Telecommunication processing method of surgical robot system and surgical robot communication system
By identifying and intercepting attack data in the surgical robot system through a three-layer detection mechanism, the problem of communication attacks in remote surgical operations is solved, ensuring system security and stability and improving detection efficiency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-29
- Publication Date
- 2026-06-26
AI Technical Summary
Existing surgical robot systems are vulnerable to external communication attacks during remote surgical operations, which can lead to operational failures or threaten patient safety, and there is a lack of effective protective measures.
A three-layer detection mechanism is adopted, including whitelist detection of the security protection platform, network traffic detection of the communication server, and correlation data fusion detection of the central control server, to identify and block attack data.
Effectively identify and intercept attack data to ensure the safe and stable operation of the surgical robot system, reduce data processing delays, and improve detection efficiency.
Smart Images

Figure CN122293443A_ABST
Abstract
Description
Technical Field
[0001] This manual belongs to the field of surgical robot control technology, and in particular relates to remote communication processing methods and surgical robot communication systems for surgical robot systems. Background Technology
[0002] With the development and promotion of robotics technology, intelligent medical devices such as surgical robot systems are gradually being applied to surgical procedures.
[0003] However, based on existing methods, doctors are easily vulnerable to external communication attacks when using surgical robot systems to perform remote surgeries on patients, which can prevent them from performing the surgeries normally and even threaten the patients' lives.
[0004] There is currently no effective solution to the above problems. Summary of the Invention
[0005] This specification provides a remote communication processing method and a surgical robot communication system for a surgical robot system, which can efficiently and accurately detect and identify attack data during remote surgery.
[0006] This specification provides a remote communication processing method for a surgical robot system, applicable to surgical robot communication systems, including: The security protection platform is invoked to perform a first detection on the target business communication data according to a preset whitelist, and a first detection result is obtained; wherein, the preset whitelist is constructed in advance based on the heartbeat communication data of the patient terminal and doctor terminal of the surgical robot system under normal conditions; the preset whitelist includes at least: preset port information, and preset combination of source IP and protocol type; Based on the first detection result, if it is determined that the target business communication data belongs to the first type of business communication data, the target business communication data is forwarded to the communication server through the security protection platform; and the first detection result is sent to the central control server; wherein, the first type of business communication data is the target business communication data that matches the combination of the target source IP and the target protocol type with the preset whitelist; The communication server is invoked to perform a second detection based on network traffic on the target business communication data, and the second detection result is obtained; the second detection result is then sent to the central control server. The central control server is used to obtain current associated data about the surgical robot communication system; and by fusing the first detection result, the second detection result, and the current associated data, a third detection is performed on the target business communication data based on the remote surgical communication scenario to obtain the third detection result; wherein, the associated data includes at least: the operating data of the patient terminal, the operating data of the doctor terminal, and the status data of the communication server; Based on the third detection result, determine whether the target business communication data is attack data.
[0007] This specification also provides a remote communication processing device for a surgical robot system, applied to a surgical robot communication system, comprising: The first detection module is used to call the security protection platform to perform a first detection on the target business communication data according to a preset whitelist and obtain a first detection result; wherein, the preset whitelist is constructed in advance based on the heartbeat communication data of the patient terminal and doctor terminal of the surgical robot system under normal conditions; the preset whitelist includes at least: preset port information, and preset combination of source IP and protocol type; The forwarding module is used to forward the target business communication data to the communication server through the security protection platform when it is determined that the target business communication data belongs to the first type of business communication data based on the first detection result; and to send the first detection result to the central control server; wherein, the first type of business communication data is the target business communication data that matches the combination of the target source IP and the target protocol type with the preset whitelist; The second detection module is used to call the communication server to perform a second detection on the target business communication data based on network traffic, obtain the second detection result, and send the second detection result to the central control server. The third detection module is used to obtain current associated data about the surgical robot communication system using the central control server; and to perform a third detection on the target business communication data based on the remote surgical communication scenario by fusing the first detection result, the second detection result, and the current associated data to obtain a third detection result; wherein, the associated data includes at least: the operating data of the patient terminal, the operating data of the doctor terminal, and the status data of the communication server; The determination module is used to determine whether the target business communication data is attack data based on the third detection result.
[0008] This specification also provides a surgical robot communication system, comprising at least: a central control server, a communication server, a security protection platform, and a doctor's terminal and a patient's terminal for the surgical robot system; wherein, The communication server is used to transmit target business communication data about the doctor's terminal and / or the patient's terminal in the surgical robot communication system; The security protection platform is used to perform a first detection on the target business communication data accessed by the system; and if it is determined that the target business communication data belongs to the first type of business communication data, the target business communication data is forwarded to the communication server; The communication server is also used to perform a second detection on the target business communication data based on network traffic, and send the second detection result to the central control server. The central control server is used to acquire current associated data about the surgical robot communication system; and by fusing the first detection result, the second detection result, and the current associated data, it performs a third detection on the target business communication data based on the remote surgical communication scenario to determine whether the target business communication data is attack data.
[0009] This specification also provides a computer program product comprising a computer program that, when executed by a processor, implements the steps of the remote communication processing method for the surgical robot system.
[0010] Based on the remote communication processing method and surgical robot communication system provided in this specification, before implementation, a preset whitelist can be constructed by acquiring and using the heartbeat communication data of the patient terminal and doctor terminal of the surgical robot system under normal conditions. The preset whitelist includes at least: preset port information, and preset combinations of source IP and protocol type. During implementation, when the surgical robot communication system detects new target business communication data, it can first call the security protection platform to perform a preliminary first detection on the target business communication data according to the preset whitelist. Based on the first detection result, the target business communication data belonging to the first category of business communication data is forwarded to the communication server. The first category of business communication data refers to target business communication data whose combination of target source IP and target protocol type matches the preset whitelist. Then, the communication server is called to perform a second detection on the target business communication data based on network traffic, and the second detection result is sent to the central control server. Finally, the central control server is used to obtain current associated data about the surgical robot communication system. By fusing the first detection result, the second detection result, and the current associated data, a third detection based on the remote surgical communication scenario is performed on the target business communication data to determine whether the target business communication data is attack data. By introducing and utilizing a three-layer detection mechanism—including a security protection platform based on a preset whitelist for initial detection, a communication server based on network traffic for initial detection, and a central control server based on the remote surgical communication scenario for initial detection—the advantages of components such as the security protection platform, communication server, and central control server can be fully utilized. This mechanism is well adapted to complex remote surgical communication scenarios, enabling efficient and comprehensive detection and identification of attack data during remote surgery, reducing latency in normal business communication data, and ensuring the safe and stable completion of remote surgical operations using the surgical robot system.
[0011] Furthermore, by directly intercepting the target business communication data when it is determined to belong to the second category of business communication data, the system avoids wasting data processing resources on subsequent detection and processing of such target business communication data. This effectively reduces the data processing burden of the surgical robot communication system while ensuring the safe and stable execution of remote surgery. Moreover, when the target business communication data is determined to belong to the first category of business communication data, the security status of the target business communication data can be further subdivided according to a preset whitelist. Differentiated second detection based on network traffic can be performed for different security statuses, which can further reduce the data processing burden of the surgical robot communication system and improve the overall detection and processing efficiency.
[0012] Then, by fusing the first detection result, the second detection result, and the current associated data, the target communication attack analysis and detection results based on the traffic attack dimension and the target surgical impact detection results based on the remote surgery dimension are determined respectively. By jointly using the target communication attack analysis and detection results and the target surgical impact detection results, a third detection based on the remote surgical communication scenario is performed. This can better adapt to complex remote surgical communication scenarios, accurately and comprehensively detect and determine whether the target business communication data is attack data, and further determine the specific attack level when the target business communication data is determined to be attack data. This allows for accurate and precise matching of emergency response processing based on the attack level, effectively ensuring the safety and stability of remote surgery based on the surgical robot system. Attached Figure Description
[0013] To more clearly illustrate the embodiments of this specification, the accompanying drawings used in the embodiments will be briefly introduced below. The drawings described below are only some embodiments recorded in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0014] Figure 1 This is a flowchart illustrating a communication control method provided in one embodiment of this specification; Figure 2 This is a schematic diagram of the structural composition of a surgical robot communication system provided in one embodiment of this specification; Figure 3 This is a schematic diagram illustrating one embodiment of the communication control method provided in this specification, applied in a scenario example. Figure 4 This is a schematic diagram illustrating one embodiment of the communication control method provided in this specification, applied in a scenario example. Figure 5 This is a schematic diagram illustrating one embodiment of the communication control method provided in this specification, applied in a scenario example. Figure 6 This is a schematic diagram illustrating one embodiment of the communication control method provided in this specification, applied in a scenario example. Figure 7 This is a schematic diagram illustrating one embodiment of the communication control method provided in this specification, applied in a scenario example. Figure 8 This is a schematic diagram of the structural composition of a computer device provided in one embodiment of this specification; Figure 9 This is a schematic diagram of the structural composition of a communication control device provided in one embodiment of this specification; Figure 10 This is a schematic diagram illustrating one embodiment of the communication control method provided in this specification, applied in a scenario example. Figure 11 This is a schematic diagram illustrating one embodiment of the communication control method provided in this specification, applied in a scenario example. Figure 12 This is a schematic diagram illustrating one embodiment of the communication control method provided in this specification, applied in a scenario example. Figure 13 This is a schematic diagram illustrating one embodiment of the communication control method provided in this specification, applied in a scenario example. Figure 14 This is a schematic diagram illustrating one embodiment of the communication control method provided in this specification, applied in a scenario example. Figure 15 This is a schematic diagram illustrating one embodiment of the communication control method provided in the embodiments of this specification, applied in a scenario example. Detailed Implementation
[0015] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this specification.
[0016] It should be noted that the information and data related to users involved in the embodiments of this specification are all information and data authorized by the user or fully authorized by the relevant parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of the relevant data all comply with relevant laws, regulations, and standards, and necessary confidentiality measures have been taken. They do not violate public order and good morals, and corresponding operation entry points are provided for users or relevant parties to choose to authorize or refuse.
[0017] It should also be noted that in the embodiments of this specification, certain software, components, models and other existing solutions in the industry may be mentioned. These should be regarded as exemplary and are only intended to illustrate the feasibility of implementing the technical solution of this application. However, it does not mean that the applicant has used or necessarily used the solution.
[0018] See Figure 1 As shown in the embodiments of this specification, a remote communication processing method for a surgical robot system is provided, wherein the method is specifically applied to a surgical robot communication system. In specific implementation, the method may include the following: S101: The security protection platform is invoked to perform a first detection on the target business communication data according to the preset whitelist, and a first detection result is obtained; wherein, the preset whitelist is constructed in advance based on the heartbeat communication data of the patient terminal and doctor terminal of the surgical robot system under normal conditions; the preset whitelist includes at least: preset port information, and preset combination of source IP and protocol type; S102: Based on the first detection result, if it is determined that the target business communication data belongs to the first type of business communication data, the target business communication data is forwarded to the communication server through the security protection platform; and the first detection result is sent to the central control server; wherein, the first type of business communication data is the target business communication data that matches the combination of the target source IP and the target protocol type with the preset whitelist; S103: Call the communication server to perform a second detection on the target business communication data based on network traffic, obtain the second detection result, and send the second detection result to the central control server; S104: Obtain current associated data about the surgical robot communication system using the central control server; and perform a third detection on the target business communication data based on the remote surgical communication scenario by fusing the first detection result, the second detection result, and the current associated data to obtain the third detection result; wherein, the associated data includes at least: the operating data of the patient terminal, the operating data of the doctor terminal, and the status data of the communication server; S105: Based on the third detection result, determine whether the target business communication data is attack data.
[0019] Among them, see Figure 2 As shown, the above-mentioned surgical robot communication system may include at least the following components: surgical robot system, communication server, central control server, and security protection platform.
[0020] Specifically, the aforementioned surgical robot system may include at least: a doctor's terminal and a patient's terminal.
[0021] For specific examples, please refer to Figure 3 As shown, the aforementioned patient terminal (or patient operating table) can be specifically positioned on one side of the patient. At least multiple robotic arms are mounted on the patient terminal. Furthermore, surgical instruments, endoscopes, and other equipment required for the surgery can be mounted on these robotic arms.
[0022] Please refer to Figure 4 As shown, the aforementioned doctor terminal (or doctor control console) can be deployed on the user's (e.g., the doctor's) side. The doctor terminal should include at least observation and operation modules.
[0023] The aforementioned patient terminal and doctor terminal together constitute the surgical robot system in this application example, and can also be collectively referred to as the surgical robot system terminal.
[0024] During the surgical procedure, the patient's terminal can acquire relevant surgical images using devices such as endoscopes; these images are then transmitted to the doctor's terminal as data packets via a communication server. The doctor's terminal receives these images and displays them to the user through an observation terminal, allowing the user to remotely monitor the surgical progress in real time.
[0025] Furthermore, based on the observed surgical situation and relevant surgical requirements, the user can generate corresponding control commands through the operating terminal; these control commands are then transmitted to the patient terminal as another type of business communication data in the form of data packets via a communication server. Correspondingly, the patient terminal receives and responds to the control commands, controlling the movement of the relevant robotic arm and / or using corresponding surgical instruments and other equipment, enabling the user to remotely perform specific surgical procedures.
[0026] Specifically, the aforementioned patient terminal can also be configured with a local control terminal (or local terminal). In certain situations, when the patient terminal is unable to communicate with the doctor's terminal, the local control terminal can be temporarily used to replace the doctor's terminal, take over control of the patient terminal, and provide emergency control of the patient terminal.
