IP Library › Granted Patent US 12,463,990
Granted Patent B2
US 12,463,990 · App. 18/512,891 · Granted Nov 4, 2025

Method and apparatus for visualizing medical device network and security attack

Inventors: Hyeok-Chan Kwon (Daejeon, KR); Byung-Ho Chung (Sejong-si, KR)
Assignee: Electronics and Telecommunications Research Institute
H04L63/1416H04L41/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,463,990
App. No.
18/512,891
Granted
Nov 4, 2025
Kind
B2
Abstract

Disclosed herein is a method for visualizing a medical device network and a security threat. The method includes representing nodes in zones that are divided into a server zone including nodes corresponding to server devices, a medical device zone including nodes corresponding to medical devices, a white zone including registered nodes excluding the server devices and the medical devices, and a gray zone including nodes included in none of the above-mentioned zones, representing links between the nodes, and representing a node and a link in which a security attack is detected using a different color when the security attack is detected in the node.

Claims (31)

1 . A method for visualizing a medical device network and a security threat, comprising:

representing nodes in zones that are divided into a server zone including nodes corresponding to server devices, a medical device zone including nodes corresponding to medical devices, a white zone including registered nodes excluding the server devices and the medical devices, and a gray zone including nodes included in none of the server zone, the medical device zone, and the white zone;

representing links between the nodes; and

representing a node and a link in which a security attack is detected using a different color when the security attack is detected in the node.

2 . The method of claim 1 , wherein types of the nodes include an IP node corresponding to a terminal having an IP address, a subnet node corresponding to each subnet address, a gray node for connecting nodes corresponding to the gray zone, and a white node for connecting nodes corresponding to the white zone.

3 . The method of claim 2 , wherein types of the links include an IP-node-to-subnet-node type, a subnet-node-to-subnet-node type, a gray-node-to-IP-node type, a white-node-to-IP-node type, a gray-node-to-subnet-node type, a white-node-to-subnet-node type, and an IP-node-to-IP-node type.

4 . The method of claim 3 , wherein a link of the IP-node-to-IP-node type is generated when a security attack is detected.

5 . The method of claim 3 , wherein:

a link of the IP-node-to-subnet-node type represents an IP node belonging to a subnet address corresponding to the subnet node, and

a link of the subnet-node-to-subnet-node type represents that communication information between IP nodes belonging to respective subnet addresses is present.

6 . The method of claim 3 , wherein, in the gray zone, a preset number of IP nodes is represented, and an IP node in which a security attack is detected is preferentially represented.

7 . The method of claim 3 , wherein representing the node and the link using the different color includes displaying detailed information, including a type of the security attack, a subtype thereof, and port information, for the link in which the security attack is detected.

8 . The method of claim 3 , wherein representing the node and the link using the different color includes displaying detailed information about the security attack for neighboring nodes around the node in which the security attack is detected.

9 . The method of claim 5 , wherein information about the security attack is stored in a database structure including a time window, a type of the security attack, and an IP address.

10 . An apparatus for visualizing a medical device network and a security threat, comprising:

memory in which at least one program is recorded; and

a processor for executing the program,

wherein the program includes instructions for performing

representing nodes in zones that are divided into a server zone including nodes corresponding to server devices, a medical device zone including nodes corresponding to medical devices, a white zone including registered nodes excluding the server devices and the medical devices, and a gray zone including nodes included in none of the server zone, the medical device zone, and the white zone,

representing links between the nodes, and

representing a node and a link in which a security attack is detected using a different color when the security attack is detected in the node.

11 . The apparatus of claim 10 , wherein types of the nodes include an IP node corresponding to a terminal having an IP address, a subnet node corresponding to each subnet address, a gray node for connecting nodes corresponding to the gray zone, and a white node for connecting nodes corresponding to the white zone.

12 . The apparatus of claim 11 , wherein types of the links include an IP-node-to-subnet-node type, a subnet-node-to-subnet-node type, a gray-node-to-IP-node type, a white-node-to-IP-node type, a gray-node-to-subnet-node type, a white-node-to-subnet-node type, and an IP-node-to-IP-node type.

13 . The apparatus of claim 12 , wherein a link of the IP-node-to-IP-node type is generated when a security attack is detected.

14 . The apparatus of claim 12 , wherein:

a link of the IP-node-to-subnet-node type represents an IP node belonging to a subnet address corresponding to the subnet node, and

a link of the subnet-node-to-subnet-node type represents that communication information between IP nodes belonging to respective subnet addresses is present.

15 . The apparatus of claim 12 , wherein, in the gray zone, a preset number of IP nodes is represented, and an IP node in which a security attack is detected is preferentially represented.

16 . The apparatus of claim 12 , wherein representing the node and the link using the different color includes displaying detailed information, including a type of the security attack, a subtype thereof, and port information, for the link in which the security attack is detected.

17 . The apparatus of claim 12 , wherein representing the node and the link using the different color includes displaying detailed information about the security attack for neighboring nodes around the node in which the security attack is detected.

18 . The apparatus of claim 14 , wherein information about the security attack is stored in a database structure including a time window, a type of the security attack, and an IP address.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 17, 2023
From: KWON, HYEOK-CHAN; CHUNG, BYUNG-HO
To: ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE
Reel/Frame 065604/0380 →
Priority Claims (1)
KR 10-2022-0175015 · Dec 14, 2022 · national
Continuity (1)
Related Publication 20240205242A1 · Jun 20, 2024
References Cited (21)
US 7539147B2 · Chang et al. · 2009 [cited by applicant]
US 9130981B2 · Yi · 2015 [cited by applicant]
US 9871806B2 · Sohn et al. · 2018 [cited by applicant]
US 10374904B2 · Dubey · 2019 [cited by examiner]
US 20090129599A1 · Garcia · 2009 [cited by examiner]
US 20100125912A1 · Greenshpon et al. · 2010 [cited by applicant]
US 20170063905A1 · Muddu et al. · 2017 [cited by applicant]
US 20190098028A1 · Ektare · 2019 [cited by examiner]
US 20200241711A1 · Pandian · 2020 [cited by examiner]
US 20240323207A1 · Lee · 2024 [cited by examiner]
KR 100582555B1 · 2006 [cited by applicant]
KR 101160903B1 · 2012 [cited by applicant]
KR 20180007832A · 2018 [cited by applicant]
KR 101987031B1 · 2019 [cited by applicant]
KR 102057459B1 · 2020 [cited by applicant]
KR 1020210177523 · 2021 [cited by examiner]
KR 102408568B1 · 2022 [cited by applicant]
KR 102438067B1 · 2022 [cited by applicant]
Taylor, Curtis R., Krishna Venkatasubramanian, and Craig A. Shue. “Understanding the security of interoperable medical devices using attack graphs.” Proceedings of the 3rd international conference on High confidence net… [cited by examiner]
Shiravi, Hadi, Ali Shiravi, and Ali A. Ghorbani. “A survey of visualization systems for network security.” IEEE Transactions on visualization and computer graphics 18.8: 1313-1329. (Year: 2011). [cited by examiner]
Paulo Salvador et al., “DICOM Interception System for Independent Image Backup,” IEEE/IFIP Network, Operations and Management Symposium, May 5, 2014. [cited by applicant]