A bastion host security protection system based on intelligent risk identification
Through the fortress safety protection system for intelligent risk identification, the fortress logs are retrieved and cleaned in real time, the log variation characteristic values are analyzed, and the trend chart is created, which solves the problems of waste of hardware resources and high management costs of fortress machines, and predictive failures and risk monitoring is achieved, which improves the operational safety and stability of fortress machines.
Patent Information
- Application Number
- CN202411653049.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-19
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2044-11-19
AI Technical Summary
The existing bastion machine system has wasted hardware resources, high management costs, poor scalability, and lacks operational safety foresight, so it is impossible to accurately predict faults and risks.
The fortress machine safety protection system based on intelligent risk identification is adopted. The fortress machine operation log is retrieved and cleaned in real time through the storage module, the detection module analyzes the log variation characteristic values, creates a trend chart and determines the operation safety, and feedbacks the output results of the module.
It realizes effective foresight failure and risk monitoring of the fortress machine, improves operational safety and stability, and reduces management costs.
Smart Images

Figure CN119520098B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of bastion hosts, and particularly relates to a bastion host security protection system based on intelligent risk recognition. Background Art
[0002] A bastion host is a network security device. In a specific network environment, it monitors and records the operation behaviors of operation and maintenance personnel on servers, network devices, etc. through various technical means. It can prevent the intrusion and damage of internal and external network users, and has functions such as identity authentication, permission management, and operation auditing. It can effectively guarantee network and data security and is an important part of an enterprise's security system.
[0003] A patent for invention with the application number 202210790944.8 discloses a bastion host access method based on a multi-local area network environment, which is characterized by including the following steps: Step S1, set a proxy gateway and the corresponding IP address for each local area network, set a single bastion host for the multi-local area network environment, and all proxy gateways are simultaneously connected to the bastion host; Step S2, set up a database under the IP address of each proxy gateway in the bastion host, and partition the database. Each partition corresponds to a host IP in the current local area network, and the partition stores the associated information of the access users of the current host IP; Step S3, after the user logs in to the bastion host system through the client, the bastion host system directly calls the associated information in the database according to the user's login information to generate request data. The request data at least includes the associated information of the access user, the proxy gateway IP, and the target host IP, and sends the request data to the corresponding proxy gateway according to the proxy gateway IP; Step S4, the proxy gateway modifies the target IP in the transport layer TCP data packet header to the target host IP and modifies the source IP to the proxy gateway IP according to the received request data. At this time, a direct connection is established between the user's client and the target host through the connection of the bastion host and the proxy gateway, and the user realizes the access to the target host.
[0004] This application aims to solve the problems of: "Since a bastion host system needs to be deployed in each network, a large number of bastion host systems need to be deployed. First, it wastes hardware resources and increases hardware costs. Each set of bastion host systems needs to be specially deployed on a single host; second, it increases management costs. Users need to manage and maintain a large number of bastion host systems at the same time. Especially when the bastion host system needs to be upgraded, each bastion host needs to be upgraded one by one, which takes a lot of time and manpower; third, the scalability is poor. Every time a new network is added, a new set of bastion host systems needs to be deployed again. Also, if there are vulnerabilities in the bastion host system itself, each bastion host needs to be repaired one by one separately."
[0005] However, for the daily operation security protection of the bastion host, most of them judge faults and risk problems in a real-time detection manner. Its defect is that the predictability of the operation security of the bastion host is poor, and it is impossible to accurately predict in advance the possible faults and risk problems that the bastion host will occur.
[0006] Therefore, a bastion host security protection system based on intelligent risk identification is proposed. Summary of the Invention
[0007] In view of the above-mentioned shortcomings of the prior art, the present invention provides a bastion host security protection system based on intelligent risk identification, which solves the technical problems proposed in the above background technology.
