The medical trade can not audit the system
Go through the development of more than 20 years, China's medical information construction has already begun to take shape, and made considerable progress. However, it is still a minor plate of medical information construction that information is safe and secret, have influenced or restricted the information-based process seriously.
In the network safety engineering solution provided for medical trade at present, still wall with flues, choose for mainstream while being anti-virus, traditional the intersection of safety engineering and means these can only stop some from external to internal attack, and it is totally powerless to steal to coming from internal information, this causes " compromise door " The incident happens again and again, initiate important machine format losing, destruction, not merely influence the normal operation of the hospital network seriously, still threaten the patient's personal secrets and life security directly.
The audit system shows the might
How to stop the emergence of this kind of incident from the safe angle? The network resists the leaf of senior products manager in the Divine Land to fluffy and introduce to the reporter, if liken the internal network of the hospital into a room, then the fire wall, anti-virus software,etc. prevent the external invading doors and windows, there are databases of all kinds of information like a lockable book case in the room, but because of the need of the business, the person (medical worker) in this room Quite a lot will go in the book case to deposit and withdraw some materials, so they all have keys to the book case, so the one that even if add two locks or change the book case into a safe case and can not act. Then how could strengthen the safety of the book case?
We can add by one in the book case height " The lens " ,When who does it note accurately, make something in front of the book case. If is a bit more advanced, this " lens " Should also possess " The automatic recognition of picture " ,Find illegally and operate, automatic " call the police " Function.
In the network, this " lens " It is one that audits the system, it should possess two following essential features:
1) The protective target of the system is information and machine format carrier, generally speaking it is the database and server host computer loading database, either call it the information system or operation system wholly. Anyone (IP) ,Any operation to carrying on in this operation system of any time, such as landing, revise, delete, add etc., can write down accurately; Can also certainly set up it and carry on the record with pertinence under according with some specified conditions depending upon need. The system needs to have behavioral analytical technique based on conversation, the network security official can carry on the examination based on time to all visitors in present network, understand what operation was paid successively in the arbitrary period of each visitor, and support to visit the course to return. Be able to keep the long time enough in information recorded, so that ex post analysis, investigating and collecting evidence.
2) Systematic to possess the disguise, should use ing itself. While installing, will not cause any influence on the network, while using, will not arrive the perception easily. So require it is a integrated apparatus, use simultaneously, adopt the way of intercepting in the bypass to gathering, analyzing and discerning through the data flow connected to important operation system of the network.
The traditional database audits the products and only pays close attention to the audit of the database, hope that so as to protect important information, prevent distorting and letting out. Indeed, the database is the important place where the data are preserved, it is very necessary to audit. However, it is not enough to only audit databases. Because there are a lot of routes of data manipulation in violation of rules and regulations of internal personnel, some violate legal provisions and visit the database directly, some log on on the host computer server that the database locates, some download the important data file of the host computer of the database through FTP. Others visit the database through other procedures or middleware systems. So, must all carry on audit to database, host computer, HTTP agreement, Telnet, FTP agreement, network traffic, middleware system, could find violation, prevent the leakage of information all more sidedly.
The network resists the Divine Land SecFox-NBA network behavior and audits the system (the auditing type of business) Can carry on all azimuthal security audit to various databases, Windows and Unix host computers, WEB application systems in customer's business network. Resist the unique business -oriented audit tactics (Business-oriented Audit Policy, is abbreviated as BAP) in the Divine Land through the network Technology, user can host computer, database included toward some business go on, set for synthetically in one strategy, realize the accurate audit of this business, thus find the potential safety hazard of this business in time.
The meaning of business -oriented audit lies in: If Oracle database of one enterprise is installed under AIX system, the database administrator adopts Telnet and logs on on the host computer that the database locates, utilize here to visit and log on in the database, has derived the data of a large number of customers, then it is relevant to delete and operate in the daily record and record, download the data file through FTP. It is unable to obtain to any information only auditing the database, but can obtain to much useful information through auditing synthetically, auditing the daily record of the host computer at first can find this staff log on the host computer in non-working time, can record and log on and visit the order line of the database while auditing Telnet, auditing FTP can find that download the mass data, the information link bunch stands up to audit these, the behavior of this staff has no place to hide.