing operations are performed based on the response strategy to complete the network security protection of the target medical device.

2. The method for handling cybersecurity risks of medical devices according to claim 1, characterized in that, Before determining the degree of security harm caused by the target cybersecurity risk event to the target medical device based on the first preset information database, the method further includes: Information is collected from various basic and medical devices connected to the hospital network to obtain equipment asset information corresponding to the hospital. Based on the hospital's medical equipment operation and maintenance information, the safety hazard levels of multiple devices and the scores corresponding to each safety hazard level are determined to obtain the first hazard level information; Based on the first degree of harm information and the equipment asset information, the mapping relationship between different network security risk events and different degrees of equipment security harm is sorted out for each type of medical equipment to obtain the first target mapping relationship; The first target mapping relationship is analyzed by rules to construct the first preset information database.

3. The method for handling network security risks of medical devices according to claim 2, characterized in that, The process of mapping different cybersecurity risk events to different security risk levels of different devices based on the first severity information and the device asset information includes: For any type of medical device, based on the first severity information and the device asset information corresponding to the current type of medical device, including device name, device category, attack event name, attack event type, number of attack events, vulnerability name, vulnerability type, vulnerability risk, number of vulnerabilities, recovery time, and recovery action, a mapping relationship between different network security risk events and different device security severity is sorted out to obtain the first target mapping relationship.

4. The method for handling network security risks of medical devices according to claim 2, characterized in that, Before determining the degree of safety hazard posed to the patient by the target device based on the second preset information database, the method further includes: Based on the hospital's safety management regulations, multiple degrees of personal safety hazard and corresponding scores for each degree of personal safety hazard are determined to obtain second degree of hazard information; Based on the second degree of hazard information, the equipment hazard risk assessment information in the equipment asset information, and the equipment usage scenario information, the mapping relationship between different equipment safety hazard levels and different personal safety hazard levels is sorted out for each type of medical equipment to obtain the second target mapping relationship; The second target mapping relationship is analyzed by rules to construct the second preset information database.

5. The method for handling network security risks of medical devices according to claim 4, characterized in that, Based on the second degree of hazard information, the equipment hazard risk assessment information in the equipment asset information, and the equipment usage scenario information, the mapping relationship between different equipment safety hazard levels and different personal safety hazard levels is analyzed for each type of medical equipment, including: For any type of medical device, based on the second degree of hazard information, the equipment hazard risk assessment results corresponding to the current type of medical device in the equipment asset information, the equipment name, equipment category, department of use, and usage status, a mapping relationship from the degree of equipment safety hazard to the degree of personal safety hazard is sorted out to obtain the second target mapping relationship.

6. The method for handling network security risks of medical devices according to claim 4, characterized in that, The step of performing rule analysis on the first target mapping relationship to construct the first preset information database includes: By performing rule-based parsing on the determined first target mapping relationship, the corresponding first rule parsing result is obtained; The first preset information base is constructed based on the parsing results of the first rule; wherein, the rule categories in the first preset information base include single rules, compound rules, and nested rules; Accordingly, the step of performing rule analysis on the second target mapping relationship to construct the second preset information database includes: By performing rule-based parsing on the determined second target mapping relationship, the corresponding second rule parsing results are obtained; The second preset information base is constructed based on the parsing results of the second rule; wherein, the rule categories in the second preset information base include single rules, compound rules and nested rules.

7. The method for handling cybersecurity risks of medical devices according to any one of claims 1 to 6, characterized in that, The step of determining a response strategy for the target network security risk event based on the degree of security threat to the target device and the degree of security threat to the target person includes: By analyzing the attack probability and severity of the target network security risk events on the hospital's network information system, the severity of the corresponding target events is determined, and a first target score and a first weight corresponding to the severity of the target events are determined. Based on the first preset information database, a second target score and a second weight are determined corresponding to the degree of safety hazard of the target medical device. Based on the second preset information database, a third target score and a third weight are determined corresponding to the degree of personal safety hazard posed by the target medical device. The target risk value corresponding to the current target medical device is determined based on the first target score, the first weight, the second target score, the second weight, the third target score, and the third weight. Based on the target risk value and the preset response measure library, a response strategy is determined for the target network security risk event.

8. A network security risk handling device for medical devices, characterized in that, include: The event monitoring module is used to monitor whether the target medical device has experienced a network security risk event. The first hazard degree determination module is used to determine the degree of security hazard caused to the target medical device by the target network security risk event based on a first preset information database if the target medical device is detected to have experienced the target network security risk event, thereby obtaining the degree of security hazard to the target device. The first preset information database is an information database constructed based on the mapping relationship between different network security risk events and the degree of security threat of different devices; The second hazard degree determination module is used to determine the degree of safety hazard caused to the patient by the safety hazard degree of the target device based on the second preset information database, so as to obtain the degree of personal safety hazard of the target device. The second preset information database is a database constructed based on the mapping relationship between the safety hazard level of different equipment and the personal safety hazard level of different equipment. The event response module is used to determine a response strategy for the target network security risk event based on the degree of security threat to the target device and the degree of personal safety threat to the target, and to execute corresponding security processing operations based on the response strategy to complete the network security protection of the target medical device.

9. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor for executing the computer program to implement the cybersecurity risk handling method for a medical device as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, Used to store a computer program, which, when executed by a processor, implements the network security risk handling method for a medical device as described in any one of claims 1 to 7.