[0008] To achieve the above objectives, the present invention is realized through the following technical solutions:
[0009] A bastion host security protection system based on intelligent risk identification, comprising:
[0010] A storage module for real-time retrieving the operation logs of the bastion host and storing the operation logs of the bastion host; a retrieval module for retrieving the operation logs of the bastion host in the storage module and forwarding the retrieved operation logs of the bastion host to the detection module; a detection module for obtaining the operation logs of the bastion host fed back by the retrieval module and detecting the abnormal change characteristic values of the operation state of the bastion host based on the operation logs of the bastion host; a visualization module for continuously receiving the abnormal change characteristic values of the operation state of the bastion host detected in the monitoring module and creating a change trend graph of the abnormal change characteristic values of the operation state of the bastion host based on the abnormal change characteristic values of the operation state of the bastion host; a determination module for traversing the change trend graph and determining whether the operation of the bastion host is safe based on the change trend graph; a feedback module for receiving the determination result of whether the operation of the bastion host is safe in the determination module, outputting the determination result when the determination result is yes, and synchronously outputting the determination result and the change trend graph when the determination result is no.
[0011] When the line representing the abnormal change characteristic value of the operation state of the bastion host in the change trend graph rises continuously three times, the determination module determines that the operation of the bastion host is unsafe; otherwise, it is determined that the operation of the bastion host is safe. The feedback target of the feedback module is any mobile computer device with a graph display function held by the system end user.
[0012] Furthermore, the content of the operation logs of the bastion host retrieved in the storage module includes: user login information, user operation information, system operation status information, security event information, and system configuration change information. When the storage module stores the operation logs of the bastion host, it stores them separately based on the content type of the operation logs of the bastion host, so that the operation logs of each type of the bastion host are stored in the same separate storage area.
[0013] Furthermore, sub-modules are provided inside the storage module, including:
[0014] A cleaning unit for traversing the running logs of the bastion host stored in each differentiated storage area of the storage module and performing data cleaning on the running logs of the bastion host;
[0015] Data cleaning logic is set in the cleaning unit, and the cleaning unit cleans the running logs of the bastion host based on the cleaning logic, and the cleaning logic is expressed as:
[0016]
[0017] In the formula: is the i-th log after cleaning; is the m-th attribute value of the i-th log after cleaning; is the j-th attribute value of the i-th log after cleaning; n is the total number of logs; a kj is the j-th attribute value of the k-th log in the original log; ΙΙ(·) is the indicator function;
[0018] Among them, each running log of the bastion host is cleaned based on the above formula to output the running log of the bastion host after cleaning.
[0019] Furthermore, the indicator function ΙΙ(·) follows that when the arithmetic expression in the parentheses is true, then ΙΙ(·)=1, otherwise, ΙΙ(·)=0, and if the arithmetic expression in the parentheses holds, it is determined to be true;
[0020] The outlier is the judgment of the outlier value, and null is the null value;
[0021]
[0022] In the formula: μ j is the mean of the j-th attribute; σ j is the standard deviation of the j-th attribute;
[0023] Among them, if |a ij -μ j >3σ j , then a ij =outlier, otherwise, a kj ≠outlier.
[0024] Furthermore, sub-modules are provided inside the retrieval module, including:
[0025] A logic unit for setting the number and location of the running logs of the bastion host retrieved during the running stage of the retrieval module;
[0026] When the storage module stores the running logs of the bastion host, it stores the running logs of the bastion host in sequence based on time series. When the logic unit sets the retrieval quantity and position of the running logs of the bastion host, it follows that: the retrieved running logs of the bastion host are always the latest running logs of the bastion host in the front position, the number of retrieved running logs of the bastion host is not less than two groups, and the higher the current usage frequency of the bastion host, the more the number of retrieved running logs of the bastion host. Conversely, the fewer the number of retrieved running logs of the bastion host.
[0027] Furthermore, a sub-module is set under the detection module, including:
[0028] A receiving unit, configured to receive the running logs of the bastion host forwarded by the retrieval module to the detection module, distinguish the running logs of the bastion host based on the content type of the running logs of the bastion host, so as to obtain a set of running logs of the bastion host, and send the set of running logs of the bastion host to the detection module;
[0029] A recording unit, configured to receive the abnormal change characteristic value of the running state of the bastion host detected by the operation of the detection module, mark and record the abnormal change characteristic value of the running state of the bastion host by applying the corresponding content type of the abnormal change characteristic value of the running state of the bastion host from the set of running logs of the bastion host;
[0030] Wherein, the content types of the running logs of the bastion host are user login information, user operation information, system running state information, security event information, and system configuration change information. Each set of running logs of the bastion host only contains the running logs of the bastion host of one content type.
