节点文献
医院网络渗透测试与数据包分析技术实践
Technical Practice of Penetration Test and Data-package Analysis of Hospital Network
【摘要】 随着《中华人民共和国网络安全法》的实施,国家对网络安全合规性要求越来越严格。现有的基于特征匹配、静态的安全防御体系在安全新形势下正在逐渐失效。为检验医院网络安全防护能力,以查促改,北京协和医院对医院网站群进行了一次渗透测试,同时部署了网络全流量安全分析系统监控网络异常数据包。本文对此次演练过程中采用的暴力破解、SQL注入、文件包含、跨站脚本攻击、命令执行漏洞等技术手段进行了深入地分析。通过此次演练,有效地提升了各方面的安全处置能力。
【Abstract】 With the implementation of the People’s Republic of China’s Law on Network Security, the demands of network security’s compliance has become stricter. The existing static security defense system based on feature matching is gradually becoming weaker under the new security situation. In order to check and improve the network security defense capability of the hospital, a penetration test is conducted on the hospital’s website group. At the same time, a network traffic safety analysis system is deployed to monitor the anomalous network data-packages. The adopted brute-force attack, SQL injection, file inclusion, crosssite scripting attacks, command execution bugs and other technical means are analyzed thoroughly during the period of practice in the paper. All aspects of security disposal capabilities are enhanced effectively through this practice.
- 【文献出处】 中国卫生信息管理杂志 ,Chinese Journal of Health Informatics and Management , 编辑部邮箱 ,2017年06期
- 【分类号】R197.3;TP393.08
- 【被引频次】2
- 【下载频次】107