API流量监测技术在医院DMZ区的实践与应用
作者:
作者单位:

(南昌大学第二附属医院 南昌 330006)

作者简介:

魏阳,助理工程师,发表论文2篇;通信作者:刘卫方。

通讯作者:

中图分类号:

R-058

基金项目:


Practice and Application of API Traffic Monitoring Technology in the Demilitarized Zone of Hospitals
Author:
Affiliation:

(The Second Affiliated Hospital of Nanchang University, Nanchang 330006, China)

Fund Project:

  • 摘要
  • 图/表
  • 访问统计
  • 参考文献
  • 相似文献
  • 引证文献
  • 资源附件
  • 文章评论
    摘要:

    目的/意义 探索应用程序接口(application programming interface,API)流量监测技术应用于医院内外网缓冲区(demilitarized zone,DMZ)的场景、问题及应对策略,以提升医院数据安全防护能力。方法/过程 在医院DMZ区部署API流量监测系统,镜像获取流量,对已有数据进行预分类分级,定义敏感数据标签,建立API资产台账,分析API安全漏洞,设计风险场景审计模型,实时监测用户访问行为。结果/结论 系统实际监测流量均值近1G、峰值近2G,识别接口80 000余个、应用2 000余个,实现医院DMZ区核心业务全流量监测,有效保护了患者隐私数据。

    Abstract:

    Purpose/Significance To explore the scenarios, problems and countermeasures of applying application programming interface (API) traffic monitoring technology to the demilitarized zone (DMZ) of hospitals, so as to enhance the hospitals’ data security protection capabilities. Method/Process The API traffic monitoring system is deployed in the DMZ of the hospital. Traffic is obtained through mirroring. Existing data is pre-classified and graded, sensitive data labels are defined, API asset ledgers are established, API security vulnerabilities are analyzed, risk scenario audit models are designed, and user access behaviors are monitored in real time. Result/Conclusion The system actually monitors an average flow of nearly 1G and a peak flow of nearly 2G, identifies over 80 000 API and over 2 000 applications, and achieves full flow monitoring of core business in the hospital’s DMZ, and effectively protects patients’ privacy data.

    参考文献
    相似文献
    引证文献
引用本文

魏阳,刘卫方,康蘋. API流量监测技术在医院DMZ区的实践与应用[J].医学信息学杂志,2025,46(10):87-92

复制
分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:
  • 最后修改日期:2025-09-30
  • 录用日期:
  • 在线发布日期: 2025-11-12
  • 出版日期:

扫码关注

官方微信