[0031] Furthermore, the abnormal characteristic value of the running state of the bastion host is expressed as:
[0032]
[0033] In the formula: K is the abnormal characteristic value of the running state of the bastion host; u is the total amount of the content types of the running logs of the bastion host; k v is the abnormal characteristic value of the running state of the bastion host represented by the content performance of the running logs of the v-th type of the bastion host; ω v is the weight;
[0034] Wherein, the weight ω v is user-defined by the system-side user and follows The larger the abnormal characteristic value K of the running state of the bastion host, the higher the running risk of the bastion host.
[0035] Furthermore, the abnormal characteristic value k of the running state of the bastion host represented by the content performance of the running logs of the v-th type v is obtained by the following formula, and the formula is:
[0036]
[0037] Where: x is the total amount of the running logs of the bastion host in the running log set of the v - type bastion host; sim(y, y + 1) is the similarity between the running logs of the y - th group of bastion hosts and the running logs of the (y + 1) - th group of bastion hosts; a y,i , b y+1,i are the i - th attribute values in the running logs of the y - th group of bastion hosts and the running logs of the (y + 1) - th group of bastion hosts; max(y i ), min(y i ) are the maximum and minimum attribute values in the running logs of the y - th group of bastion hosts; max((y + 1) i ), min((y + 1) i ) are the maximum and minimum attribute values in the running logs of the (y + 1) - th group of bastion hosts;
[0038] Among them, represents taking the average of .
[0039] Furthermore, when the information corresponding to the i - th attribute value is character - type information:
[0040]
[0041] Furthermore, the storage module is internally interconnected with a cleaning unit through a local area network. The storage module is interconnected with a retrieval module through a local area network. The retrieval module is internally interconnected with a logic unit through a local area network. The retrieval module is interconnected with a detection module through a local area network. The lower - level of the detection module is interconnected with a receiving unit and a recording unit through a local area network. The receiving unit is interconnected with the logic unit through a local area network. The detection module is interconnected with a visualization module, a determination module, and a feedback module through a local area network.
[0042] Adopting the technical solution provided by the present invention, compared with the known public technologies, it has the following beneficial effects:
[0043] The present invention provides a bastion host security protection system based on intelligent risk identification. During the operation of the system, by obtaining the historical running logs of the bastion host, data cleaning is performed on the historical running logs of the bastion host to obtain high - value reference logs. Further, based on the comprehensive analysis of the cleaned historical running logs of the bastion host, digital detection is performed on the abnormal change of the running state of the bastion host. Finally, a trend chart is created based on the monitoring results, and according to the trend of the trend chart, the security of the current running state of the bastion host is determined, bringing an effective and relatively accurate predictive failure and risk monitoring and protection effect to the bastion host. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] To more clearly illustrate the technical solutions in the embodiments of the present invention or in the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0045] Figure 1 It is a schematic structural diagram of a bastion host security protection system based on intelligent risk identification. Specific embodiments
[0046] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0047] The following further describes the present invention in combination with embodiments.
