中国卫生信息管理杂志2024,Vol.21Issue(6) :909-914.DOI:10.3969/j.issn.1672-5166.2024.06.019

基于威胁情报的DNS助力医院网络安全建设实践

Practice of Using Threat Intelligence-Enabled DNS to Enhance Hospital Network Security

余莎莎 肖辉 郑清 赵幽
中国卫生信息管理杂志2024,Vol.21Issue(6) :909-914.DOI:10.3969/j.issn.1672-5166.2024.06.019

基于威胁情报的DNS助力医院网络安全建设实践

Practice of Using Threat Intelligence-Enabled DNS to Enhance Hospital Network Security

余莎莎 1肖辉 1郑清 1赵幽1
扫码查看

作者信息

  • 1. 武汉大学中南医院,湖北省武汉市,430071
  • 折叠

摘要

目的 利用威胁情报和域名解析系统(DNS)加强医院网络安全.方法 在医院互联网出口配置基于威胁情报的安全DNS策略,让医院终端及互联网信息系统通过安全DNS访问互联网.结果 应用安全DNS后,医院对外的恶意域名访问被100%拦截,能有效拦截和阻断高级持续性威胁.结论 通过应用基于威胁情报的安全DNS,提升了医院对网络安全漏洞的定位能力,缩短了响应时间,降低了处置成本,这对于做好医院网络安全加固和提升医院安全整体水平具有借鉴意义.

Abstract

Objective To enhance hospital network security using threat intelligence and DNS. Methods Configure a threat intelligence-enabled secure DNS strategy at the hospital's internet exit,allowing hospital terminals and internet information systems to access the internet through the secure DNS. Results After implementing the secure DNS,the hospital has achieved a 100% interception rate for outbound malicious domain access. It can effectively intercept and block advanced persistent threats. Conclusion By utilizing a secure DNS based on threat intelligence,the hospital has strengthened its ability to locate security threats,shortened the time and cost of threat response. It is of reference significance for strengthening hospital network security and improving the overall level of hospital security.

关键词

威胁情报/DNS/网络安全

Key words

threat intelligence/DNS/network security

引用本文复制引用

出版年

2024
中国卫生信息管理杂志
卫生部统计信息中心

中国卫生信息管理杂志

CSTPCD
影响因子:1.2
ISSN:1672-5166
段落导航相关论文