基于智能化监测平台的医疗数据交互风险治理研究
目的/意义 本研究聚焦医疗机构在API数据交互场景下的智能化风险监测平台建设,识别高风险漏洞,防止数据泄露,强化数据交互安全。方法/过程 采用数据平面开发套件技术实现旁路流量分析,实时监控某三甲综合医院业务系统的访问行为。基于OWASP公布的10大API安全漏洞,建立多维度风险评估模型,结合日常数据安全运营,构建“分析-监测-评估-溯源”数据交互安全保障体系。结果/结论 医院针对平台监测出的API安全漏洞、数据泄露类风险、Web攻击类风险、账号安全类风险,进行了专项整改,避免了数据泄露的发生,提升医院数据交互监测水平和安全保障能力。
Purpose/Significance This study focuses on the construction of an intelligent risk monitoring platform for medical institutions in API data interaction scenarios, identify high-risk vulnerabilities, prevent data leakage, and strengthen data exchange security. Method/Process Using Data Plane Development Kit technology to achieve bypass flow analysis and real-time monitoring of the access behavior of a tertiary comprehensive hospitals business system. Establish a multidimensional risk assessment model based on top 10 API security vulnerabilities published by OWASP, combined with daily data security operations, building a Analysis Monitoring Evaluation Traceability Data Interaction Security Guarantee System. Result/Conclusion The hospital has carried out special rectification for API security vulnerabilities, data leakage risks, web attack risks, and account security risks detected by the platform, avoiding the occurrence of data leaks and improving the hospitals data interaction monitoring level and security protection capabilities.
王利平、熊尚华、黄玉清、周宸棋、金珊
计算技术、计算机技术
PI风险监测风险评估模型旁路流量分析
PI Risk MonitorRisk Assessment ModelBypass flow analysis
王利平,熊尚华,黄玉清,周宸棋,金珊.基于智能化监测平台的医疗数据交互风险治理研究[EB/OL].(2025-04-02)[2025-08-18].https://www.biomedrxiv.org.cn/article/doi/bmr.202506.00069.点此复制
评论