[0048] Embodiment 1:
[0049] A bastion host security protection system based on intelligent risk identification in this embodiment, as Figure 1 shown, includes:
[0050] A storage module for retrieving the running logs of the bastion host in real time and storing the running logs of the bastion host;
[0051] Sub-modules are provided inside the storage module, including:
[0052] A cleaning unit for traversing the running logs of the bastion host stored in each storage interval in the storage module and performing data cleaning on the running logs of the bastion host;
[0053] A data cleaning logic is set in the cleaning unit, and the cleaning unit cleans the running logs of the bastion host based on the cleaning logic. The cleaning logic is expressed as:
[0054]
[0055] In the formula: is the i-th log after cleaning; is the m-th attribute value of the i-th log after cleaning; is the j-th attribute value of the i-th log after cleaning; n is the total number of logs; a kj is the j-th attribute value of the k-th log in the original log; ΙΙ(·) is the indicator function;
[0056] Among them, each bastion host operation log is cleaned based on the above formula to output the cleaned bastion host operation log;
[0057] It is indicated that the indicator function ΙΙ(·) follows that when the arithmetic expression in the parentheses is true, ΙΙ(·) = 1; otherwise, ΙΙ(·) = 0. When the arithmetic expression in the parentheses holds, it is determined to be true;
[0058] outlier is the judgment of outliers, and null is the null value;
[0059]
[0060] In the formula: μ j is the mean of the j-th attribute; σ j is the standard deviation of the j-th attribute;
[0061] Among them, if |a ij - μ j > 3σ j , then a ij = outlier; otherwise, a kj ≠ outlier;
[0062] The retrieval module is used to retrieve the bastion host operation log from the storage module and forward the retrieved bastion host operation log to the detection module;
[0063] The retrieval module is internally provided with sub-modules, including:
[0064] The logic unit is used to set the number and location of the bastion host operation logs retrieved during the operation stage of the retrieval module;
[0065] Among them, when the storage module stores the bastion host operation log, the bastion host operation log is stored in sequence based on the time sequence. When the logic unit sets the retrieved number and location of the bastion host operation log, it follows that: the retrieved bastion host operation log is always the latest bastion host operation log in the front position, the number of retrieved bastion host operation logs is not less than two groups, and the higher the current usage frequency of the bastion host, the more the number of retrieved bastion host operation logs; otherwise, the fewer the number of retrieved bastion host operation logs;
[0066] The detection module is used to obtain the bastion host operation log fed back by the retrieval module and detect the abnormal change characteristic value of the bastion host operation status based on the bastion host operation log;
[0067] The detection module is provided with sub-modules at the lower level, including:
[0068] A receiving unit, configured to receive the FortiGate operation logs forwarded by the retrieval module to the detection module, distinguish the FortiGate operation logs based on the content type of the FortiGate operation logs, so as to obtain a set of FortiGate operation logs, and send the set of FortiGate operation logs to the detection module;
[0069] A recording unit, configured to receive the abnormal change characteristic values of the FortiGate operation status detected by the detection module during operation, mark and record the abnormal change characteristic values of the FortiGate operation status by applying the corresponding content type of the abnormal change characteristic values of the FortiGate operation status from the set of FortiGate operation logs;
[0070] Wherein, the content types of the FortiGate operation logs are user login information, user operation information, system operation status information, security event information, and system configuration change information, and each set of FortiGate operation logs only contains FortiGate operation logs of one content type;
[0071] The abnormal characteristic value of the FortiGate operation status is expressed as:
[0072]
[0073] In the formula: K is the abnormal characteristic value of the FortiGate operation status; u is the total amount of the content types of the FortiGate operation logs; k v is the abnormal characteristic value of the FortiGate operation status represented by the content performance of the FortiGate operation logs of the v-th type; ω v is the weight;
[0074] Wherein, the weight ω v is user-defined by the system end user and obeys The larger the abnormal characteristic value K of the FortiGate operation status, the higher the operation risk of the FortiGate;
[0075] The abnormal characteristic value k of the FortiGate operation status represented by the content of the FortiGate operation logs of the v-th type v is obtained by the following formula:
[0076]
[0077] In the formula: x is the total amount of the FortiGate operation logs in the set of FortiGate operation logs of the v-th type; sim(y, y + 1) is the similarity between the y-th group of FortiGate operation logs and the (y + 1)-th group of FortiGate operation logs; a y,i and b y+1,i are the i-th attribute values in the y-th group of FortiGate operation logs and the (y + 1)-th group of FortiGate operation logs; max(y i ) and min(y i ) are the maximum attribute value and the minimum attribute value in the y-th group of FortiGate operation logs; max((y + 1) i ) and min((y + 1) i) are the maximum and minimum attribute values in the y+1th group of bastion host operation logs;
