A method and system for real-time transmission of audit data through a bastion host
By setting up the historical session library, real-time session library and syslog service port in the basin engine, the operation and maintenance operation behavior is transmitted to the service layer in real time, and the problem of real-time synchronization of operation and maintenance operation records in the basin remote operation and maintenance system is solved, and timely alarms and multi-protocol compatibility for high-risk operations are achieved, with little performance impact.
Patent Information
- Application Number
- CN202211491320.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-25
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2042-11-25
AI Technical Summary
In the bastion machine remote operation and maintenance system, the operation and maintenance audit event is obtained only after the session is over, resulting in the operation and maintenance operation records that cannot be synchronized to the audit interface in real time, and the administrator cannot prevent risks in a timely manner.
By setting up the historical session library, real-time session library and syslog service port in the protocol agent of the bastion machine engine, the operation and maintenance operation behavior is recorded in real time, and data is passed to the service layer in real time through the syslog protocol, and encryption modules are added to ensure security.
It realizes real-time display of operation and maintenance operation behavior and timely alarms for high-risk operations, reduces the risk impact, is compatible with multiple protocols, and has a small performance impact.
Smart Images

Figure CN115883656B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of operation and maintenance auditing, and specifically, to a method and system for real-time transmission of audit data through a bastion host. Background Art
[0002] Currently, in some business scenarios where a bastion host is used to manage core assets, it is necessary to wait until the session ends before the command statement information and session video in the relevant database tables can be read out, then recorded in the business layer directory file, and then displayed and alerted to the management personnel on the front-end interface. This method will result in the inability to synchronize the operation and maintenance operation records of a large number of operation and maintenance personnel on the assets to the audit interface in real time, making it impossible for the administrator to prevent risks in a timely manner and take avoidance measures to reduce the risk impact.
[0003] Based on the above problems, in the current bastion host business scenario, there is an urgent need for a platform with the ability to display real-time data information interfaces and a function to connect to a third-party log platform for early warning, so that the administrator can perceive business risks in a timely manner.
[0004] Therefore, the present invention proposes a method that can transmit underlying data to the business layer directory to display real-time audit data, and the present invention has a wide range of applications and is compatible with audit data of command statements and videos such as ssh, linux, and database protocols. Summary of the Invention
[0005] The purpose of the present invention is to provide a method and system for real-time transmission of audit data through a bastion host, realizing the function of transmitting underlying data to the business layer directory to display real-time audit data, and having the effect of a wide range of applications.
[0006] The present invention is achieved by the following technical solutions: A method for real-time transmission of audit data through a bastion host includes the following steps:
[0007] Step S1, the client uses a remote connection tool to remotely access the bastion host;
[0008] Step S2, set a historical session library, a real-time session library, and a syslog service port in the protocol proxy of the bastion host engine. When the bastion host connects to the server, the session starts;
[0009] Step S3, when the session starts, the historical session library, the real-time session library, and the syslog service port record the operation and maintenance operation behaviors. The protocol proxy of the bastion host engine synchronizes the session start signal to the business layer, and the syslog service port transmits the operation and maintenance operation behaviors to the business layer in real time. The business layer generates a session file and transmits the audit data in real time until the session ends.
[0010] In this technical solution, the bastion host accesses the target server through the target server address, target server port, and engine protocol proxy input by the business personnel. Among the remote connection tools used by the client: when using the Rdp protocol, the remote connection tools include mstsc and microsoft remote desktop; when using the Ssh protocol, the remote connection tools include crt, putty, mobaxterm, and xshell; when using a database, the remote connection tools include navicat and dbeaver.
[0011] To better implement the present invention, further, the step S2 includes:
[0012] The bastion host uses the engine protocol proxy to record real-time operation and maintenance operation behaviors, and stores the operation and maintenance operation behaviors in the historical session library, real-time session library, and syslog service port.
[0013] To better implement the present invention, further, the step S2 includes:
[0014] The operation and maintenance operation behaviors include the behaviors of character commands, session recordings, image texts, and file upload and download logs.
[0015] To better implement the present invention, further, configure the syslog protocol in the syslog service port;
[0016] Send real-time data to the business layer and the audit platform according to the syslog protocol.
[0017] Add an encryption module outside the historical session library, real-time session library, and syslog service port.