[0027] The aforementioned communication servers may specifically include a main communication server and a backup communication server. Under normal circumstances, the main server operates and is responsible for data transmission in the surgical robot communication system; the backup server is on standby and performs real-time data synchronization with the main server.
[0028] The aforementioned security protection platform can specifically be a cloud service platform responsible for network communication security protection of the surgical robot communication system. Specifically, the security protection platform may include: a DDoS protection module (e.g., providing terabit-level traffic scrubbing), a cloud firewall module (e.g., providing a database of tens of millions of IP reputation points), and a security center module (e.g., providing SOAR automated response services), etc. The aforementioned security protection platform can be a self-developed component platform or a platform provided by a cooperating third party; this specification does not limit its scope.
[0029] The aforementioned central control server is specifically responsible for the data management, analysis and decision-making of the surgical robot communication system, as well as the supervision and control of related components.
[0030] In addition, the aforementioned surgical robot communication system may also include a web server. This web server may be connected to at least the user terminal and the central control server.
[0031] Specifically, the aforementioned user terminal may include a front-end applied to the user side, capable of data collection, data transmission, and other functions. Specifically, the user terminal may be an electronic device such as a desktop tablet, laptop, or smartphone. Alternatively, the user terminal may also be a software application that can run on the aforementioned electronic device. For example, it may be an app running on a smartphone.
[0032] Correspondingly, users (e.g., maintenance personnel of the surgical robot communication system) can also use user terminals to query the operating status of each component in the surgical robot communication system, the system's business communication data processing records, the system's network parameters, the preset whitelists and monitoring thresholds used by the system, as well as attack events that have occurred in the system, related emergency response logs, and so on, through the web server. Furthermore, users can also use user terminals to adaptively adjust the preset whitelists and monitoring thresholds used by the system through the web server.
[0033] Specifically, the aforementioned security protection platform is connected to at least the communication server, the aforementioned communication server is connected to at least the terminal of the surgical robot system, the security protection platform, and the central control server, and the aforementioned central control server is connected to at least the communication server and the security protection platform.
[0034] Furthermore, to better protect the data security of the surgical robot communication system, encrypted networks can be used to connect the relevant components in the surgical robot communication system.
[0035] Specifically, based on the first encryption rule, a dedicated encrypted heartbeat communication link can be established between the doctor's terminal, the patient's terminal, the main communication server, and the backup communication server, so that the doctor's terminal and the patient's terminal can securely transmit business communication data related to surgery through this dedicated encrypted heartbeat communication link.
[0036] According to the second encryption rule, a dedicated encrypted synchronization link can be established between the central control server, the security protection platform, and the main communication server / backup communication server so that the central control server, the security protection platform, and the main communication server / backup communication server can securely synchronize the preset whitelist through this dedicated encrypted synchronization link.
[0037] According to the third encryption rule, a dedicated encrypted command transmission link can be established between the web server and the central control server so that the central control server and the web server can securely transmit relevant commands from the user terminal through this dedicated encrypted command transmission link.
[0038] Specifically, the aforementioned target service communication data can be understood as newly detected service communication data to be transmitted in the system, but whose security status cannot be determined. This target service communication data may include one or multiple service communication data sets.
[0039] The aforementioned pre-defined whitelist can be understood as a whitelist that is pre-constructed based on heartbeat communication data under normal conditions, such as patient terminals and doctor terminals, and is dynamically updated for pre-detection based on network traffic.
[0040] Specifically, the aforementioned preset whitelist can be a whitelist based on three-dimensional network traffic characteristics, which may include multiple secure preset port information, as well as secure preset combinations of source IP and protocol types.
[0041] It should be noted that the reason for choosing and using preset port information, as well as preset combinations of source IPs and protocol types to construct the preset whitelist is twofold. Firstly, when using a security platform for pre-detection based on network traffic (e.g., first-level detection), it's possible to efficiently and conveniently extract features such as source IPs, protocol types, and port information from target business communication data without consuming excessive data processing resources to deeply process the data. Secondly, extensive correlation analysis revealed that in remote data communication scenarios, the combination of source IPs and protocol types, along with port information, has a stronger correlation with attack data compared to other features. Therefore, by using combinations of source IPs and protocol types, along with port information, it's possible to balance identification accuracy and processing efficiency with as few features as possible, accurately detecting and identifying attack data.
[0042] In practice, when the system detects newly received target service communication data, it will not directly respond to and transmit the target service communication data. Instead, it will first call the security protection platform to extract and perform pre-detection (i.e., first detection) of the target service communication data based on network traffic, according to a preset whitelist and the target source IP, target port information, and target protocol type. Specifically, the target port information may include the port information of the source port associated with the target service communication data, as well as the port information of the destination port.
[0043] Based on the initial detection results, the security protection platform can perform preliminary screening and filtering. Target business communication data whose combination of target source IP and target protocol type does not match a preset whitelist is identified as second-category business communication data; this second-category business communication data is then directly filtered and blocked. This second-category business communication data is highly likely to contain abnormal attack data. Target business communication data whose combination of target source IP and target protocol type matches a preset whitelist is identified as first-category business communication data; this first-category business communication data is then accessed by the system and forwarded to the communication server for further detection; simultaneously, the initial detection results are sent to the central control server.
[0044] This allows the security platform to efficiently identify high-risk second-type business communication data in advance using a pre-defined whitelist, requiring only a small amount of data processing. It can then promptly filter and block this type of communication data, preventing its continued transmission within the system. This serves two purposes: firstly, it allows for the early filtering and interception of high-risk attack data, preventing it from entering the surgical robot's communication system and damaging its components; secondly, it effectively reduces the amount of data processing required for subsequent detection, improving overall processing efficiency.
[0045] After receiving the target business communication data forwarded by the security protection platform, the communication server will not directly transmit the target business communication data within the system. Instead, it will perform further detection on the target business communication data based on network traffic (i.e., second detection) to conduct a more comprehensive and detailed risk detection on the target business communication data from the perspective of network traffic, and obtain the corresponding second risk detection result. The target business communication data, together with the second detection result, will then be forwarded to the central control server.
[0046] The central server can obtain current associated data about the surgical robot communication system; then, by integrating the first detection result, the second detection result, and the current associated data, a third detection based on the remote surgical communication scenario is performed. The communication attack situation and the impact of the communication attack on remote surgical control are comprehensively analyzed to obtain a more comprehensive and accurate third detection result that is adapted to complex remote surgical communication scenarios. Finally, based on the third detection result, it can be determined whether the target business communication data belongs to attack data.
[0047] The aforementioned associated data may include at least: operational data from the patient's terminal, operational data from the doctor's terminal, and status data from the communication server. Furthermore, the associated data may also include surgical information.
[0048] Specifically, the operational data of the aforementioned patient terminal may include at least one of the following: communication delay parameters, link stability indication parameters, command reception success rate, command execution success rate, heartbeat communication status, joint node motion status parameters, and mounted component status parameters.
[0049] The operational data of the aforementioned doctor terminal may specifically include at least one of the following: communication latency parameters, link stability indication parameters, command issuance success rate, heartbeat communication status, and status parameters of the operating end.
[0050] The status data of the aforementioned communication server may specifically include at least one of the following: CPU utilization, memory usage, data transmission rate, etc.
[0051] The aforementioned surgical information may specifically include at least one of the following: surgical type, surgical stage, degree of dependence of surgical operations on remote communication during the surgical process, surgical instruments on the patient terminal involved in the surgical process, and surgical instructions related to surgical operation control involved in the surgical process.
[0052] Specifically, the central control server can obtain the operating data of the doctor's terminal and the operating data of the patient's terminal through a dedicated encrypted heartbeat communication link between the communication server and the doctor's terminal and the patient's terminal, according to the first encryption rule; obtain the status data of the communication server through a dedicated encrypted synchronization link, according to the second encryption rule; and obtain the surgical code of the surgery currently being performed by the surgical robot system; and then obtain the corresponding surgical information by querying a preset surgical information database based on the surgical code.
[0053] Specifically, the central control server can call the relevant functional modules and algorithm models deployed on the security protection platform to assist in the third detection based on remote surgical communication scenarios, so as to obtain third detection results with high reference value and small error.
[0054] Specifically, if the target business communication data is determined to be attack data based on the third detection result, in addition to calling the security protection platform to intercept and process the target business communication data in a timely manner, the attack level of the target business communication data can also be determined based on the third detection result. Then, based on the attack level of the target business communication data, and considering factors such as communication attacks and the impact of such communication attacks on remote surgical control, a matching target emergency response strategy is determined from the preset emergency response strategy set. And according to the target emergency response strategy, emergency response processing is carried out on the surgical robot communication system to minimize the damage of attack data to the surgical robot communication system and ensure the safe and stable performance of surgery based on the surgical robot system.
[0055] The aforementioned attack levels include various levels such as mild, moderate, and severe attacks. Specifically, mild attacks have a relatively minor impact on the remote surgical control of the surgical robot system, moderate attacks have a relatively moderate impact, and severe attacks have a relatively severe impact.
[0056] The aforementioned set of preset emergency response strategies can contain multiple preset strategies, each corresponding to a specific attack level. Specifically, this set of preset emergency response strategies can be constructed in advance through data statistics and clustering learning on a large number of system emergency response records.
[0057] Conversely, if the third detection result determines that the target service communication data is not attack data, the central control server can send a pass notification to the communication server indicating that the target service communication data has passed the detection. Accordingly, the communication server can respond to the pass notification, respond to the target service communication data, and transmit the target service communication data normally within the system, so that the system can properly process the specific service data within the data packets carried by the target service communication data.
[0058] Based on the above embodiments, by constructing a surgical robot communication system with the above structure, and by utilizing the security protection platform, communication server, and central control server within the surgical robot communication system to perform a multi-level detection mechanism on newly detected target business communication data, including a first detection based on initial screening of network traffic, a second detection based on fine analysis of network traffic, and a third detection based on comprehensive correlation analysis of remote surgical communication scenarios, the relevant components of the surgical robot communication system can be fully utilized. This allows for better adaptation to complex remote surgical communication scenarios, efficient and accurate detection and identification of attack data during remote surgery, and timely matching processing. While ensuring the safe and stable operation of the surgical robot system and patient surgical safety, it effectively reduces the overall data processing volume, improves overall processing efficiency, and reduces the transmission delay of normal business communication data.
[0059] In some embodiments, after intercepting target business communication data using a security protection platform, one or more of the target source IP, target protocol type, and target port information of the target business communication data can be added to a temporary blacklist.
[0060] Subsequently, before conducting the first detection, the security protection platform can check whether the source IP, protocol type, and port information of new business communication data match the temporary blacklist. If all matches are confirmed, the subsequent first detection can be skipped, and the business communication data can be directly intercepted.
[0061] Meanwhile, the protection platform can also continuously monitor subsequent target source IPs, or business communication data involving target protocol types or target port information that have passed detection, within a specified time period (e.g., 10 minutes) based on the temporary blacklist; if no attack behavior is observed in the above business communication data within the specified time period, the corresponding target source IP, target protocol type, or target port information can be removed from the temporary blacklist.
[0062] In some embodiments, see Figure 5 As shown, the aforementioned security protection platform performs a first detection on the target business communication data based on a preset whitelist. In specific implementation, this may include the following: S5-1: Call the security protection platform to extract the target source IP, target protocol type, and target port information of the target business communication data; S5-2: Detect whether the combination of the target source IP and target protocol type, and the target port information of the target service communication data match the preset whitelist; S5-3: When the combination of the target source IP and the target protocol type of the target service communication data matches the preset whitelist, the target service communication data is determined to belong to the first category of service communication data.
[0063] In practice, the security protection platform can extract features from the target business communication data based on the preset business traffic feature template to quickly obtain the required target source IP, target protocol type, and target port information.
[0064] In practice, when the combination of the target source IP and target protocol type of the target business communication data matches a preset whitelist, the target business communication data is determined to belong to the first category of business communication data. Based on the preset whitelist, it can be preliminarily determined that the target business communication data does not currently pose a significant attack risk and passes the pre-detection stage. Conversely, when the combination of the target source IP and target protocol type of the target business communication data does not match a preset whitelist, the target business communication data is determined to belong to the second category of business communication data. Based on the preset whitelist, it can be preliminarily determined that the target business communication data poses a significant attack risk and fails the pre-detection stage.
[0065] Based on the above embodiments, by introducing and using a preset whitelist for the detection of the three-dimensional features of interest, it is possible to quickly complete the pre-detection with a small amount of data processing, and to discover and intercept target business communication data with obvious attack risks in advance.
[0066] In some embodiments, when the combination of the target source IP and the target protocol type of the target service communication data matches a preset whitelist, the method may further include the following: S1: Determine the first traffic parameters of the target service communication data; wherein, the first traffic parameters include at least one of the following: number of packets sent per second, number of packets lost, and data packet size; S2: Based on the first traffic parameter threshold, detect whether the first traffic parameter of the target service communication data meets the first traffic requirement; S3: When the first flow parameter of the target service communication data meets the first flow requirement, the target service communication data is determined to belong to the first type of service communication data.
[0067] The aforementioned target service communication data may carry specific data packets, which may contain relevant service data. This service data may specifically be image data, audio data, or command data, etc.
[0068] The aforementioned first traffic parameter threshold can be a general traffic parameter threshold. Specifically, the aforementioned first traffic parameter threshold may include at least one of the following: a first packet sending threshold, a first packet loss threshold, a first data packet size threshold, etc.
[0069] Specifically, the aforementioned first traffic parameter threshold can be determined in advance based on the statistical results of the traffic parameters of the full heartbeat communication data under normal conditions of the patient terminal and doctor terminal of the surgical robot system, without further subdividing specific situations, and the clustering results of the traffic parameters involved in historical attack data.