[0078] in, Express ;
[0079] When the information corresponding to the i-th attribute value is character information:
[0080]
[0081] A visualization module is used to continuously receive the abnormal characteristic values of the bastion host operation status detected in the monitoring module, and create a change trend chart of the abnormal characteristic values of the bastion host operation status based on the abnormal characteristic values of the bastion host operation status;
[0082] A determination module is used to traverse the change trend graph and determine whether the bastion host is running safely based on the change trend graph;
[0083] The feedback module is used to receive the judgment result of whether the bastion host is running safely in the judgment module, and output the judgment result when the judgment result is yes, and output the judgment result together with the change trend graph when the judgment result is no;
[0084] When the line representing the abnormal characteristic value of the bastion host's operating status in the change trend graph rises three times in a row, the judgment module determines that the bastion host is operating unsafely, otherwise, it is determined that the bastion host is operating safely. The feedback target of the feedback module is any mobile computer device with a graphic display function held by the system end user;
[0085] The storage module is interactively connected to a cleaning unit through a local area network, the storage module is interactively connected to a retrieval module through a local area network, the retrieval module is interactively connected to a logic unit through a local area network, the retrieval module is interactively connected to a detection module through a local area network, the detection module is interactively connected to a receiving unit and a recording unit through a local area network, the receiving unit is interactively connected to the logic unit through the local area network, and the detection module is interactively connected to a visualization module, a judgment module and a feedback module through the local area network.
[0086] In this embodiment, the storage module runs to retrieve the operation logs of the bastion host in real time, stores the operation logs of the bastion host, the cleaning unit synchronously traverses the operation logs of the bastion host stored in each storage area in the storage module, cleans the data of the operation logs of the bastion host, the retrieval module runs later to retrieve the operation logs of the bastion host in the storage module, forwards the retrieved operation logs of the bastion host to the detection module, the logic unit synchronously sets the number and location of the operation logs of the bastion host retrieved during the operation stage of the retrieval module, and then the detection module obtains the operation logs of the bastion host fed back by the retrieval module, detects the abnormal change characteristic values of the operation state of the bastion host based on the operation logs of the bastion host, the receiving unit synchronously receives the operation logs of the bastion host forwarded by the retrieval module to the detection module, differentiates the operation logs of the bastion host based on the content type of the operation logs of the bastion host to obtain a set of operation logs of the bastion host, and sends the set of operation logs of the bastion host to the detection module, the recording unit receives in real time the abnormal change characteristic values of the operation state of the bastion host detected by the detection module during operation, marks and records the abnormal change characteristic values of the operation state of the bastion host by applying the corresponding content type of the set of operation logs of the bastion host from which the abnormal change characteristic values of the operation state of the bastion host are derived;
[0087] Then, the visualization module continuously receives the abnormal change characteristic values of the operation state of the bastion host detected in the monitoring module, creates a change trend graph of the abnormal change characteristic values of the operation state of the bastion host based on the abnormal change characteristic values of the operation state of the bastion host, the determination module further traverses the change trend graph, determines whether the operation of the bastion host is safe based on the change trend graph, and finally the feedback module receives the determination result of whether the operation of the bastion host in the determination module is safe. When the determination result is yes, the determination result is output. When the determination result is no, the determination result and the change trend graph are synchronously output;
[0088] Based on the above system operation, it brings effective predictive fault and security risk monitoring and protection effects to the bastion host, ensuring the long-term stable operation of the bastion host;
[0089] On the other hand, during the system operation, the operation logs of the bastion host are cleaned through a limited data cleaning logic formula to ensure that effective and valuable operation logs of the bastion host are screened for subsequent security detection of the bastion host, and the security of the operation state of the bastion host is determined by calculating the digital abnormal change characteristic values of the operation state of the bastion host, effectively improving the readability and convenience of the security monitoring process of the operation state of the bastion host.