[0018] In this technical solution, an asymmetric encryption algorithm can be used in the encryption module. The asymmetric encryption algorithm is a method for keeping keys secret. The asymmetric encryption algorithm requires two keys: a public key (abbreviated as publickey) and a private key (abbreviated as privatekey). The public key and the private key are a pair. If data is encrypted with the public key, only the corresponding private key can be used to decrypt it. Since different keys are used for encryption and decryption, this algorithm is called an asymmetric encryption algorithm. The basic process of implementing confidential information exchange using the asymmetric encryption algorithm is as follows: Party A generates a pair of keys and makes the public key public. Other parties (Party B) who need to send information to Party A use this key (Party A's public key) to encrypt the confidential information and then send it to Party A; Party A then decrypts the encrypted information with its own private key. When Party A wants to reply to Party B, it is just the opposite. Party A uses Party B's public key to encrypt the data. Similarly, Party B uses its own private key to decrypt it. On the other hand, Party A can sign the confidential information with its own private key and then send it to Party B; Party B then verifies the signature of the data sent back by Party A using Party A's public key. Party A can only decrypt any information encrypted with its public key using its private key. The asymmetric encryption algorithm has relatively good confidentiality, and it eliminates the need for end-users to exchange keys. Characteristics of the asymmetric cryptosystem: The algorithm strength is complex, and the security depends on the algorithm and the key. However, due to the complexity of its algorithm, the encryption and decryption speed is not as fast as that of symmetric encryption and decryption. In the symmetric cryptosystem, there is only one key, and it is not public. If decryption is required, the other party has to know the key. Therefore, ensuring its security is to ensure the security of the key. In the asymmetric key system, there are two keys, and one of them is public. In this way, it is not necessary to transmit the other party's key like in the symmetric cipher. In this way, the security is much greater.
[0019] Therefore, adding an encryption module outside the historical session library, real-time session library, and syslog service port will increase the security of this solution.
[0020] The step S3 further includes:
[0021] The character command includes the character command executed by the ssh protocol proxy;
[0022] The session video includes the session video generated by the RDP protocol proxy;
[0023] The image text includes the image text recognized by ocr;
[0024] The file upload and download log includes the event log of file upload and download and the statement text log executed by the database protocol.
[0025] The present invention also provides a system for real-time transmitting audit data through a bastion host, including a client and a bastion host, wherein:
[0026] A client for remotely accessing a bastion host using a remote connection tool;
[0027] A bastion host for setting up a historical session library, a real-time session library, and a syslog service port in the protocol proxy of the engine. When the bastion host connects to the server, the session starts;
[0028] When the session starts, the historical session library, the real-time session library, and the syslog service port record the operation and maintenance operation behaviors. The protocol proxy of the bastion host engine synchronizes the session start signal to the business layer. The syslog service port transmits the operation and maintenance operation behaviors to the business layer in real time. The business layer generates a session file and transmits the audit data in real time until the session ends.
[0029] Compared with the prior art, the present invention has the following advantages and beneficial effects:
[0030] (1) The present invention uses the method of adding a syslog service port to solve the problem of untimely transmission of session event log data;
[0031] (2) The present invention is compatible with most protocol operation and maintenance scenarios, such as ssh, rdp, databases, etc.;
[0032] (3) The syslog service port transmits the compressed and transcoded binary data in the intranet to the audit platform, and uses the ocr image recognition technology to identify and alarm high-risk operations;
[0033] (4) The present invention has little impact on performance occupancy. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] The present invention will be further described in conjunction with the following drawings and embodiments. All creative concepts of the present invention should be regarded as the disclosed content and the protection scope of the present invention.
[0035] Figure 1 It is a session flow chart provided by the present invention.
[0036] Figure 2 It is a schematic diagram of real-time transmission of audit data provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0037] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. It should be understood that the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments, and therefore should not be regarded as a limitation of the protection scope. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technical staff in the art without creative work belong to the protection scope of the present invention.
[0038] In the description of the present invention, it should be noted that unless otherwise clearly specified and defined, the terms "set", "connected", and "coupled" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can also be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two components. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.
[0039] Remote operation and maintenance system: The system here refers to the server, the bastion host, and the client.
