医院近源网络攻击风险分析及对策建议
作者:
作者单位:

(北京协和医院 北京 100730)

作者简介:

孟晓阳,高级工程师,发表论文20余篇;通信作者:孙国强。

通讯作者:

中图分类号:

R-058

基金项目:

中国医学科学院医学与健康科技创新工程项目(项目编号:2022-I2M-1-019)。


Risk Analysis and Countermeasure Suggestions for Hospital Near-source Cyber-attacks
Author:
Affiliation:

(Peking Union Medical College Hospital,Beijing 100730,China)

Fund Project:

  • 摘要
  • 图/表
  • 访问统计
  • 参考文献
  • 相似文献
  • 引证文献
  • 资源附件
  • 文章评论
    摘要:

    目的/意义 分析医院面临的近源网络攻击风险,提出对策建议。方法/过程 结合实际工作经验,先以近源网络攻击者视角对医院网络架构、现场物理环境、人员行为等方面进行风险分析,再以防守者视角,结合合规要求和技术实践做法,提出对策建议。结果/结论 识别出无线局域网破解、有线网络插口暴露、自助机配置不当、投毒与钓鱼、敏感信息泄漏5类主要风险,提出加强Wi-Fi管理、联网终端准入全覆盖、多部门协作管理自助机设备、内网终端禁用移动存储介质、网络安全教育应与时俱进5条防范建议。

    Abstract:

    Purpose/Significance To analyze the risks of near-source cyber-attacks faced by hospitals, and to propose countermeasures. Method/Process Combined with practical work experience, the risk analysis of hospital network architecture, on-site physical environment, personnel behavior and other aspects is carried out from the perspective of near-source cyber-attacker. Then, from the perspective of defender and in combination with regulatory requirements and technical practices, countermeasures and suggestions are proposed. Result/Conclusion 5 main risks are identified, including wireless LAN cracking, exposed wired network sockets, improper configuration of self-service machines, poisoning & phishing, and sensitive information leakage. 5 preventive suggestions are put forward, including strengthening Wi-Fi management, full coverage of network terminal access, multi-department collaboration in self-service device management, disabling mobile storage media on Intranet terminals, and updating cyber-security education.

    参考文献
    相似文献
    引证文献
引用本文

孟晓阳,杨巍,张楠,等.医院近源网络攻击风险分析及对策建议[J].医学信息学杂志,2024,45(9):87-90

复制
分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:
  • 最后修改日期:2024-05-06
  • 录用日期:
  • 在线发布日期: 2024-10-17
  • 出版日期:

扫码关注

官方微信