[0090] Embodiment 2:
[0091] At the specific implementation level, on the basis of Embodiment 1, this embodiment further specifically describes a bastion host security protection system based on intelligent risk recognition in Embodiment 1 with reference to Figure 1 as shown:
[0092] The content of the bastion host operation logs retrieved from the storage module includes: user login information, user operation information, system operation status information, security event information, and system configuration change information. When the storage module stores the bastion host operation logs, it stores them separately based on the content type of the bastion host operation logs, so that each type of bastion host operation log content is stored in the same separate storage interval.
[0093] Through the above settings, the specific content types of the bastion host operation logs are further defined, and the storage logic of the storage module for the bastion host operation logs is defined, providing the necessary operation data support for the subsequent model operation in the system of Embodiment 1.
[0094] In summary, during the operation of the system in the above embodiments, by obtaining the historical operation logs of the bastion host, cleaning the data of the bastion host historical operation logs to obtain high-value reference logs, further comprehensively analyzing according to the cleaned bastion host historical operation logs, digitally detecting the abnormal changes in the operation status of the bastion host, finally creating a trend chart based on the monitoring results, and identifying according to the trend of the trend chart to determine the security of the current operation status of the bastion host, which brings effective and relatively accurate predictive fault and risk monitoring and protection effects to the bastion host.
[0095] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements will not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A bastion host security protection system based on intelligent risk identification, characterized in that, Including: A storage module, configured to retrieve the running logs of the bastion host in real time and store the running logs of the bastion host. A retrieval module, configured to retrieve the running logs of the bastion host from the storage module and forward the retrieved running logs of the bastion host to the detection module. A detection module, configured to obtain the running logs of the bastion host fed back by the retrieval module and detect the characteristic values of the abnormal change in the running state of the bastion host based on the running logs of the bastion host. A visualization module, configured to continuously receive the characteristic values of the abnormal change in the running state of the bastion host detected in the monitoring module and create a change trend graph of the characteristic values of the abnormal change in the running state of the bastion host based on the characteristic values of the abnormal change in the running state of the bastion host. A determination module, configured to traverse the change trend graph and determine whether the bastion host is running safely based on the change trend graph. A feedback module, configured to receive the determination result of whether the bastion host is running safely in the determination module, output the determination result when the determination result is yes, and synchronously output the determination result and the change trend graph when the determination result is no. Among them, when the line representing the characteristic value of the abnormal change in the running state of the bastion host in the change trend graph rises continuously three times, the determination module determines that the bastion host is running unsafely; otherwise, it determines that the bastion host is running safely. The feedback target of the feedback module is any mobile computer device with a graph display function held by the system-end user. The content of the running logs of the bastion host retrieved by the storage module includes: user login information, user operation information, system running state information, security event information, and system configuration change information. When the storage module stores the running logs of the bastion host, it stores them separately based on the content type of the running logs of the bastion host, so that each type of content of the running logs of the bastion host is stored in the same separate storage interval. There are sub-modules inside the storage module, including: A cleaning unit, configured to traverse the running logs of the bastion host stored in each separate storage interval in the storage module and perform data cleaning on the running logs of the bastion host. There is a data cleaning logic set in the cleaning unit. The cleaning unit cleans the running logs of the bastion host based on the cleaning logic, and the cleaning logic is expressed as: Wherein: is the i-th log after cleaning; is the m-th attribute value of the i-th log after cleaning; is the j-th attribute value of the i-th log after cleaning; n is the total number of logs; a kj is the j-th attribute value of the k-th log in the original log; ΙΙ(·) is the indicator function; Among them, each running log of the bastion host is cleaned according to the above formula to output the running logs of the bastion host after cleaning.
2. The security protection system of a bastion host based on intelligent risk identification according to claim 1, wherein The indicator function ΙΙ(·) obeys that when the arithmetic expression in the parentheses is true, ΙΙ(·)=1; otherwise, ΙΙ(·)=0. When the arithmetic expression in the parentheses holds, it is determined to be true. The outlier is the judgment of abnormal values, and null is the null value. where: μ j is the mean of the j-th attribute; σ j is the standard deviation of the j-th attribute; where, |a ij - μ j | > 3σ j , then a ij = outlier, otherwise, a kj ≠ outlier.