[0070] In specific implementation, when it is determined, based on the first traffic parameter threshold, that at least one first traffic parameter of the target service communication data does not meet the requirements, the target service communication data can be determined to not meet the first traffic requirements. For example, when it is detected that the number of packets sent per second of the target service communication data is greater than the first packet number threshold, it can be determined that the number of packets sent per second of the target service communication data does not meet the first traffic requirements, and thus the target service communication data is determined to belong to the second type of service communication data. When it is determined, based on the first traffic parameter threshold, that all first traffic parameters of the target service communication data meet the first traffic requirements, the target service communication data is determined to belong to the first type of service communication data.
[0071] Based on the above embodiments, by further detecting the first traffic parameter of the target business communication data that has passed the detection based on the preset whitelist, the pre-detection based on the security protection platform can achieve higher accuracy.
[0072] In some embodiments, the above method may further include the following: S1: When it is determined that the combination of the target source IP and the target protocol type of the target business communication data does not match the preset whitelist, or when it is determined that the first traffic parameter of the target business communication data does not meet the first traffic requirement, the target business communication data is determined to belong to the second type of business communication data. S2: Call the security protection platform to intercept the target business communication data.
[0073] In practice, after the security protection platform intercepts the target business communication data, relevant information of the target business communication data (such as the target source IP, target port information, and target port information) can be added to the first detection result so that the preset whitelist can be traced back and updated using the first detection result.
[0074] In some embodiments, when the combination of the target source IP and the target protocol type of the target service communication data matches a preset whitelist, the method may further include the following: S1: When it is determined that the target port information of the target service communication data matches the preset whitelist, a lightweight detection tag is set for the target service communication data; S2: When it is determined that the target port information of the target service communication data does not match the preset whitelist, a key detection mark is set for the target service communication data.
[0075] Correspondingly, the target business communication data forwarded by the security protection platform to the communication server can also carry corresponding detection tags; among them, the detection tags are either lightweight detection tags or key detection tags.
[0076] In practice, after receiving the target business communication data, the communication server can acquire and distinguish the target business communication data under different risk conditions based on the detection markers, and use the matching detection method to perform the specific second detection.
[0077] In some embodiments, the above-mentioned invocation of the communication server to perform a second network traffic-based detection on the target service communication data may include the following: S1: Call the communication server to determine the matching target detection rule based on the detection marker carried in the target business communication data; S2: Based on the target detection rules, perform a second detection on the target service communication data based on network traffic.
[0078] In practice, a matching detection rule can be determined from a preset set of detection rules based on the detection markers, serving as the target detection rule. The preset set of detection rules includes at least a first detection rule corresponding to lightweight detection and a second detection rule corresponding to key detection.
[0079] In some embodiments, the second detection of the target service communication data based on network traffic described above may specifically include the following: When the detection marker is a lightweight detection marker, the corresponding second detection result is obtained by detecting the data volume of the data packets involved in the target service communication data and the format information of the target protocol; When the detection marker is a key detection marker, a second traffic parameter threshold that matches the target service communication data is determined; and based on the second traffic parameter threshold, anomaly detection is performed on the second traffic parameters related to the target service communication data to obtain the corresponding second detection result; wherein, the second traffic parameter includes at least one of the following: data packet frequency, data packet size range, and data packet type.
[0080] In practice, when the detection marker is a lightweight detection marker, it can be determined that the target business communication data has a relatively higher probability of not being attack data, and the risk is low. At this time, a lightweight second detection can be performed based on the matching target detection rules, which has a relatively small data processing volume and a relatively fast speed.
[0081] Specifically, when performing lightweight second detection, it is not necessary to deeply analyze and process the specific content of the target service communication data. It is only necessary to count the data volume of the data packets involved in the target service communication data. At the same time, by obtaining the message structure of the target service communication data and the key fields in the message, the format information of the target protocol on which the target service communication data is based is obtained. Then, by detecting whether the number of data packets in the data packets involved in the target service communication data whose data volume exceeds a preset abnormal data volume threshold is greater than a preset number of risks, and by detecting whether the format information of the target protocol matches the protocol format of the relevant transmission link, the corresponding second detection result is obtained.
[0082] When a target is flagged as a priority detection target, it can be determined that the target business communication data has a relatively higher probability of being attack data, posing a greater risk. In this case, a secondary, more comprehensive, and detailed priority detection can be performed based on matching target detection rules, which involves a larger data processing volume and slower speed.
[0083] When conducting a specific type of secondary detection, the target protocol type and / or target port information of the target service communication data can be used to determine the matching threshold of the secondary traffic parameters. At the same time, through data statistics, one or more of the following can be determined: the data packet frequency, data packet size range, data packet type, etc. of the target service communication data. The secondary traffic parameters of the target service communication data can then be obtained by performing anomaly detection on the above-mentioned secondary traffic parameters based on the threshold of the secondary traffic parameters, and the corresponding secondary detection results can be obtained.
[0084] Specifically, the second traffic parameter threshold, unlike the first traffic parameter threshold, can be a traffic parameter threshold that is subdivided for one or more specific situations. The second traffic parameter threshold may include at least one of the following: a second data packet frequency threshold, a second data packet size range, a second data packet type range, etc.
[0085] Specifically, different situations can be distinguished based on the target protocol type and target port information, and then a second traffic parameter threshold for the target service communication data can be selected and used according to the different situations; wherein, the second traffic parameter threshold corresponding to different situations can involve second traffic parameter thresholds of different types and different values.
[0086] For example, based on the target protocol type and target port information, when it is determined that the current situation involves a user initiating a surgical robot system, a smaller numerical range can be determined and used as the second data packet size range for that situation. When it is determined that the current situation involves a user invoking an endoscope on a patient terminal to observe the surgical environment, a larger numerical range can be determined and used as the second data packet size range for that situation.
[0087] Furthermore, when the detection marker is a key detection target, the second detection may also include: performing anomaly scanning and detection on the protocol behavior of the target protocol and the port behavior of the target port of the target service communication data to obtain the corresponding second detection result.
[0088] Specifically, the target service communication data can be parsed to obtain the target protocol upon which it is based; key behavioral fields in the target protocol can be extracted; and scanning detection can be performed based on these key behavioral fields to obtain protocol behavior anomaly scanning detection data. Simultaneously, based on the source port information in the target port information, the source port of the target service communication data can be determined; then, corresponding test signals are sent to the source port, and feedback signals from the source port are collected to obtain port behavior anomaly scanning detection data for the target port. Finally, the protocol behavior anomaly scanning detection data of the target protocol and the port behavior anomaly scanning detection data of the target port are combined to obtain the corresponding second detection result.
[0089] Based on the above embodiments, different risk situations of target business communication data can be distinguished, and a matching method can be used to perform a second detection based on network traffic. This can effectively reduce the overall data processing volume of the system and improve the overall processing efficiency while ensuring the detection effect.
[0090] In some embodiments, the surgical information may specifically include at least one of the following: surgical type, surgical stage, the degree of dependence of surgical operations on remote communication during the surgical process, surgical instruments of the patient terminal involved in the surgical process, surgical instructions related to surgical operation control involved in the surgical process, etc.
[0091] Of course, it should be noted that the surgical information listed above is only illustrative. In actual implementation, depending on the specific circumstances and treatment needs, the surgical information mentioned above may also include other data related to the surgery. This instruction manual does not limit this.
[0092] In some embodiments, see Figure 6 As shown, the above-mentioned third detection of target business communication data based on a remote surgical communication scenario is performed by fusing the first detection result, the second detection result, and the current associated data. In specific implementation, this may include the following: S6-1: Merge the first detection result, the second detection result, and the current associated data to obtain the target fused data; S6-2: Based on the target fusion data, perform communication attack analysis and detection to obtain the corresponding target communication attack analysis and detection results; S6-3: Based on the target fusion data and the target communication attack analysis and detection results, perform the impact detection of communication attacks on remote surgical control, and obtain the corresponding target surgical impact detection results; S6-4: Based on the target communication attack analysis and detection results and the target surgical impact detection results, determine the corresponding third detection result.
[0093] In practical implementation, for relatively simple cases, the target fusion data can be used to detect whether the communication quality of the surgical machine system suddenly declines (e.g., the packet loss rate of data packets and command-type business data in heartbeat communication between the doctor's terminal and the patient's terminal exceeds the preset packet loss rate risk threshold, the frequency and amplitude of delay jitter in heartbeat communication exceed the preset jitter safety range, or the image frame rate transmitted by heartbeat communication is lower than the preset frame rate threshold, etc.) or even interrupts (e.g., at least one of the doctor's terminal and the patient's terminal is detected to have timed out and failed to send heartbeat communication data normally, etc.), and whether the current resource load of the communication server exceeds the preset safety load range. This analysis determines whether the target business communication data that passed the first and second detections has a communication attack risk (e.g., causing resource occupation problems), and obtains the corresponding communication attack analysis and detection results. Further, based on the surgical information, the current specific surgical situation is determined. Based on this surgical situation, the target fusion data and the target communication attack analysis and detection results are combined to detect the impact of communication attacks on remote surgical control, obtaining the corresponding target surgical impact detection results. For example, if the current surgical situation involves using an endoscope to observe the overall surgical environment, the amount and frequency of the image data to be transmitted are relatively large. In this case, if there is a sudden drop in communication quality and / or the current resource load of the communication server exceeds the preset safe load range for a short period of time (e.g., 10 seconds), it can be judged to be relatively reasonable and have a relatively small impact on remote surgical control, thus obtaining the corresponding target surgical impact detection result. At this time, by combining the target communication attack analysis detection result and the target surgical impact detection result, it can be determined that the target business communication data cannot be identified as attack data at present and needs to be further monitored, thus obtaining the corresponding third detection result.
[0094] In practical implementation, for relatively complex situations, the following steps can be taken: First, based on the combination of target source IP and target protocol type involved in the first or second detection result, search the business communication data processing records of the surgical robot communication system within a reference time period (the most recent day). Obtain the historical records of the first detection result, second detection result, and associated data related to the combination of target source IP and target protocol type within the reference time period as reference auxiliary data. Then, according to the preset fusion rules, extract the corresponding data features from the first detection result, second detection result, current associated data, and reference auxiliary data respectively, and combine them to obtain multiple detection feature groups. Each detection feature group corresponds to a time point and includes the first detection feature extracted based on the first detection result, the second detection feature extracted based on the second detection result, and the associated detection feature extracted based on the associated data at the corresponding time point. Finally, arrange the multiple detection feature groups in chronological order to obtain the corresponding detection feature sequence as the target fusion data.
[0095] In practice, the target fusion data can be processed first using a pre-set communication attack analysis model to perform time-series analysis and detection based on communication attacks. By utilizing the knowledge learned and mastered, the communication attack risks related to the target business communication data can be analyzed from at least five different risk dimensions: malicious instruction injection, forged instructions, session hijacking, replay attacks, and data eavesdropping, and the corresponding target communication attack analysis and detection results can be obtained.
[0096] Specifically, the aforementioned pre-defined communication attack analysis model can be an algorithm model that can perform communication attack analysis and detection by training a large amount of sample data through reinforcement learning based on an improved BiLSTM (Bidirectional Long Short-Term Memory Networks) model structure.
[0097] Specifically, the improved BiLSTM structure mentioned above can refer to a bidirectional long short-term memory network based on attention mechanisms and multidimensional feature representations. Based on this network, long-term dependencies in sequence data can be effectively captured and processed by introducing special storage units and gating mechanisms.
[0098] It should be noted that the improved BiLSTM architecture mentioned above is introduced and used here because it is possible to establish long-distance dependencies between forward and reverse time series by using independent LSTM layers with opposite directions, so that the model can extract the required detection features more accurately. At the same time, by introducing an attention mechanism, the model can more easily focus on detection features with relatively high value, thereby effectively solving the gradient vanishing problem of conventional LSTM architecture.
[0099] Specifically, the aforementioned pre-defined communication attack analysis model includes at least five parallel feature processing modules: a first feature processing module corresponding to malicious instruction injection detection, a second feature processing module corresponding to forged instructions, a third feature processing module corresponding to session hijacking, a fourth feature processing module corresponding to replay attacks, and a fifth feature processing module corresponding to data eavesdropping; wherein each feature processing module is constructed based on an improved BiLSTM structure.
[0100] Specifically, each feature processing module may include at least: a first LSTM layer and a second LSTM layer; wherein the first LSTM layer includes multiple first LSTM substructures connected in forward temporal sequence, and the second LSTM layer includes multiple second LSTM substructures connected in reverse temporal sequence. Furthermore, each first LSTM substructure is connected to a corresponding first attention unit, which is also connected to other first LSTM substructures in the first LSTM layer; each second LSTM substructure is connected to a corresponding second attention unit, which is also connected to other second LSTM substructures in the second LSTM layer. The first LSTM layer is used to extract and process the deep-level process evolution features of the corresponding risk dimension; the second LSTM layer is used to extract and process the deep-level initial features of the corresponding risk dimension.
[0101] Specifically, in the aforementioned feature processing module, the first LSTM layer and the second LSTM layer are independent and operate in opposite directions. By jointly using the first and second LSTM layers, long-distance dependencies between forward and reverse time series can be established, respectively. Specifically, the first LSTM layer can extract deep-level process evolution features from the forward time series, while the second LSTM layer can deduce deep-level initial features from the reverse time series. Furthermore, by setting corresponding attention units in the first and second LSTM layers respectively, an attention mechanism is introduced, which makes it easier for the model to focus on more valuable features, effectively solving the gradient vanishing problem of conventional LSTM architectures.
[0102] Furthermore, in the communication attack analysis model, each feature processing module is also connected to a corresponding first classification network; the aforementioned multiple first classification networks are connected in parallel with a common second classification network.