[0040] Embodiment 1:
[0041] A method for real-time transmission of audit data through a bastion host in this embodiment. Currently, in some business scenarios where a bastion host is used to manage core assets, after the session ends, the command statement information and session video in the relevant database table can be read out, and then recorded in the business layer directory file, and displayed on the front-end interface and alerted to the management personnel. In this scenario, a large number of operation and maintenance operation records of the operation and maintenance personnel on the assets cannot be synchronized to the audit interface in real time, resulting in the administrator being unable to perceive risks in a timely manner and take measures to reduce the risk impact. Therefore, the ability to display real-time data information on the interface and connect to a third-party log platform for early warning is required, so that the administrator can perceive business risks in a timely manner.
[0042] In the research on real-time transmission of audit data, a common method is to use polling. The CPU periodically sends inquiries, reads the audit data in the database every few seconds, provides services if there is any, and then asks the next peripheral after the service ends, and then repeats continuously. In this way, relatively real-time data transmission and interface display at the business level are achieved. The disadvantage of this technology is that this method will have a great impact on the product performance. Reading the data in the underlying real-time database at the business level in a cycle of seconds. When the number of sessions is too large, this solution has high performance requirements and high costs, and may affect the response speed of the product.
[0043] In the prior art, the real-time session library serves to record and display, while the historical session library serves to store. Then, why is a syslog port added in the present invention? It is because when a session comes in, it is uncertain whether there is a risk. If there are high-risk operations during the operation and maintenance process by the operation and maintenance personnel, syslog can timely upload the real-time execution commands to the business front-end for display, alerting the administrator to take protective measures and reducing the impact on the business. For example, when the operation and maintenance personnel access the target asset through the bastion host, if a high-risk operation is triggered during the operation and maintenance process, such as a command like "rm -rf" to delete the database, the engine protocol proxy will timely transfer the audit data to syslog. The business program can read the data above in real time and display it on the front-end page. The business side can configure monitoring or interface with a third-party log platform for early warning. When there are audit records of high-risk commands such as "rm -rf" to delete the database or "reboot" to restart the server, the administrator will be alerted in a timely manner by means such as text messages and emails to take protective measures and reduce the impact on the business..
[0044] In the existing technologies, the engine protocol proxy blocks. However, the real-time session library only records the session for a few seconds. Suppose the session duration is 16 hours, and the real-time session library only records the latest 5s of the session. When the user views the session at the 12th hour, the session viewed is the last 5s of the 12th hour, and the sessions of the remaining 11 hours, 59 minutes, and 55 seconds are stored in the historical session library. That is to say, if there is a high-level risk, then this risk still has a delay. By adding a syslog port, we can view the data in real time at the business layer. In addition, it should be emphasized that when there is no business layer, the bastion host bottom layer engine can also directly read the business to read the data in the syslog port. The engine will not read it. Syslog is equivalent to a log source here. The data recorded by the engine protocol proxy will be transmitted here. It is equivalent that what the engine transmits is electric current, syslog is equivalent to a socket, and the business program is equivalent to a plug to obtain this electric current from syslog.
[0045] Embodiment 2:
[0046] This embodiment further optimizes on the basis of Embodiment 1. The main purpose of the present invention is to overcome the defect that the underlying audit data cannot be collected and transmitted to the interface for display in real time when the bastion host remote operation and maintenance system is used, and to provide a method for real-time transmitting the underlying audit data to the business layer of the bastion host for the user to view in real time or interface with a third-party audit platform based on the syslog protocol. The client remotely accesses the bastion host and accesses the target server through the bastion host underlying protocol proxy
[0047] The bastion host records relevant operation and maintenance operations, and the underlying engine models and analyzes them, performs standardization and filtering processing, and analyzes and records the operation behavior library. The recorded operation behavior library includes: character command records, session video records, image and text records, file upload and download records, etc.
[0048] Send the relevant record behavior library logs to the audit directory through the syslog protocol, supporting the sending of character records, such as character commands executed by the ssh protocol proxy, image text recognized by ocr, event logs of file upload and download, statement text logs executed by the database protocol, etc., to meet the needs of most compliance scenarios. Due to the limitations of the syslog protocol itself, it does not support sending videos and files, etc. For this part, a compression transcoding server can be configured on the server to transcode and compress the session video files in real time, and transfer them to the audit platform through syslog for decompression and output. Moreover, ocr image recognition rules can be configured to warn of high-risk operations of operation and maintenance personnel in the video, and to protect against security incidents.
