节点文献

医院网络渗透测试与数据包分析技术实践

Technical Practice of Penetration Test and Data-package Analysis of Hospital Network

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 孟晓阳朱卫国黄迎萍张楠陈小平

【Author】 Meng Xiaoyang;Zhu Weiguo;Huang Yingping;Zhang Nan;Chen Xiaoping;

【机构】 北京协和医院石化盈科信息技术有限责任公司成都科来软件有限公司

【摘要】 随着《中华人民共和国网络安全法》的实施,国家对网络安全合规性要求越来越严格。现有的基于特征匹配、静态的安全防御体系在安全新形势下正在逐渐失效。为检验医院网络安全防护能力,以查促改,北京协和医院对医院网站群进行了一次渗透测试,同时部署了网络全流量安全分析系统监控网络异常数据包。本文对此次演练过程中采用的暴力破解、SQL注入、文件包含、跨站脚本攻击、命令执行漏洞等技术手段进行了深入地分析。通过此次演练,有效地提升了各方面的安全处置能力。

【Abstract】 With the implementation of the People’s Republic of China’s Law on Network Security, the demands of network security’s compliance has become stricter. The existing static security defense system based on feature matching is gradually becoming weaker under the new security situation. In order to check and improve the network security defense capability of the hospital, a penetration test is conducted on the hospital’s website group. At the same time, a network traffic safety analysis system is deployed to monitor the anomalous network data-packages. The adopted brute-force attack, SQL injection, file inclusion, crosssite scripting attacks, command execution bugs and other technical means are analyzed thoroughly during the period of practice in the paper. All aspects of security disposal capabilities are enhanced effectively through this practice.

【基金】 中国医学科学院医学与健康科技创新工程-医学大数据信息采集和分析评估(课题编号:2016-12M-2-004)
  • 【文献出处】 中国卫生信息管理杂志 ,Chinese Journal of Health Informatics and Management , 编辑部邮箱 ,2017年06期
  • 【分类号】R197.3;TP393.08
  • 【被引频次】2
  • 【下载频次】107
节点文献中: 

本文链接的文献网络图示:

本文的引文网络