[0103] In practice, each feature processing module can first process the target fusion data to extract the deep-level process evolution features and initial features of the corresponding risk dimension. Then, the process evolution features and initial features are fused to obtain the deep-level fusion features of the corresponding risk dimension. Next, the corresponding first classification network is used to process the corresponding deep-level fusion features to perform temporal detection analysis of the relevant risk dimension and obtain the temporal sub-detection analysis vector of the corresponding risk dimension. Finally, the second classification network is used to process the temporal sub-detection risk vectors of multiple risk dimensions to perform overall temporal attack detection analysis and obtain and output the corresponding target statistical attack analysis detection results.
[0104] In practice, after obtaining the corresponding target communication attack analysis and detection results, the target communication attack analysis and detection sub-results corresponding to multiple time points can be extracted based on the target communication attack analysis and detection results. Then, each communication attack analysis and detection sub-result is spliced into the feature group of the corresponding time point in the target fusion data to obtain the spliced target fusion data. Then, using the preset surgical impact detection model, the spliced target fusion data is processed to perform a more refined detection of the impact of communication attacks on remote surgical control, combining communication attacks with remote surgical communication scenarios, so as to obtain the corresponding target surgical impact detection results.
[0105] Specifically, the aforementioned pre-defined surgical impact detection model can be an algorithm model that is pre-trained using a large amount of sample data through machine learning based on an improved multi-scale TCN-GRU hybrid structure, and can combine communication attacks with remote surgical communication scenarios to comprehensively detect the impact of communication attacks on remote surgical control.
[0106] Specifically, the aforementioned TCN (Temporal Convolutional Network) can be understood as a type of convolutional network, suitable for processing long-term series data and supporting parallel computing capabilities. Accordingly, by introducing a TCN network into the model, on the one hand, the model can support parallel computing, improving its processing efficiency; on the other hand, it can leverage the advantages of TCN networks in processing long-term series data, facilitating subsequent long-range dependency modeling. The aforementioned GRU (Gate Recurrent Unit) can be understood as a variant of a recurrent neural network (RNN). Based on this structure, the gate unit can solve problems in RNNs such as the inability to retain information for long periods and gradient issues during backpropagation; simultaneously, it can preserve information from long-term series data without erasing it over time or removing it because it is irrelevant to the prediction.
[0107] Specifically, the aforementioned pre-defined surgical impact detection model may include at least: a multi-scale segmentation module, a convolutional network layer based on a TCN structure, a splicing layer, and a prediction layer based on a GRU structure.
[0108] The convolutional network layer includes multiple time-scale branch processing structures; each time-scale branch processing structure includes at least multiple connected dilated convolutional layers and max pooling layers; the number of dilated convolutional layers and the dilation rate of the dilated convolutional layers in each time-scale branch processing structure are determined according to the time scale corresponding to that time-scale branch processing structure; the splicing layer is also connected to an attention fusion module.
[0109] Specifically, the aforementioned multiple time-scale branch processing structures may include: a first time-scale branch processing structure corresponding to 1 minute, a second time-scale branch processing structure corresponding to 5 minutes, and a third time-scale branch processing structure corresponding to 30 minutes.
[0110] Accordingly, in specific implementation, the multi-scale partitioning module can first be used to divide the spliced target fusion data of the input model into time windows according to preset window rules, obtaining three sub-fusion sequences corresponding to the three different time-scale branch processing structures mentioned above. Then, the first time-scale branch processing structure, the second time-scale branch processing structure, and the third sub-time-scale branch processing structure are used to process the first sub-fusion sequence (corresponding to 1 minute), the second sub-fusion sequence (corresponding to 5 minutes), and the third sub-fusion sequence (corresponding to 30 minutes) output by the multi-scale partitioning module, respectively, to obtain the corresponding first-scale time-series feature processing results, second-scale time-series feature processing results, and third-scale time-series feature processing results.
[0111] In this way, by introducing and utilizing the above-mentioned branch processing structures with different time scales, the distinction between different time scales is achieved. This enables the third time scale branch processing structure to capture and extract long-term data change features, the second time scale branch processing structure to capture and extract medium-term data change features, and the first time scale branch processing structure to capture and extract short-term data change features, thereby obtaining time series feature processing results with multiple different time scales that meet the requirements.
[0112] The aforementioned prediction layer may include a GRU structure and a fully connected layer. The GRU structure can be used to model long-term dependencies in the input temporal feature processing results. The fully connected layer can be used for specific analysis and detection based on the data output by the GRU structure.
[0113] The aforementioned attention fusion module may specifically include a gated network structure based on a self-attention mechanism, consisting of fully connected layers. This structure can be used to analyze and dynamically weight the processing results of different temporal features output by branch processing structures at different time scales according to the overall trend of change.
[0114] In practical implementation, the splicing layer can be used to splice the temporal feature processing results of multiple time scales based on the feature channel dimension to obtain an initial comprehensive feature vector. Then, the attention fusion module can be used to perform global average pooling on the initial comprehensive feature vector and compress the sequence information of each feature channel along the time dimension to obtain a globally compressed feature vector. The attention fusion module can then use a gating network to analyze the nonlinear dependency relationship between the feature channels based on the globally compressed feature vector and adaptively adjust the weight coefficients of the feature channels. Based on the adjusted weight coefficients, the features in the initial comprehensive feature vector can be weighted and adjusted to obtain the target comprehensive feature vector. The prediction layer can then use a GRU structure to perform long-term dependency modeling and analysis on the target comprehensive feature vector to determine the specific impact information, including the device nodes and impact degree of the doctor's terminal affected by communication attacks in the remote surgical field, the device nodes and impact degree of the affected patient terminal, and the affected surgical operations and impact methods. This yields a target surgical impact detection result that is suitable for complex remote surgical communication scenarios and has high reference value.
[0115] In practice, the detection results of target communication attack analysis and target surgical impact can be spliced together to obtain a more comprehensive and adaptable third detection result that simultaneously considers the communication attack and its impact on remote surgical control.
[0116] In some embodiments, the target surgical impact detection results may specifically include at least one of the following: the device node of the affected doctor's terminal and the degree of impact, the device node of the affected patient's terminal and the degree of impact, the affected surgical operation and the mode of impact, etc.
[0117] The aforementioned impacts include one or more of the following: tampering with surgical instructions regarding the surgical procedure, affecting the normal transmission of surgical instructions, intercepting surgical data during the surgical procedure, etc.
[0118] Of course, it should be noted that the target surgical impact detection results listed above are only illustrative. In actual implementation, depending on the specific circumstances and processing needs, the above target surgical impact detection results may also include other data and information. This instruction manual does not limit this.
[0119] In some embodiments, see Figure 7 As shown, after determining whether the target business communication data is attack data based on the third detection result, the method may further include the following in its specific implementation: S7-1: When the target service communication data is determined to be attack data, the target service communication data is intercepted; S7-2: Based on the third detection result, determine the attack level of the target business communication data; wherein, the attack level includes: light attack, medium attack, and severe attack; S7-3: Determine the appropriate emergency response strategy based on the attack level of the target business communication data; S7-4: Perform emergency response processing on the surgical robot communication system according to the target emergency response processing strategy.
[0120] In practice, the communication server includes at least a main communication server and a backup communication server. Accordingly, based on the third detection result, when it is determined that the main communication server and the backup communication server are in normal condition, it can be judged that the impact of the target business communication data on remote surgical control is relatively minor, and the attack level of the target business communication data can be determined as a mild attack; based on the third detection result, when it is determined that one of the main communication server and the backup communication server is in abnormal condition, it can be judged that the impact of the target business communication data on remote surgical control is relatively moderate, and the attack level of the target business communication data can be determined as a moderate attack; based on the third detection result, when it is determined that both the main communication server and the backup communication server are in abnormal condition, it can be judged that the impact of the target business communication data on remote surgical control is relatively severe, and the attack level of the target business communication data can be determined as a severe attack.
[0121] Furthermore, when determining the attack level in the manner described above, it is also possible to consider whether the communication attack affects the transmission of critical surgical instructions. When it is determined that the main communication server is in an abnormal state and the backup communication server is in an abnormal state, and / or the communication attack affects the transmission of critical surgical instructions, the attack level of the target business communication data can be determined as a severe attack.
[0122] Specifically, the aforementioned key surgical instructions may refer to instructions related to surgical procedures (e.g., cutting operations) that directly affect the patient's life safety as determined by the third test results, and / or instructions related to dangerous equipment (e.g., scalpels) that may endanger the patient's life safety and are mounted on the patient's terminal.
[0123] In specific implementation, when the attack level of the current target business communication data is a minor attack, the above-mentioned emergency response handling strategy for the surgical robot communication system is implemented. Specifically, this may include the following: when the target source IP does not match the preset whitelist, the business communication data from the target source IP is blocked within the first observation period; and the business communication data related to the target source IP is continuously observed within the first observation period; if no abnormal attack behavior is found, the business communication data from the target source IP is unblocked; otherwise, the target source IP is added to the temporary blacklist. When the target source IP matches the preset whitelist, but at least one of the target protocol type and target port information does not match the preset whitelist, a deep scan of the target protocol or target port is performed first to obtain the corresponding deep scan results. Based on the deep scan results, if it is determined that there is no attack risk, traffic limiting can be applied to the service communication data from the target source IP during the second observation period. The service communication data related to the target source IP is continuously monitored during the second observation period. If no abnormal attack behavior is detected, normal transmission of service communication data from the target source IP is restored. Otherwise, the target source IP is added to a temporary blacklist. If an attack risk is determined based on the deep scan results, the target source IP is directly added to the temporary blacklist.
[0124] In specific implementation, when the attack level of the current target business communication data is a medium attack, the above-mentioned emergency response handling strategy for the surgical robot communication system is implemented. Specifically, this may include the following: switching and running a backup communication server to replace the main communication server; calling the security defense platform to intercept business communication data from the target source IP and adjusting the relevant cleaning threshold of the security protection platform to perform AI intelligent enhanced protection; simultaneously, calling the security defense platform to intercept business communication data associated with the target protocol and / or target port, and adding the target protocol and / or target port to a temporary blacklist.
[0125] In specific implementation, when the attack level of the current target business communication data is a severe attack, the above-mentioned emergency response handling strategy for the surgical robot communication system will be implemented. Specifically, this may include the following: suspending the communication of the surgical robot communication system; and activating the local terminal of the patient terminal of the surgical robot system to take over control of the operation of the patient terminal instead of the doctor terminal; then calling the local terminal to encrypt the surgical data during the takeover control process according to the preset emergency encryption rules; and sending the encrypted surgical data to the central control server through a backup encrypted link (e.g., a 5G-based encrypted link) for emergency temporary interaction; at the same time, attempting to repair the main communication server and the backup server, and issuing alarm prompts to the operation and maintenance personnel.
[0126] Based on the above embodiments, appropriate emergency response measures can be accurately and precisely tailored to different attack levels to ensure the safe and stable operation of the surgical robot system and avoid causing harm to the patient.
[0127] In some embodiments, the method may further include the following: S1: During the security testing phase, the communication server is invoked to collect heartbeat communication data of the patient terminal and doctor terminal of the surgical robot system under normal conditions; S2: Based on the heartbeat communication data, extract the corresponding heartbeat communication features under normal conditions; S3: Construct a preset whitelist based on the heartbeat communication characteristics under normal conditions.
[0128] When conducting specific security tests, the above-mentioned surgical robot communication system can be tested under simulated normal interference environments to ensure that heartbeat communication data with normal interference but no attack can be collected comprehensively as heartbeat communication data under normal conditions with high reference value.
[0129] Furthermore, based on the aforementioned heartbeat communication data, corresponding heartbeat communication features can be extracted; then, clustering learning can be performed on the heartbeat communication features to determine those with high representativeness and broad coverage, which will serve as the heartbeat communication features under normal conditions; and based on the aforementioned heartbeat communication features under normal conditions, a preset whitelist can be constructed.
[0130] Based on the above embodiments, a preset whitelist with high accuracy and good effect can be constructed.
[0131] In some embodiments, the method may further include the following: S1: Every preset time interval, the central control server is invoked to organize the business communication data processing records of the surgical robot communication system for the current time interval; and the business communication data processing records for the current time interval are uploaded to the security protection platform; S2: Utilize the security protection platform to process business communication data for the current time period and generate an attack analysis report for the current time period; S3: Utilize the central control server to update the preset whitelist based on the attack analysis report for the current time period.
[0132] In practice, after the system completes the detection of each business communication data, the central control server can organize the detection process of the business communication data, as well as the related first detection result, second detection result, and third detection result, into a record data corresponding to the business communication data, and record and update it in the business communication data processing record.
[0133] In practice, at preset time intervals (e.g., every two days), the central control server can be invoked to collect and upload the business communication data processing records for the current time period to the security protection platform. The security protection platform can then combine this data with relevant data from other partners obtained via the internet during the current time period. Through big data analysis of the business communication data processing records for the current time period, it can collect and analyze the attack characteristics and trends in the remote surgical communication scenario during the current time period. Based on these attack characteristics and trends, an attack analysis report for the current time period is generated and returned to the central control server. The central control server can then dynamically adjust and update the preset whitelist, as well as related detection rules and models, based on the attack analysis report for the current time period and the attack characteristics and trends in the remote surgical communication scenario during the current time period. This ensures continuous, accurate, and efficient detection and identification of attack data.