[0049] After the audit directory receives the corresponding operation behavior logs, it will be displayed and warned in real time on the interface until the session ends.
[0050] The syslog protocol belongs to a master-slave protocol: the syslog sender will send out a small text message (less than 1024 octets) to the syslog receiver. The receiver is usually named "syslogd", "syslog daemon" or syslog server. System log messages can be sent using the UDP protocol and / or the TCP protocol. These data are sent in plain text type. However, since SSL encryption wrappers (such as Stunnel, sslio or sslwrap, etc.) are not part of the syslog protocol itself, they can be used to provide a layer of encryption through SSL / TLS. Syslog is often referred to as system log or system record, and is a standard for transmitting log messages on the Internet protocol (TCP / IP) network. This term is often used to refer to the actual syslog protocol, or those applications or databases that submit syslog messages.
[0051] The syslog protocol belongs to a master-slave protocol: the syslog sender will send out a small text message (less than 1024 octets) to the syslog receiver. The receiver is usually named "syslogd", "syslog daemon" or syslog server. System log messages can be sent using the UDP protocol and / or the TCP protocol. These data are sent in plain text type. However, since SSL encryption wrappers (such as Stunnel, sslio or sslwrap, etc.) are not part of the syslog protocol itself, they can be used to provide a layer of encryption through SSL / TLS.
[0052] Syslog is commonly used for information system management and information security auditing. Although it has many deficiencies, it still receives support from quite a number of devices and receivers on various platforms. Therefore, Syslog can be used to integrate log records from many different types of systems into a centralized repository.
[0053] Other parts of this embodiment are the same as those of Embodiment 1, so they will not be elaborated here.
[0054] Embodiment 3:
[0055] This embodiment is further optimized based on the above Embodiment 1 or 2. The business layer uses a polling method to obtain real-time data generated by the engine protocol proxy, which can also solve the problem of untimely transmission.
[0056] Other parts of this embodiment are the same as those of the above Embodiment 1 or 2, so they will not be elaborated here.
[0057] Embodiment 4:
[0058] This embodiment is further optimized based on any one of the above Embodiments 1-3. As Figure 2 shown, when the underlying protocol proxy session starts, the session start signal is synchronized to the bastion host business file directory to generate a session file record. For the engine protocol proxy session, the operation behaviors of the operation and maintenance personnel on the target server are recorded in real time and transmitted to the historical session library, real-time session library, and Syslog of the engine in real time. The Syslog protocol is configured to send relevant data to the business layer and the audit platform for consumption.
[0059] Other parts of this embodiment are the same as any one of the above Embodiments 1-3, so they will not be elaborated here.
[0060] Embodiment 5:
[0061] This embodiment is further optimized based on any one of the above Embodiments 1-4. In the current existing technologies, most of them are that after a session ends, the business layer goes to obtain the relevant session data recorded by the underlying engine.
[0062] This method may cause that when a security event occurs, the management personnel cannot be informed in the first time to make corresponding avoidance handling.
[0063] Using the Syslog method can transmit the character data recorded by the underlying engine to the business interface in real time, compress and transcode the video data and transmit it to the audit platform for output, and give early warnings about high-risk operations of the operation and maintenance personnel through ocr image recognition.
[0064] Avoid the risk that the security event of high-risk operations of the operation and maintenance personnel cannot be transmitted to the interface in time to alarm the administrator.
[0065] Compared with the method of polling for data, the main advantage of the present invention is that it has less impact on performance and does not affect the data records of the underlying real-time session database.