3. The security protection system of a bastion host based on intelligent risk recognition according to claim 1, wherein There are sub-modules inside the retrieval module, including: A logic unit, configured to set the number and position of the running logs of the bastion host retrieved during the running stage of the retrieval module. Among them, when the storage module stores the running logs of the bastion host, it stores the running logs of the bastion host in sequence based on time series. When the logic unit sets the number and position of the running logs of the bastion host retrieved, it obeys that the retrieved running logs of the bastion host are always the latest running logs of the previous position, the number of retrieved running logs of the bastion host is not less than two groups, and the higher the current usage frequency of the bastion host, the more the number of retrieved running logs of the bastion host; otherwise, the fewer the number of retrieved running logs of the bastion host.
4. A bastion host security protection system based on intelligent risk identification according to claim 1, characterized in that, There are sub-modules under the detection module, including: A receiving unit, used for receiving the bastion machine operation log forwarded by the calling module to the detection module, distinguishing the bastion machine operation log based on the content type of the bastion machine operation log to obtain the bastion machine operation log set, and sending the bastion machine operation log set to the detection module; A recording unit is used to receive the abnormal characteristic value of the bastion host operation state detected by the detection module, mark the abnormal characteristic value of the bastion host operation state by using the corresponding content type of the bastion host operation log set from which the abnormal characteristic value of the bastion host operation state is derived, and record it; Among them, the content types of the bastion host operation log are user login information, user operation information, system operation status information, security event information, and system configuration change information. Each set of bastion host operation log sets only contains bastion host operation logs of one content type.
5. The bastion host security protection system based on intelligent risk recognition according to claim 4, characterized in that, The abnormal characteristic value of the bastion host operation status is expressed as: Where: K is the abnormal characteristic value of the bastion host's operating status; u is the total amount of content types of the running logs of the bastion host; k v is the abnormal feature value of the running state of the bastion host represented by the running logs of the v-th type of bastion host; ω v is the weight; Among them, the weight ω v is user-defined by the system-side user and follows The larger the abnormal eigenvalue K of the bastion host running state is, the higher the running risk of the bastion host is.
6. The security protection system of a bastion host based on intelligent risk recognition according to claim 5, characterized in that, The abnormal eigenvalue k of the running state of the bastion host manifested by the running log content of the v-type bastion host v is obtained by the following formula: Where: x is the total amount of the running logs of the bastion host of the vth type in the running log set of the bastion host; sim(y, y + 1) is the similarity between the running logs of the yth group of bastion hosts and the running logs of the (y + 1)th group of bastion hosts; a y,i , b y+1,i are the ith attribute values in the running logs of the yth group of bastion hosts and the running logs of the (y + 1)th group of bastion hosts; max(y i ), min(y i ) are the maximum attribute value and the minimum attribute value in the running logs of the yth group of bastion hosts; max((y + 1) i ), min((y + 1) i ) are the maximum attribute value and the minimum attribute value in the running logs of the (y + 1)th group of bastion hosts; Among them, represents the averaging of .
7. The bastion host security protection system based on intelligent risk recognition according to claim 6, characterized in that, When the information corresponding to the i-th attribute value is character information:
8. The security protection system of a bastion host based on intelligent risk identification according to claim 1, characterized in that, The storage module is interactively connected to a cleaning unit via a local area network, the storage module is interactively connected to a retrieval module via a local area network, the retrieval module is interactively connected to a logic unit via a local area network, the retrieval module is interactively connected to a detection module via a local area network, the detection module is interactively connected to a receiving unit and a recording unit at a lower level via a local area network, the receiving unit is interactively connected to the logic unit via a local area network, and the detection module is interactively connected to a visualization module, a determination module and a feedback module via a local area network.
Citation Information
Patent Citations
A bastion host system and bastion host access method based on a multi-LAN environment
CN115296848B
Bastion host operation and maintenance management system
CN117874680A