[0134] As can be seen from the above, the remote communication processing method for the surgical robot system provided in this specification can, before implementation, acquire and construct a preset whitelist based on the heartbeat communication data of the patient terminal and doctor terminal of the surgical robot system under normal conditions. The preset whitelist includes at least: preset port information, and preset combinations of source IP and protocol type. In specific implementation, when the surgical robot communication system detects new target business communication data, it can first call the security protection platform to perform a preliminary first detection on the target business communication data according to the preset whitelist, and based on the first detection result, forward the target business communication data belonging to the first category of business communication data to the communication server. The first category of business communication data refers to target business communication data whose combination of target source IP and target protocol type matches the preset whitelist. Then, the communication server is called to perform a second detection on the target business communication data based on network traffic, and the second detection result is sent to the central control server. Finally, the central control server is used to obtain current associated data about the surgical robot communication system; and by fusing the first detection result, the second detection result, and the current associated data, a third detection based on the remote surgical communication scenario is performed on the target business communication data to determine whether the target business communication data is attack data. By introducing and utilizing a three-layer detection framework, which includes a security protection platform based on a preset whitelist for initial detection, a communication server based on network traffic for initial detection, and a central control server based on the remote surgical communication scenario for initial detection, it can be well adapted to complex remote surgical communication scenarios. It can efficiently and accurately detect and identify attack data during remote surgery, reduce the delay of normal business communication data, and ensure that remote surgery can be completed safely and stably using the surgical robot system.
[0135] See Figure 2 As shown in the embodiments of this specification, a surgical robot communication system is also provided, which may include at least: a central control server, a communication server, a security protection platform, and a doctor's terminal and a patient's terminal of the surgical robot system; wherein, The communication server is used to transmit target business communication data about the doctor's terminal and / or the patient's terminal in the surgical robot communication system; The security protection platform is used to perform a first detection on the target business communication data accessed by the system; and if it is determined that the target business communication data belongs to the first type of business communication data, the target business communication data is forwarded to the communication server; The communication server is also used to perform a second detection on the target business communication data based on network traffic, and send the second detection result to the central control server. The central control server is used to acquire current associated data about the surgical robot communication system; and by fusing the first detection result, the second detection result, and the current associated data, it performs a third detection on the target business communication data based on the remote surgical communication scenario to determine whether the target business communication data is attack data.
[0136] Based on the aforementioned surgical robot communication system, by introducing and utilizing a three-layer detection framework—including a security protection platform based on a preset whitelist for initial detection, a communication server based on network traffic for initial detection, and a central control server based on the remote surgical communication scenario for initial detection—it can be well adapted to complex remote surgical communication scenarios. It can efficiently and accurately detect and identify attack data during remote surgery, reduce the latency of normal business communication data, and ensure that remote surgery can be completed safely and stably using the surgical robot system.
[0137] This specification provides an embodiment of a computer device, see below. Figure 8 As shown. The computer device includes a network communication port 801, a processor 802, and a memory 803. These structures are connected by internal cables so that they can perform specific data interaction.
[0138] Specifically, the network communication port 801 can be used to receive target service communication data.
[0139] The processor 802 can specifically be used to invoke a security protection platform to perform a first detection on target business communication data according to a preset whitelist, and obtain a first detection result; wherein, the preset whitelist is pre-constructed based on the heartbeat communication data of the patient terminal and doctor terminal of the surgical robot system under normal conditions; the preset whitelist includes at least: preset port information, and a preset combination of source IP and protocol type; based on the first detection result, if it is determined that the target business communication data belongs to the first type of business communication data, the security protection platform forwards the target business communication data to the communication server; and sends the first detection result to the central control server; wherein, the first type of business communication data is the target source IP and target protocol. The system retrieves target business communication data whose type combination matches a preset whitelist; it then calls a communication server to perform a second detection on the target business communication data based on network traffic, obtaining a second detection result; and sends the second detection result to a central control server; it uses the central control server to obtain current associated data about the surgical robot communication system; and by fusing the first detection result, the second detection result, and the current associated data, it performs a third detection on the target business communication data based on a remote surgical communication scenario, obtaining a third detection result; wherein, the associated data includes at least: patient terminal operation data, doctor terminal operation data, and communication server status data; based on the third detection result, it determines whether the target business communication data is attack data.
[0140] The memory 803 can be used to store the corresponding instruction program and related intermediate data.
[0141] Based on the above method, the relevant structural performance of computer equipment can be effectively utilized to improve the data processing speed of electronic devices and efficiently realize the data processing for communication control of remote surgical robot systems.
[0142] In this embodiment, the network communication port 801 can be a virtual port bound to different communication protocols, thereby enabling the sending or receiving of different data. For example, the network communication port can be a port responsible for web data communication, a port responsible for FTP data communication, or a port responsible for email data communication. Furthermore, the network communication port can also be a physical communication interface or communication chip. For example, it can be a wireless mobile network communication chip, such as GSM or CDMA; it can also be a Wi-Fi chip; or it can be a Bluetooth chip.
[0143] In this embodiment, the processor 802 can be implemented in any suitable manner. For example, the processor can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers, etc. This specification is not limiting.
[0144] In this embodiment, the memory 803 may include multiple layers. In a digital system, anything that can store binary data can be a memory. In an integrated circuit, a circuit with storage function but no physical form is also called a memory, such as RAM, FIFO, etc. In a system, a storage device with a physical form is also called a memory, such as a memory stick, TF card, etc.
[0145] This specification also provides a computer-readable storage medium for a remote communication processing method based on the above-described surgical robot system. The computer-readable storage medium stores computer program instructions that, when executed, implement the following: calling a security protection platform to perform a first detection on target business communication data according to a preset whitelist, obtaining a first detection result; wherein the preset whitelist is pre-constructed based on heartbeat communication data under normal conditions from the patient's terminal and the doctor's terminal of the surgical robot system; the preset whitelist includes at least: preset port information, and a preset combination of source IP and protocol type; based on the first detection result, if it is determined that the target business communication data belongs to the first type of business communication data, forwarding the target business communication data to a communication server through the security protection platform; and sending the first detection result to... A central control server is used. The first type of business communication data is target business communication data whose combination of target source IP and target protocol type matches a preset whitelist. The communication server is invoked to perform a second detection based on network traffic on the target business communication data, obtaining a second detection result. This second detection result is then sent to the central control server. The central control server is used to obtain current associated data about the surgical robot communication system. By fusing the first detection result, the second detection result, and the current associated data, a third detection is performed on the target business communication data based on a remote surgical communication scenario, obtaining a third detection result. The associated data includes at least: patient terminal operation data, doctor terminal operation data, and communication server status data. Based on the third detection result, it is determined whether the target business communication data is attack data.
[0146] In this embodiment, the storage medium includes, but is not limited to, Random Access Memory (RAM), Read-Only Memory (ROM), Cache, Hard Disk Drive (HDD), or Memory Card. The memory can be used to store computer program instructions. The network communication unit can be an interface configured according to standards specified in the communication protocol for network connection communication.
[0147] In this embodiment, the specific functions and effects implemented by the program instructions stored in the computer-readable storage medium can be explained in comparison with other embodiments, and will not be repeated here.
[0148] This specification also provides a computer program product, comprising at least a computer program, which, when executed by a processor, implements the following method steps: calling a security protection platform to perform a first detection on target business communication data according to a preset whitelist, and obtaining a first detection result; wherein, the preset whitelist is pre-constructed based on heartbeat communication data under normal conditions of the patient terminal and doctor terminal of the surgical robot system; the preset whitelist includes at least: preset port information, and a preset combination of source IP and protocol type; based on the first detection result, if it is determined that the target business communication data belongs to a first type of business communication data, forwarding the target business communication data to a communication server through the security protection platform; and sending the first detection result to a central control server; wherein, the first... One type of business communication data is target business communication data that matches the combination of the target source IP and the target protocol type with a preset whitelist. The communication server is invoked to perform a second detection based on network traffic on the target business communication data, obtaining a second detection result. This second detection result is then sent to the central control server. The central control server is used to obtain current associated data about the surgical robot communication system. By fusing the first detection result, the second detection result, and the current associated data, a third detection is performed on the target business communication data based on a remote surgical communication scenario, obtaining a third detection result. The associated data includes at least: patient terminal operation data, doctor terminal operation data, and communication server status data. Based on the third detection result, it is determined whether the target business communication data is attack data.
[0149] See Figure 9 As shown in the embodiments of this specification, a remote communication processing device for a surgical robot system is also provided. This device may specifically include the following structural modules: The first detection module 901 can be used to call the security protection platform to perform a first detection on the target business communication data according to a preset whitelist and obtain a first detection result; wherein, the preset whitelist is constructed in advance based on the heartbeat communication data of the patient terminal and doctor terminal of the surgical robot system under normal conditions; the preset whitelist includes at least: preset port information, and preset combination of source IP and protocol type; The forwarding module 902 can be used to forward the target business communication data to the communication server through the security protection platform based on the first detection result and when it is determined that the target business communication data belongs to the first type of business communication data; and send the first detection result to the central control server; wherein, the first type of business communication data is the target business communication data that matches the combination of the target source IP and the target protocol type with the preset whitelist; The second detection module 903 can be used to call the communication server to perform a second detection on the target business communication data based on network traffic, obtain the second detection result, and send the second detection result to the central control server. The third detection module 904 can be used to obtain the current associated data of the surgical robot communication system using the central control server; and to perform a third detection on the target business communication data based on the remote surgical communication scenario by fusing the first detection result, the second detection result, and the current associated data to obtain the third detection result; wherein, the associated data includes at least: the operating data of the patient terminal, the operating data of the doctor terminal, and the status data of the communication server; The determination module 905 can be used to determine whether the target business communication data is attack data based on the third detection result.
[0150] In some embodiments, when the first detection module 901 is specifically implemented, it can call the security protection platform to perform a first detection on the target service communication data according to a preset whitelist in the following manner: call the security protection platform to extract the target source IP, target protocol type, and target port information of the target service communication data; detect whether the combination of the target source IP and target protocol type and the target port information of the target service communication data match the preset whitelist; when it is determined that the combination of the target source IP and target protocol type of the target service communication data matches the preset whitelist, it is determined that the target service communication data belongs to the first type of service communication data.
[0151] In some embodiments, when it is determined that the combination of the target source IP and the target protocol type of the target service communication data matches a preset whitelist, the device may further be used to: determine a first traffic parameter of the target service communication data; wherein the first traffic parameter includes at least one of the following: number of packets sent per second, number of packets lost, and data packet size; detect whether the first traffic parameter of the target service communication data meets a first traffic requirement based on a first traffic parameter threshold; and determine that the target service communication data belongs to a first type of service communication data when it is determined that the first traffic parameter of the target service communication data meets the first traffic requirement.
[0152] In some embodiments, the device may also be used to: determine that the target service communication data belongs to the second type of service communication data when it is determined that the combination of the target source IP and the target protocol type of the target service communication data does not match the preset whitelist, or when it is determined that the first traffic parameter of the target service communication data does not meet the first traffic requirement; and call the security protection platform to intercept the target service communication data.
[0153] In some embodiments, when it is determined that the combination of the target source IP and the target protocol type of the target service communication data matches a preset whitelist, the device may further be used to: set a lightweight detection flag for the target service communication data when it is determined that the target port information of the target service communication data matches a preset whitelist; and set a heavy-duty detection flag for the target service communication data when it is determined that the target port information of the target service communication data does not match a preset whitelist.
[0154] In some embodiments, when the second detection module 903 is specifically implemented, it can call the communication server to perform a second detection based on network traffic on the target service communication data in the following manner: the communication server determines the matching target detection rule according to the detection tag carried by the target service communication data; and performs a second detection based on network traffic on the target service communication data according to the target detection rule.
[0155] In some embodiments, when the second detection module 903 is specifically implemented, it can perform a second detection based on network traffic on the target service communication data in the following manner: when the detection mark is a lightweight detection mark, the corresponding second detection result is obtained by detecting the data volume of the data packets involved in the target service communication data and the format information of the target protocol; when the detection mark is a key detection mark, a second traffic parameter threshold matching the target service communication data is determined; and based on the second traffic parameter threshold, anomaly detection is performed on the second traffic parameters of the target service communication data to obtain a corresponding second detection result; wherein, the second traffic parameters include at least one of the following: data packet frequency, data packet size range, and data packet type.
[0156] In some embodiments, the current associated data may further include surgical information; wherein the surgical information may specifically include at least one of the following: surgical type, surgical stage, the degree of dependence of surgical operations on remote communication during the surgical process, surgical instruments of the patient terminal involved in the surgical process, surgical instructions related to surgical operation control involved in the surgical process, etc.
[0157] In some embodiments, when the third detection module 904 is specifically implemented, it can perform a third detection on the target business communication data based on the remote surgical communication scenario by fusing the first detection result, the second detection result, and the current associated data in the following manner: fusing the first detection result, the second detection result, and the current associated data to obtain target fused data; performing communication attack analysis and detection based on the target fused data to obtain corresponding target communication attack analysis and detection results; performing impact detection of communication attacks on remote surgical control based on the target fused data and the target communication attack analysis and detection results to obtain corresponding target surgical impact detection results; and determining the corresponding third detection result based on the target communication attack analysis and detection results and the target surgical impact detection results.
[0158] In some embodiments, the target surgical impact detection results may specifically include at least one of the following: the device node of the affected doctor's terminal and the degree of impact, the device node of the affected patient's terminal and the degree of impact, the affected surgical operation and the mode of impact, etc.
[0159] In some embodiments, after determining whether the target service communication data is attack data based on the third detection result, the device may further be used to: intercept the target service communication data when it is determined that the target service communication data is attack data; determine the attack level of the target service communication data based on the third detection result; wherein the attack level includes: mild attack, moderate attack, and severe attack; determine a matching target emergency response handling strategy based on the attack level of the target service communication data; and perform emergency response handling for the surgical robot communication system based on the target emergency response handling strategy.