[0066] In the present invention, an encryption module can also be added. In the encryption module, an asymmetric encryption algorithm can be used. The asymmetric encryption algorithm is a method of keeping keys secret. The asymmetric encryption algorithm requires two keys: a public key (abbreviated as publickey) and a private key (abbreviated as privatekey). The public key and the private key are a pair. If data is encrypted with the public key, only the corresponding private key can be used to decrypt it. Since different keys are used for encryption and decryption, this algorithm is called an asymmetric encryption algorithm. The basic process of implementing confidential information exchange using the asymmetric encryption algorithm is as follows: Party A generates a pair of keys and makes the public key public. Other parties (Party B) who need to send information to Party A use this key (Party A's public key) to encrypt the confidential information and then send it to Party A; Party A then decrypts the encrypted information with its own private key. When Party A wants to reply to Party B, it is just the opposite. Party A uses Party B's public key to encrypt the data. Similarly, Party B uses its own private key to decrypt it. On the other hand, Party A can sign the confidential information with its own private key and then send it to Party B; Party B then verifies the signature of the data sent back by Party A with Party A's public key. Party A can only decrypt any information encrypted with its public key with its private key. The asymmetric encryption algorithm has good confidentiality and eliminates the need for end users to exchange keys. Characteristics of the asymmetric cryptosystem: The algorithm strength is complex, and the security depends on the algorithm and the key. However, due to the complexity of its algorithm, the encryption and decryption speed is not as fast as that of the symmetric encryption and decryption. In the symmetric cryptosystem, there is only one key, and it is not public. If decryption is required, the other party has to know the key. Therefore, ensuring its security is to ensure the security of the key. In the asymmetric key system, there are two keys, one of which is public, so there is no need to transmit the other party's key like in the symmetric cryptosystem. In this way, the security is much greater.
[0067] Other parts of this embodiment are the same as any one of the above-mentioned Embodiments 1-4, so they will not be elaborated here.
[0068] The above are only the preferred embodiments of the present invention, and do not impose any form of limitation on the present invention. Any simple modification or equivalent change made to the above embodiments based on the technical essence of the present invention falls within the protection scope of the present invention.
Claims
1. A method for real-time transmission of audit data through a bastion host, characterized in that, It includes the following steps: Step S1, the client remotely accesses the bastion host using a remote connection tool; Step S2, set the historical session library, real-time session library, and syslog service port in the protocol proxy of the bastion host engine. When the bastion host connects to the server, the session starts; Step S3, when the session starts, the historical session library, real-time session library, and syslog service port record the operation and maintenance operation behaviors. The protocol proxy of the bastion host engine synchronizes the session start signal to the business layer session directory. The syslog service port transmits the operation and maintenance operation behaviors to the business layer session directory in real time. A corresponding session file will be generated under the directory, and the audit data will be transmitted in real time until the session ends; The said Step S2 includes: The bastion host uses the engine protocol proxy to record the real-time operation and maintenance operation behaviors and stores the operation and maintenance operation behaviors in the historical session library, real-time session library, and syslog service port; The said operation and maintenance operation behaviors include the behaviors of character commands, session recordings, image texts, and file upload / download logs; Configure a compression transcoding server on the server to transcode and compress the session recording files in real time, transmit them to the audit platform through the syslog protocol for decompression and output, and configure ocr image recognition rules to warn of high-risk operations of operation and maintenance personnel in the video recording for security event protection.
2. The method for real-time transferring audit data through a bastion host according to claim 1, wherein It includes: Configure the syslog protocol in the said syslog service port; Send real-time data to the business layer and audit platform according to the syslog protocol.
3. A method for real-time transmission of audit data through a bastion host according to claim 1, characterized in that It includes: Add an encryption module outside the historical session library, real-time session library, and syslog service port.
4. A method for real-time transmitting audit data through a bastion host according to claim 3, characterized in that, It includes: The said character commands include the character commands executed by the ssh protocol proxy; The said session recordings include the session recordings generated by the RDP protocol proxy; The said image texts include the image texts recognized by ocr; The said file upload / download logs include the event logs of file upload / download and the statement text logs executed by the database protocol.
5. A system for real-time transmission of audit data through a bastion host, which is used to execute the method described in claim 1; characterized in that, It includes a client and a bastion host, where: The client is used to remotely access the bastion host using a remote connection tool; The bastion host is used to set the historical session library, real-time session library, and syslog service port in the protocol proxy of the engine. When the bastion host connects to the server, the session starts; When the session starts, the historical session library, real-time session library, and syslog service port record the operation and maintenance operation behaviors. The protocol proxy of the bastion host engine synchronizes the session start signal to the business layer. The syslog service port transmits the operation and maintenance operation behaviors to the business layer in real time. The business layer generates a session file and transmits the audit data in real time until the session ends.
Citation Information
Patent Citations
Remote access reinforced and centralized monitoring system of scheduling data network
CN108366090A
Big data activity project log analysis and resource allocation method
CN114297159A
Cited By
Method and system for carrying out operation and maintenance auditing on network isolation assets, equipment and medium
CN121367615A