[0160] In some embodiments, the communication server may include at least: a primary communication server and a backup communication server; Accordingly, when the device is specifically implemented, it can determine the attack level of the target business communication data as a mild attack based on the third detection result when it is determined that the main communication server and the backup communication server are in normal status. Based on the third detection result, if it is determined that one of the main communication server and the backup communication server is in an abnormal state, the attack level of the target business communication data is determined to be a medium attack. Based on the third detection result, when it is determined that both the main communication server and the backup communication server are in an abnormal state, the attack level of the target business communication data is determined to be a severe attack.
[0161] In some embodiments, the device can also be used to: call a communication server during the security testing phase to collect heartbeat communication data of the patient terminal and doctor terminal of the surgical robot system under normal conditions; extract corresponding heartbeat communication features under normal conditions based on the heartbeat communication data; and construct a preset whitelist based on the heartbeat communication features under normal conditions.
[0162] In some embodiments, the device can also be used to: call the central control server at preset time intervals to organize the business communication data processing records of the surgical robot communication system for the current time period; upload the business communication data processing records for the current time period to the security protection platform; generate an attack analysis report for the current time period based on the business communication data processing of the current time period using the security protection platform; and update the preset whitelist based on the attack analysis report for the current time period using the central control server.
[0163] It should be noted that the units, devices, or modules described in the above embodiments can be implemented by computer chips or physical entities, or by products with certain functions. For ease of description, the above devices are described by dividing them into various modules according to their functions. Of course, in implementing this specification, the functions of each module can be implemented in one or more software and / or hardware, or the module that implements the same function can be implemented by a combination of multiple sub-modules or sub-units, etc. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection between the devices or units shown or discussed can be through some interfaces, and the indirect coupling or communication connection between devices or units can be electrical, mechanical, or other forms.
[0164] As can be seen from the above, the remote communication processing device for the surgical robot system provided in the embodiments of this specification, by introducing and utilizing a three-layer detection framework including a security protection platform based on a preset whitelist for first detection, a communication server based on network traffic for second detection, and a central control server based on the remote surgical communication scenario, can be well adapted to complex remote surgical communication scenarios. It can efficiently and accurately detect and identify attack data during remote surgery, reduce the delay of normal business communication data, and ensure that remote surgery can be completed safely and stably using the surgical robot system.
[0165] In a specific scenario example, the remote communication processing method for the surgical robot system provided in this manual can be applied to achieve real-time attack early warning and tiered emergency response communication control during remote surgery. For detailed implementation procedures, please refer to [the manual's documentation]. Figure 10 As shown, it includes the following content.
[0166] In this scenario example, considering that the security protection of the current remote surgical communication system mainly relies on conventional network security equipment to achieve attack detection and interception. However, in conventional detection, a uniform detection standard is used for all accessing IPs, only identifying the IP address without associating it with the protocol type and port information specific to the business, and failing to distinguish the security of the communication source and the validity of the business traffic. As a result, when applied to remote surgical communication scenarios, the following problems exist: (1) Delayed attack detection response and high false alarm rate: The passive mode of "detecting after the attack occurs" is adopted, and the attack behavior is judged only by analyzing a single network traffic, without combining the actual operating status of the remote surgical robot and the characteristics of surgical communication. Furthermore, a uniform detection strategy is adopted for all IPs, without distinguishing between the source IP of normal surgical communication and unfamiliar IPs. It is easy to misjudge normal surgical instructions and image data transmission as attack traffic, with a detection response delay of more than 1 second and no emergency preparation time; (2) Rigid emergency response mechanism: A "one-size-fits-all" approach is adopted. The interception or network disconnection mode does not respond in a graded manner according to the attack intensity, server status and the scope of the impact of the surgery, which is prone to problems such as "insufficient protection leading to surgical interruption" or "excessive protection interfering with normal surgery"; (3) Low efficiency of main and backup server switching: After the main communication server fails, manual intervention is required to complete the switching, which takes too long and cannot meet the millisecond-level requirements for continuous transmission of remote surgical instructions; (4) No unified control and display core: The operating data of terminals and servers and network security data in the system are collected in a decentralized manner, and there is no dedicated core server for fusion analysis and unified decision-making. At the same time, there is a lack of dedicated Web monitoring platform. The platform realizes the visualization of security status and the issuance of manual emergency commands; (5) The protection capability has no iterative optimization mechanism: after the emergency response, the attack data is not summarized and analyzed in the whole process, and the detection model cannot be optimized based on historical attack cases. When the same attack occurs repeatedly, the defense efficiency is not improved; (6) The data protection and surgical continuity are not taken into account: the local emergency takeover mode is not designed, and when both the main and backup servers are paralyzed, there is no effective means to ensure the control of the surgical robot and the security of surgical data, which is easy to cause medical accidents; (7) The multi-dimensional detection strategy is missing: the heartbeat communication between the robot system terminal and the server is not used to identify the source IP, business protocol type and dedicated port of normal communication. It is impossible to accurately filter non-business traffic. Only a single address verification is performed on normal surgical communication. There are still problems of non-business traffic occupying detection resources and interfering with normal communication. The detection accuracy and efficiency are limited; (8) The non-business traffic identification and filtering capabilities are weak: the business-specific IP + protocol type + port three-dimensional whitelist is not established. It is impossible to quickly distinguish between surgical business traffic and irrelevant network traffic. A large amount of non-business traffic enters the detection process, increasing detection overhead and reducing communication and detection efficiency. At the same time, it is easy for attackers to launch covert attacks using non-business ports / protocols.
[0167] To address the aforementioned issues and their root causes, this scenario example considers a comprehensive design that utilizes a three-dimensional hierarchical detection system based on heartbeat communication (IP + protocol type + port), multi-source data fusion early warning, three-level emergency response, millisecond-level primary / backup switching, local emergency takeover, and iterative model optimization. This approach aims to achieve dual protection of remote surgical communication security and surgical continuity.
[0168] For specific implementation, please refer to Figure 10 As shown, a remote surgical communication system (e.g., a surgical robot communication system) is first constructed. This system includes: 1- Surgical robot remote doctor terminal (e.g., doctor terminal), 2- Surgical robot system patient terminal (e.g., patient terminal), 3- Central control server, 4- Main communication server, 5- Backup communication server, 6- Web server, 7- Cloud server provider network security protection platform (e.g., security protection platform), and 8- Patient-side local control terminal (e.g., patient terminal). The specific functions and connections of each node are shown below.
[0169] The aforementioned remote doctor terminal of the surgical robot (robot system terminal) can: issue surgical motion control commands, receive 3D endoscopic images and surgical status data, maintain heartbeat communication with the main / backup communication server as the robot system terminal, and receive attack warning information; at the same time, it can also maintain heartbeat communication with the central control server and execute relevant server switching commands. The aforementioned surgical robot system's patient-side (robot system terminal) executes remote control commands, acquires surgical images (e.g., 3D endoscopic images) and robot operating status data, maintains heartbeat communication with the primary / backup communication server as the robot system terminal, and has a local control terminal that can take over robot control by switching local commands in an emergency; at the same time, it can also maintain heartbeat communication with the central control server and execute relevant server switching commands; The aforementioned central control server serves as the core of system data management and decision-making. It connects bidirectionally to all nodes, enabling multi-source data fusion analysis, attack risk assessment, security policy execution, automatic primary / backup server switching, and synchronizing a three-dimensional whitelist (IP + protocol type + port) and non-business traffic filtering rules to the cloud security protection platform. It also receives network security incident reports and statistical data from the cloud security protection platform. Furthermore, it can interact with the web server to exchange three-dimensional whitelists, server status, emergency operation instructions, and network security incident information; and synchronize server status with the primary / backup communication servers. The aforementioned primary / backup communication servers: carry the core data transmission from end to end in remote surgery. The primary server operates normally, while the backup server synchronizes its status in real time and supports millisecond-level switching. They extract and store the source IP, business protocol type, and dedicated port of normal communication from the heartbeat communication of the robot system terminal, establish a three-dimensional whitelist, and report it to the central control server and cloud security protection platform to execute the three-dimensional layered detection strategy of IP + protocol type + port. The aforementioned web server serves as a monitoring platform for the remote surgical communication security system. It enables the visualization of surgical location, server status, network parameters, attack events, emergency response logs, and a three-dimensional whitelist. It also receives temporary manual security commands and forwards them to the central control server, supporting manual management of the three-dimensional whitelist. The aforementioned cloud server provider's network security protection platform includes a DDoS protection module (terabit-level traffic scrubbing), a cloud firewall module (tens of millions of IP reputation databases), and a security center module (SOAR automated response). It provides basic attack detection, traffic scrubbing, and attack tracing capabilities, receives instructions and a three-dimensional whitelist from the central control server, and executes a three-dimensional layered detection strategy to achieve pre-filtering of non-business traffic.
[0170] Specifically, each node achieves bidirectional networking through an encrypted network. The remote doctor / patient end of the surgical robot establishes a dedicated encrypted heartbeat communication link with the primary / backup communication server. The primary / backup communication server establishes a three-dimensional whitelist synchronization link with the central control server and cloud security protection platform. The web server establishes a dedicated encrypted command transmission link with the central control server.
[0171] Based on the above system, see Figure 10 and Figure 11 As shown, the specific implementation can include five core steps: system initialization and data acquisition configuration, configuration of three-dimensional hierarchical detection based on heartbeat communication (IP + protocol type + port), real-time attack early warning detection, hierarchical emergency response execution, and attack analysis and model optimization. The specific operations of each step are shown below.
[0172] Step 1: System initialization and data acquisition configuration.
[0173] In practice, firstly, a remote surgical communication security architecture can be built, connecting the main / backup communication servers to the cloud server provider's network security protection platform, completing the bidirectional networking of the central control server, web server and all terminals / servers, and establishing a dedicated command transmission link between the web server and the central control server; Next, a full-link encrypted transmission protocol can be configured, including encrypted surgical data transmission between the surgical robot and the communication server, encrypted management data transmission between the central control server and each node, and encrypted instruction transmission between the web server and the central control server. At the same time, an encrypted heartbeat communication protocol between the remote doctor / patient end of the surgical robot and the main / backup communication server can be configured, and the heartbeat communication frequency and data format can be set. Then, the central control server can configure unified data collection rules to collect in real time: network traffic data of the main / backup communication server (data packet size, transmission rate, number of connections, protocol type, port information); device and network status data of the surgical robot remote doctor / patient end (communication latency, link stability, command reception / sending success rate, heartbeat communication status); and operating status data of each server (CPU utilization, memory usage, command processing rate). The collected data is preprocessed and synchronized to the Web server for visualization. Furthermore, the central control server can be used to preset attack warning thresholds based on the normal data characteristics of remote surgical communication, and combined with the attack intensity, server operating status, scope of impact of remote surgery, and protocol / port status to formulate three-level emergency response trigger conditions, which are then synchronized to the web server for filing. Furthermore, configure the monitoring platform function of the web server, build a visual display interface for surgical location and server information, real-time monitoring of network parameters, attack monitoring and emergency response, system status summary, and a three-dimensional whitelist of IP + protocol type + port, develop a manual security command receiving interface and set command verification, encryption and forwarding rules; Finally, the central control server can be used to pre-define a list of business protocol types and business port segments / fixed ports specific to the remote surgery business based on its characteristics. This list can be synchronized to the primary / backup communication server and the cloud server provider's network security protection platform as a benchmark for heartbeat communication extraction and non-business traffic filtering. At the same time, non-business traffic filtering rules can be configured to clarify the scope of protocols / ports to be directly filtered and the exception handling mechanism.
[0174] Step 2: Configure three-dimensional layered detection based on heartbeat communication (IP + protocol type + port).
[0175] For specific implementation, please refer to Figure 12 As shown, firstly, in the pre-collection and verification stage, the remote doctor terminal of the surgical robot, the patient terminal of the surgical robot system, and the primary / backup communication server establish continuous encrypted heartbeat communication. The primary / backup communication server synchronously extracts the terminal's real source IP, service protocol type, and service-specific port from the heartbeat communication data packet, and uses a three-dimensional whitelist (e.g., a preset whitelist) to verify the legality, validity, and matching of the protocol / port with the preset service list. Secondly, the primary / backup communication servers will mark the verified IP + protocol type + port combination as normal business communication characteristics, establish and update the three-dimensional whitelist of IP + protocol type + port in real time, and synchronize it to the central control server and the cloud server provider's network security protection platform. The whitelist supports manual addition / deletion / modification of single or combined characteristics through the web server. Furthermore, the central control server configures a three-dimensional layered detection strategy for the primary / backup communication server and the cloud security protection platform to achieve three layers of protection detection (e.g., first detection and second detection): 1) Direct filtering of non-business traffic: For traffic that does not match the three-dimensional whitelist protocol type / port, regardless of whether the IP is in the whitelist, it is directly filtered by the cloud security protection platform and does not enter the subsequent detection stage; 2) Lightweight detection of normal business traffic: For IP + protocol type + port combinations that fully match the three-dimensional whitelist, only basic traffic anomalies (such as traffic surges exceeding thresholds, abnormal protocol interaction formats) are detected, simplifying the detection process and reducing detection overhead. 3) Focused detection of unfamiliar / abnormal traffic: For traffic from unfamiliar IPs, or IPs that match the whitelist but have abnormal protocol types / ports, we will launch in-depth detection such as full-dimensional traffic analysis, malicious feature matching, IP reputation database query, and protocol behavior analysis to improve the accuracy of attack identification.
[0176] For details, please refer to Figure 11 As shown, it can include the following specific contents. In the diagram, S1 (system initialization and data acquisition configuration) is the basic preparation stage of the entire process. After completing the architecture construction, encryption configuration, data acquisition rule setting, early warning / response condition configuration, and monitoring platform construction, it enters S2; S2 (3D Layered Detection Configuration) is the pre-attack detection strategy configuration stage. After completing the heartbeat communication establishment, 3D whitelist synchronization, and 3D protection strategy configuration, it enters the S3 continuous detection stage. S3 (Real-time Attack Warning Detection) is a routine detection step. It continuously and cyclically detects when there is no attack risk, and immediately triggers S4 when a potential attack risk is detected. S4 (Tiered Emergency Response Execution) is the emergency response phase. It automatically triggers a light / medium / severe tiered response based on the attack intensity, server status, surgical impact, and three-dimensional anomaly type. After the response is completed, it proceeds to S5. S5 (Attack Analysis and Model Optimization) is a closed-loop iterative process. After summarizing the attack data of the entire process and optimizing the model and strategy, the optimization results are fed back to S2 and S3 to update the detection configuration and model parameters, so as to continuously upgrade the protection capabilities. When there is no attack risk, S3 directly completes a single detection cycle. After S5 is optimized, it also enters the continuous loop detection stage.
[0177] The overall process forms a complete closed loop of "configuration-detection-response-optimization-reconfiguration", highlighting the iterative optimization characteristics of the pre-configuration and protection model based on the three-dimensional hierarchical detection of IP + protocol type + port using heartbeat communication. Figure 12 For details on the relevant connection data, please refer to Table 1.
[0178] Table 1
[0179] Step 3: Real-time attack warning and detection.
[0180] In practice, firstly, the primary / backup communication server collaborates with the cloud server provider's network security protection platform to perform detection according to a three-dimensional layered detection strategy: the cloud security protection platform first filters non-business protocol / port traffic, and then performs light / key detection on the remaining traffic; for the key detection traffic, new protocol type anomaly identification and port scanning behavior detection are added, and the cloud security protection platform's DDoS protection module and cloud firewall module simultaneously analyze the compliance of protocol interactions and the rationality of port access, and transmit the filtering results and detection results to the central control server in real time; Secondly, in the fusion judgment and early warning recording stage, the central control server integrates multi-source data such as three-dimensional layered detection results, non-business traffic filtering results, surgical robot end operation status data, server operation status data, and heartbeat communication status data to make multi-dimensional judgments, exclude traffic fluctuations in normal surgical communication, normal interaction of protocols / ports, and avoid false alarms caused by single IP detection or unfiltered non-business traffic. Then, based on preset thresholds and data fusion, the central control server determines potential attack risks and generates attack warning information (including attack type, attack source IP, attack intensity, affected nodes / links, attack source IP type, abnormal protocol type, abnormal port, and whether it is a non-business traffic attack) at least 0.5 seconds in advance. This information is simultaneously pushed to the remote doctor / patient terminal of the surgical robot and a pop-up reminder is displayed on the web server. If the IP is on the whitelist but the protocol / port is abnormal, an additional special alarm for normal IP but abnormal protocol / port is pushed to remind staff to check whether the terminal has been compromised, the protocol has been tampered with, or the port has been exploited. Finally, the central control server initiates full recording of attack data (e.g., attack data recording), retaining full-link data of the entire attack process (including three-dimensional layered detection records, non-business traffic filtering records, protocol / port detection records, and heartbeat communication records), and synchronizing it to the web server for storage backup.
[0181] Step 4: Implement tiered emergency response.
[0182] In practice, the central control server determines the attack level based on attack information (including attack intensity, server status, scope of impact of the operation, and abnormal combination types of IP + protocol type + port), and automatically triggers a three-level emergency response mechanism of light, medium and heavy. The web server synchronizes the response status and logs in real time, and also supports staff to issue manual security commands through the web server, which are executed by the central control server first.
[0183] 4.1 Mild Attack Response
[0184] Regarding the triggering conditions: A small amount of abnormal traffic was detected (minor abnormality from unfamiliar IPs / abnormal basic traffic from whitelisted IPs / minor abnormality from whitelisted IPs + protocol / port). The primary / backup servers were operating normally and did not affect the transmission of surgical instructions.
[0185] For emergency response procedures, please refer to Figure 13 As shown, it may include the following: ① If the IP is an unfamiliar IP and the anomaly is minor: The central control server instructs the cloud security protection platform to call the ModifyDDoSBlackWhiteIpList interface to accurately add the attacking source IP to the blacklist without affecting normal surgical communication; specifically, the IP can be added to the blacklist and blocked for 10-15 seconds. If no actual attack is found, the IP will be unblocked. ② If it is a whitelisted IP and the basic traffic is abnormal: the central control server immediately pushes an alarm to the web server and staff terminals, and initiates a deep review of the abnormal traffic. Traffic limiting is only implemented when an attack risk is confirmed, and direct blocking is not used. ③ If it is a whitelisted IP and the protocol / port is slightly abnormal: The central control server pushes a special alarm and initiates a deep re-examination of the protocol / port. Rate limiting is only applied to the IP + abnormal protocol / port combination when an attack risk is confirmed. Communication between the IP and normal protocol / port is not blocked. If no attack risk is confirmed, the alarm is lifted and normal communication is restored. ④ Continuously monitor attack sources / abnormal combinations. If an unknown IP does not attack for 10-15 seconds, it will be automatically removed from the blacklist. If the abnormal items in the whitelist are re-checked and found to be risk-free, the alarm will be lifted. If the attack continues to escalate, a moderate response will be triggered. ⑤ Maintain uninterrupted surgical communication throughout the entire process, synchronizing response status and test results to the web server. After the response is completed, re-examine and incrementally update the 3D whitelist.
[0186] 4.2 Response to a Moderate Attack
[0187] Regarding the triggering conditions: The main communication server fails (communication link interruption for more than 3 seconds), while the backup server is operating normally; or a large number of unknown IPs launch an attack that cannot be intercepted by light detection and does not affect the core transmission of surgical instructions; or multiple whitelisted IPs show protocol / port abnormalities, posing a risk of mass intrusion.
[0188] For emergency response procedures, please refer to Figure 14 As shown, it may include the following: ① Parallel processing 1: The central control server automatically triggers the primary / backup switch, switching the link between the surgical robot and the communication server to the backup server within 0.3 seconds, and synchronizing the 3D whitelist and hierarchical detection strategy to the backup server; ② Parallel processing 2: If it is a large number of unknown IP attacks, the cloud security protection platform's IP reputation database will be linked to block malicious unknown IPs in batches. At the same time, the cloud security protection platform will be instructed to strengthen the protection of backup servers, adjust the DDoS cleaning threshold, enable AI intelligent protection, and start full-link traffic cleaning for unknown IPs. ③ Parallel processing 3: Intercept abnormal protocols / ports across the entire link and add the abnormal protocol types / ports to a temporary blacklist; ④ After the response and handling are completed, the primary server can automatically switch back or maintain a primary-backup dual-active state after being repaired, and the switchover decision and logs are synchronized to the Web server; then, a comprehensive review of the protocols / ports of all whitelisted IPs can be performed; and incremental updates can be carried out.
[0189] The entire process is handled remotely without human intervention, ensuring the continuity of the surgical procedure.
[0190] 4.3 Severe Attack Response
[0191] Triggering conditions: Both the primary and backup servers are paralyzed and unable to communicate normally; or the attack results in an extremely high risk of surgical instructions being tampered with; or the whitelisted IPs are confirmed to have been compromised / impersonated, causing core communication anomalies; or the protocol / port is maliciously tampered with, resulting in abnormal surgical data transmission.
[0192] For emergency response procedures, please refer to Figure 15 As shown, it may include the following: ① The central control server instructs the local control terminal on the patient's end of the surgical robot system to take over control of the robot and suspend remote operation; if the whitelisted IP is abnormal, the IP is immediately removed from the whitelist and added to the blacklist, and a full re-examination is initiated for other whitelisted IPs; if the protocol / port is tampered with, the abnormal protocol / port is immediately added to the blacklist and the protocol / port verification rules are strengthened. ② Instruct the local control terminal to encrypt and store surgical data (operation records, robot parameters, surgical images), and attempt to send the data back to the central control server via a dedicated 5G backup link; ③ The command cloud security protection platform activates the highest level of protection, and works with the SOAR automated response module to trace the source of unfamiliar IPs and intercept them across the entire chain, and to block and trace the source of abnormal protocols / ports across the entire chain; at the same time, it sends emergency alarms to technical personnel, and the alarm information is prominently displayed on the web server; ④ After the primary and backup servers are repaired, the attack is completely blocked, and the whitelisted IPs and protocols / ports are re-checked and found to be risk-free, the risk suppression is completed; the central control server instructs the local terminal to return control, synchronize local surgical data to the primary server, and restore the normal remote surgical mode; and re-checks and incrementally updates the three-dimensional whitelist, while updating the layered detection strategy, and the entire status is displayed in real time on the Web server.
[0193] Step 5: Attack analysis and model optimization.
[0194] In practice, firstly, after the emergency response is completed (attack interception / server recovery / operation completion), the central control server summarizes the entire attack process data (including attack type, source IP, abnormal combination of IP + protocol type + port, attack duration, traffic peak, protection measures, response effect, operation impact, three-dimensional layered detection effect, non-business traffic filtering effect, etc.) and transmits it to the cloud security protection platform and web server. Secondly, the cloud security protection platform generates attack analysis reports (including attack details, protection vulnerabilities, optimization suggestions for three-dimensional layered detection strategies, optimization suggestions for non-business traffic filtering rules, and security hardening suggestions for business protocols / ports) and Level 3 audit reports based on aggregated data. The reports are displayed visually on the web server and support multi-dimensional queries. Next, the central control server inputs the core data of the attack analysis report into the built-in attack detection model, optimizes the model parameters through machine learning algorithms, focusing on optimizing the matching rules of IP + protocol type + port, non-business traffic filtering thresholds, and identification features of abnormal protocols / ports, updates the attack identification feature library and warning thresholds, and dynamically optimizes the judgment logic in conjunction with cloud security threat intelligence; at the same time, it optimizes the verification rules of the three-dimensional whitelist to improve the ability to identify complex attacks such as protocol tampering, port exploitation, and IP spoofing + abnormal protocols / ports; Finally, the central control server synchronizes the optimized detection model, 3D layered detection strategy, and non-business traffic filtering rules to the cloud security protection platform and the primary / backup communication server, and registers them on the web server to achieve iterative upgrades of the system's protection capabilities.
[0195] Furthermore, through real-time attack early warning detection, attack analysis, and model optimization, continuous cyclical detection and protection optimization can be achieved, thereby continuously improving protection capabilities.
[0196] The above scenario examples validate the remote communication processing method for the surgical robot system provided in this manual. By employing a three-dimensional layered detection strategy based on heartbeat communication (IP + protocol type + port), the method utilizes the encrypted heartbeat communication between the surgical robot system terminal and server to synchronously extract and verify the source IP, service protocol type, and service-specific port of normal communication. A dynamic three-dimensional whitelist is established, achieving three layers of protection: direct filtering of non-service traffic, lightweight detection of normal service traffic, and focused detection of unfamiliar / abnormal traffic. This significantly reduces the detection overhead of normal surgical communication and improves communication efficiency, while also enabling targeted deep detection of unfamiliar IPs and abnormal protocols / ports, greatly improving the accuracy of attack identification. Simultaneously, special re-inspections and alarms are performed on the whitelisted IPs and abnormal protocols / ports, effectively preventing covert attacks such as terminal intrusion, protocol tampering, and port exploitation, distinguishing it from existing methods. The technology employs a unified IP detection mode; by adopting a non-business traffic pre-filtering mechanism: based on the protocol types and ports specific to surgical procedures, non-business traffic is pre-filtered in the cloud, preventing it from entering subsequent detection stages. This reduces detection resource consumption at the source, significantly improving the transmission efficiency of normal surgical communication and the processing efficiency of the detection stage. Simultaneously, it prevents attackers from using non-business traffic for attack camouflage, enhancing the overall defense capabilities of the system; and by adopting a multi-source data fusion early warning mechanism: breaking through the traditional model of single traffic analysis, it fuses and analyzes three-dimensional layered detection results, non-business traffic filtering results, heartbeat communication status data, surgical robot operation status data, and server operation status data. Combining the scenario-specific characteristics of remote surgical communication with the specific characteristics of business protocols / ports, it excludes normal traffic fluctuations and normal protocol / port interactions, achieving zero-risk attack detection.A 5-second or longer warning time significantly reduces false alarms, allowing ample time for emergency preparation and preventing protective measures from interfering with normal surgery. A three-tiered emergency response design based on surgical impact and three-dimensional features is employed: tiered triggering conditions are established by combining attack intensity, server operating status, impact of remote surgical command transmission, and abnormal IP + protocol type + port combinations. This allows for refined and differentiated emergency response handling for unfamiliar IPs, whitelisted IPs, and whitelisted IPs with abnormal protocols / ports. This achieves "precise IP blocking / protocol / port re-inspection for light attacks, millisecond-level primary / backup switching + batch malicious IP / abnormal protocol / port interception for medium attacks, and local emergency takeover + comprehensive three-dimensional whitelist re-inspection for severe attacks," completely resolving the traditional "one-size-fits-all" approach. The system addresses the drawbacks of traditional "knife-cut" protection, balancing safety and surgical continuity to meet the uninterrupted medical requirements of remote surgery. It employs a centralized control server for unified management and decision-making: a dedicated central control server serves as the system core, enabling unified collection and analysis of multi-source data, unified execution of security policies, automatic switching between primary and backup servers, and unified synchronization and management of a three-dimensional whitelist of IP, protocol type, and port. This solves the problems of fragmented data, poor coordination, and chaotic multi-dimensional feature management in existing systems, ensuring the timeliness and accuracy of all protective operations. Furthermore, it utilizes millisecond-level automatic switching between primary and backup communication servers: a pre-defined quantitative judgment standard for primary server failure is used, achieved through a communication link switching module built into the central control server.Automatic primary / backup failover within 3 seconds, with synchronized 3D whitelist and hierarchical detection strategies during failover, supports active-active redundancy, and solves the problems of low efficiency and asynchronous strategies in manual failover. This is crucial for ensuring continuous transmission of surgical instructions and meeting the real-time requirements of remote surgery. By integrating visualization and manual emergency response via a web server: a dedicated web monitoring platform is designed to achieve visualized management and manual operation of the IP + protocol type + port 3D whitelist. Real-time data display of non-business traffic filtering and protocol / port detection is added, enabling full-dimensional visualization of surgery, network, heartbeat communication, 3D hierarchical detection, and security status. It also supports the issuance and priority execution of temporary manual security commands and whitelist management commands, balancing automated protection and manual emergency intervention, and improving the system's flexibility in responding to sudden attacks. Through iterative optimization of the attack data closed-loop protection model: it realizes full-process attack data (including 3D hierarchical detection, non-business traffic...) The system collects, aggregates, and analyzes data (including filtering, protocol / port detection, heartbeat communication, and whitelist management data). Based on machine learning algorithms, it continuously optimizes the attack detection model, focusing on improving the matching rules for IP + protocol type + port and the three-dimensional layered detection strategy. This is simultaneously updated to the cloud security protection platform and communication server, forming a complete closed loop of "filtering-detection-response-analysis-optimization." This solves the problem of existing protection capabilities being unable to iterate, achieving highly efficient defense against similar and compound attacks. By employing a patient-side local emergency takeover and dual data protection mechanism: when both primary and backup servers fail, the local control terminal on the patient side of the surgical robot system takes over robot control, avoiding surgical errors caused by lost / tampered instructions. Simultaneously, surgical data is protected by "local encrypted storage + remote feedback via backup link," ensuring patient safety and data integrity. This serves as the last line of defense for remote surgical communication security, significantly reducing the probability of medical accidents.
[0197] While this specification provides the steps of operation for the methods described in the embodiments or flowcharts, more or fewer steps may be included based on conventional or non-inventive means. The order of steps listed in the embodiments is merely one possible order of execution among many steps and does not represent the only possible order. In actual device or client product execution, the methods shown in the embodiments or drawings may be executed sequentially or in parallel (e.g., in a parallel processor or multi-threaded processing environment, or even a distributed data processing environment). The terms "comprising," "including," or any other variations thereof are intended to cover a non-exclusive inclusion, such that a process, method, product, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, product, or apparatus. Without further limitations, the presence of other identical or equivalent elements in a process, method, product, or apparatus that includes said elements is not excluded. The terms "first," "second," etc., are used to denote names and do not indicate any particular order.
[0198] Those skilled in the art will also know that, besides implementing the controller in the form of purely computer-readable program code, the same functions can be achieved by logically programming the method steps, making the controller take the form of logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers (PLCs), and embedded microcontrollers. Therefore, such a controller can be considered a hardware component, and the devices within it used to implement various functions can also be considered structures within that hardware component. Alternatively, the devices used to implement various functions can be considered as both software modules implementing the method and structures within a hardware component.
[0199] This specification can be described in the general context of computer-executable instructions that are executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, classes, etc., that perform a specific task or implement a specific abstract data type. This specification can also be practiced in distributed computing environments, where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer-readable storage media, including storage devices.
[0200] As can be seen from the above description of the embodiments, those skilled in the art can clearly understand that this specification can be implemented by means of software plus necessary general-purpose hardware platforms. Based on this understanding, the technical solutions of this specification can essentially be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, mobile terminal, computer device, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments of this specification.
[0201] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on its differences from other embodiments. This specification can be used in numerous general-purpose or special-purpose computer system environments or configurations. Examples include: personal computers, computer equipment, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable electronic devices, network PCs, minicomputers, mainframe computers, and distributed computing environments including any of the above systems or devices, etc.
[0202] Although this specification has been described by way of examples, those skilled in the art will know that this application has many variations and modifications, and it is intended that the text described herein include these variations and modifications without departing from the spirit of this specification.
Claims
1. A remote communication processing method for a surgical robot system, characterized in that, Applications in surgical robot communication systems include: The security protection platform is invoked to perform a first detection on the target business communication data according to a preset whitelist, and a first detection result is obtained; wherein, the preset whitelist is constructed in advance based on the heartbeat communication data of the patient terminal and doctor terminal of the surgical robot system under normal conditions; the preset whitelist includes at least: preset port information, and preset combination of source IP and protocol type; Based on the first detection result, if it is determined that the target business communication data belongs to the first type of business communication data, the target business communication data is forwarded to the communication server through the security protection platform; and the first detection result is sent to the central control server; wherein, the first type of business communication data is the target business communication data that matches the combination of the target source IP and the target protocol type with the preset whitelist; The communication server is invoked to perform a second detection based on network traffic on the target business communication data, and the second detection result is obtained; the second detection result is then sent to the central control server. The central control server is used to obtain current associated data about the surgical robot communication system; and by fusing the first detection result, the second detection result, and the current associated data, a third detection is performed on the target business communication data based on the remote surgical communication scenario to obtain the third detection result; wherein, the associated data includes at least: the operating data of the patient terminal, the operating data of the doctor terminal, and the status data of the communication server; Based on the third detection result, determine whether the target business communication data is attack data.
2. The remote communication processing method for the surgical robot system according to claim 1, characterized in that, The security protection platform performs a first detection on the target business communication data based on a preset whitelist, including: The security protection platform is invoked to extract the target source IP, target protocol type, and target port information of the target business communication data; The system detects whether the combination of the target source IP and the target protocol type, as well as the target port information, of the target business communication data match the preset whitelist. When the combination of the target source IP and the target protocol type of the target business communication data matches a preset whitelist, the target business communication data is determined to belong to the first category of business communication data.
3. The remote communication processing method for the surgical robot system according to claim 2, characterized in that, When the combination of the target source IP and the target protocol type of the target service communication data matches a preset whitelist, the method further includes: Determine the first traffic parameters of the target service communication data; wherein the first traffic parameters include at least one of the following: number of packets sent per second, number of packets lost, and data packet size; Based on the first traffic parameter threshold, detect whether the first traffic parameter of the target service communication data meets the first traffic requirement; When the first traffic parameter of the target service communication data meets the first traffic requirement, the target service communication data is determined to belong to the first type of service communication data.
4. The remote communication processing method for the surgical robot system according to claim 3, characterized in that, The method further includes: When it is determined that the combination of the target source IP and the target protocol type of the target business communication data does not match the preset whitelist, or when it is determined that the first traffic parameter of the target business communication data does not meet the first traffic requirement, the target business communication data is determined to belong to the second type of business communication data. The security protection platform is invoked to intercept the target business communication data.
5. The remote communication processing method for the surgical robot system according to claim 2, characterized in that, When the combination of the target source IP and the target protocol type of the target service communication data matches a preset whitelist, the method further includes: When it is determined that the target port information of the target service communication data matches the preset whitelist, a lightweight detection tag is set for the target service communication data; When it is determined that the target port information of the target service communication data does not match the preset whitelist, a key detection mark is set for the target service communication data.
6. The remote communication processing method for the surgical robot system according to claim 5, characterized in that, The step of calling the communication server to perform a second detection of the target service communication data based on network traffic includes: The communication server is invoked to determine the matching target detection rules based on the detection tags carried in the target business communication data; According to the target detection rules, the target service communication data is subjected to a second detection based on network traffic.
7. The remote communication processing method for the surgical robot system according to claim 6, characterized in that, The second detection of the target service communication data based on network traffic includes: When the detection marker is a lightweight detection marker, the corresponding second detection result is obtained by detecting the data volume of the data packets involved in the target service communication data and the format information of the target protocol; When the detection marker is a key detection marker, a second traffic parameter threshold that matches the target service communication data is determined; and based on the second traffic parameter threshold, anomaly detection is performed on the second traffic parameters related to the target service communication data to obtain the corresponding second detection result; wherein, the second traffic parameter includes at least one of the following: data packet frequency, data packet size range, and data packet type.
8. The remote communication processing method for the surgical robot system according to claim 1, characterized in that, The current associated data also includes surgical information; The surgical information includes at least one of the following: surgical type, surgical stage, degree of dependence of surgical operations on remote communication during the surgical process, surgical instruments on the patient terminal involved in the surgical process, and surgical instructions related to surgical operation control involved in the surgical process.
9. The remote communication processing method for the surgical robot system according to claim 8, characterized in that, The third detection of the target business communication data based on the remote surgical communication scenario, by fusing the first detection result, the second detection result, and the current associated data, includes: The target fused data is obtained by fusing the first detection result, the second detection result, and the current associated data; Based on the target fusion data, communication attack analysis and detection are performed to obtain the corresponding target communication attack analysis and detection results; Based on the target fusion data and the target communication attack analysis and detection results, the impact of communication attacks on remote surgical control is detected, and the corresponding target surgical impact detection results are obtained. Based on the target communication attack analysis and detection results and the target surgical impact detection results, the corresponding third detection result is determined.
10. The remote communication processing method for the surgical robot system according to claim 9, characterized in that, The target surgical impact detection results include at least one of the following: the device node of the affected doctor terminal and the degree of impact, the device node of the affected patient terminal and the degree of impact, and the affected surgical operation and the mode of impact.
11. The remote communication processing method for the surgical robot system according to claim 9, characterized in that, After determining whether the target business communication data is attack data based on the third detection result, the method further includes: When the target business communication data is determined to be attack data, the target business communication data is intercepted. Based on the third detection result, the attack level of the target business communication data is determined; wherein, the attack level includes: light attack, medium attack, and severe attack; Based on the attack level of the target business communication data, determine the corresponding target emergency response handling strategy; Based on the aforementioned target emergency response strategy, emergency response processing is carried out regarding the surgical robot communication system.
12. The remote communication processing method for the surgical robot system according to claim 11, characterized in that, The communication server includes at least: a main communication server and a backup communication server; Accordingly, based on the third detection result, when it is determined that the main communication server and the backup communication server are in normal condition, the attack level of the target business communication data is determined to be a mild attack. Based on the third detection result, it has been determined that one of the main communication server and the backup communication server is in an abnormal state, and the attack level of the target business communication data is determined to be a medium attack. Based on the third detection result, when it is determined that both the main communication server and the backup communication server are in an abnormal state, the attack level on the target business communication data is determined to be a severe attack.
13. The remote communication processing method for the surgical robot system according to claim 1, characterized in that, The method further includes: During the security testing phase, the communication server is invoked to collect heartbeat communication data from the patient's terminal and the doctor's terminal of the surgical robot system under normal conditions. Based on the heartbeat communication data, the corresponding heartbeat communication features under normal conditions are extracted; A preset whitelist is constructed based on the heartbeat communication characteristics under normal conditions.
14. The remote communication processing method for the surgical robot system according to claim 13, characterized in that, The method further includes: Every preset time interval, the central control server is invoked to organize the business communication data processing records of the surgical robot communication system for the current time period; and the business communication data processing records for the current time period are uploaded to the security protection platform. The security protection platform processes business communication data for the current time period to generate an attack analysis report for that time period. The preset whitelist is updated using the central control server based on the attack analysis report for the current time period.
15. A remote communication processing device for a surgical robot system, characterized in that, Applications in surgical robot communication systems include: The first detection module is used to call the security protection platform to perform a first detection on the target business communication data according to a preset whitelist and obtain a first detection result; wherein, the preset whitelist is constructed in advance based on the heartbeat communication data of the patient terminal and doctor terminal of the surgical robot system under normal conditions; the preset whitelist includes at least: preset port information, and preset combination of source IP and protocol type; The forwarding module is used to forward the target business communication data to the communication server through the security protection platform when it is determined that the target business communication data belongs to the first type of business communication data based on the first detection result; and to send the first detection result to the central control server; wherein, the first type of business communication data is the target business communication data that matches the combination of the target source IP and the target protocol type with the preset whitelist; The second detection module is used to call the communication server to perform a second detection on the target business communication data based on network traffic, obtain the second detection result, and send the second detection result to the central control server. The third detection module is used to obtain current associated data about the surgical robot communication system using the central control server; and to perform a third detection on the target business communication data based on the remote surgical communication scenario by fusing the first detection result, the second detection result, and the current associated data to obtain a third detection result; wherein, the associated data includes at least: the operating data of the patient terminal, the operating data of the doctor terminal, and the status data of the communication server; The determination module is used to determine whether the target business communication data is attack data based on the third detection result.
16. A surgical robot communication system, characterized in that, It includes at least: a central control server, a communication server, a security protection platform, and the doctor's terminal and patient terminal of the surgical robot system; among which, The communication server is used to transmit target business communication data about the doctor's terminal and / or the patient's terminal in the surgical robot communication system; The security protection platform is used to perform a first detection on the target business communication data accessed by the system; and if it is determined that the target business communication data belongs to the first type of business communication data, the target business communication data is forwarded to the communication server; The communication server is also used to perform a second detection on the target business communication data based on network traffic, and send the second detection result to the central control server. The central control server is used to acquire current associated data about the surgical robot communication system; and by fusing the first detection result, the second detection result, and the current associated data, it performs a third detection on the target business communication data based on the remote surgical communication scenario to determine whether the target business communication data is attack data.
17. A computer program product, characterized in that, The system includes a computer program that, when executed by a processor, implements the steps of the remote communication processing method for the surgical robot system according to any one of claims 1 to 14.