A bank virtual desktop remote access control method and system based on firewall
By dividing business content and analyzing security information on the bank virtual desktop, determining the security level of the business window and configuring firewall instances, combined with dynamic monitoring strategies, the problem of fixed firewall configuration in the existing technology is solved, and the security and adaptability of remote access control of bank virtual desktops is improved.
Patent Information
- Application Number
- CN202510221495.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-27
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2045-02-27
AI Technical Summary
In the prior art, the problem of the configuration of firewall instances and the fixed remote security monitoring policy have resulted in poor security and low adaptability of remote access control of bank virtual desktops, and the stability and security of the remote cannot be guaranteed.
By obtaining banking business content, dividing the virtual desktop, analyzing the security information of the virtual desktop in each business window to determine its security level, and configuring firewall instances based on the security level. During remote access, the firewall instance monitors and controls content, defines access scenarios, and sets dynamic monitoring policies.
Improve the security and adaptability of remote access control of bank virtual desktops, and ensure the stability and security of remote access by targeted configuration of firewall instances and dynamic monitoring policies.
Smart Images

Figure CN119728303B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of firewall security monitoring, and in particular to a firewall-based bank virtual desktop remote access control method and system. Background Art
[0002] With the digital transformation of banking business, virtual desktop technology has been widely used in remote office scenarios due to its convenience, flexibility and security. However, remote access to virtual desktops also brings many security risks, such as unauthorized access and data leakage. In order to ensure the secure access to bank virtual desktops, firewall technology is particularly important. As the first line of defense for network security, firewalls can effectively monitor and control the data flow in and out of the network by formulating and implementing security policies, preventing potential malicious attacks and illegal access.
[0003] In the prior art, the configuration of firewall instances and remote security monitoring strategies are often fixed, without considering the interaction between virtual desktops of multiple business windows, resulting in poor security and low adaptability of remote access control of bank virtual desktops, and failure to guarantee remote stability and security.
[0004] Therefore, how to improve the security and adaptability of remote access control of bank virtual desktops is a technical problem that needs to be solved. Summary of the invention
[0005] The purpose of the present invention is to solve the problems of poor security and low adaptability of bank virtual desktop remote access control in the prior art due to failure to consider the interaction between virtual desktops of multiple business windows, and to propose a firewall-based bank virtual desktop remote access control method, which includes:
[0006] Obtain banking business content, divide the bank virtual desktop according to the banking business content, and obtain virtual desktops of different business windows;
[0007] Analyze the security information of the virtual desktop of each service window to determine the security level of the virtual desktop of each service window, and configure the firewall instance based on the security level of the virtual desktop of the service window;
[0008] After receiving the remote access request from the bank staff, the firewall instance checks the remote access request. If the request passes the check, the firewall instance releases the remote access request to the virtual desktop.
[0009] During the remote access process of the virtual desktop of the business window, the firewall instance monitors the control content of the remote access, defines the access scenario of the virtual desktop of the business window, and sets a dynamic monitoring strategy according to the control content and the access scenario.
[0010] In some embodiments of the present application, the bank virtual desktop is divided according to the banking business content to obtain virtual desktops of different business windows, including:
[0011] Split the banking business content into multiple business types, determine the interactive content between business types, and build an interactive relationship diagram between all business types;
[0012] The interaction relationship diagram is split according to the business type to form a plurality of specific interaction relationship diagrams, and each business type and the specific interaction relationship diagram corresponding to the business type are used as the virtual desktop of the business window.
[0013] In some embodiments of the present application, the security information of the virtual desktop of each service window is analyzed to determine the security level of the virtual desktop of each service window, including:
[0014] Security information includes data categories, historical security records, data information assets, and interactions with business windows;
[0015] Conduct a multi-dimensional sensitivity assessment of all data categories involved in the virtual desktop of the business window to determine the sensitivity of all data categories in the virtual desktop of each business window;
[0016] Evaluate the value of the data and information assets involved in the virtual desktop of the business window to determine the value of the data and information assets;
[0017] The historical security records record the security incidents and incident handling situations that have occurred in the business window in the past, match the security incidents and incident handling situations, and determine the risk factor of the business window based on the security incidents and the corresponding incident handling situations;
[0018] Calculate the interaction index of each business window based on the interaction status of the business window and the specific interaction relationship diagram;
[0019] The security level of the virtual desktop of the business window is determined by the sensitivity of all data categories, the value of data information assets, the risk factor of the business window and the interaction index of the business window.
[0020] In some embodiments of the present application, the interaction index of each service window is calculated according to the interaction status of the service window and the specific interaction relationship diagram, including:
[0021] The nodes corresponding to each business window and the data flow frequency, dependency strength and isolation level between the nodes are marked on the specific interaction relationship diagram according to the interaction of the business windows. The length and weight of the edges between the nodes on the specific interaction relationship diagram are defined according to the data flow frequency, dependency strength and isolation level.
[0022] The degree centrality, closeness centrality and betweenness centrality of each node on the specific interaction relationship graph are calculated through graph theory algorithms, and the degree centrality, closeness centrality and betweenness centrality are normalized. The interaction index of each business window is calculated by integrating degree centrality, closeness centrality and betweenness centrality.
[0023] in, For the The interaction index of a business window, Respectively The interaction weights of degree centrality, closeness centrality and betweenness centrality of each business window, Respectively The degree centrality, closeness centrality and betweenness centrality of each business window, express The maximum value in For the The first constant corresponding to a business window.
[0024] In some embodiments of the present application, the security level of the virtual desktop of the business window is determined by the sensitivity of all data categories, the value of data information assets, the risk coefficient of the business window and the interaction index of the business window, including: in, For the The security level of the virtual desktop of each business window, For the The risk factor of each business window, Respectively The sensitivity of the data category of each business window and the value of the data information asset are combined with their respective weights. Respectively The sensitivity of the data categories of each business window and the value of data information assets, For the The adjustment coefficient of a business window, represents the adjustment coefficient obtained by the interactive index mapping, For the The second constant corresponding to the service window, [] is the rounding symbol.
[0025] In some embodiments of the present application, a firewall instance is configured based on the security level of the virtual desktop of the service window, including:
[0026] The rule template of the firewall instance is defined according to the security level of the virtual desktop of the business window. The rule template includes access control rules, traffic filtering rules and transmission encryption rules. The security levels of the virtual desktops of different business windows correspond to different levels of access control rules, traffic filtering rules and transmission encryption rules. The firewall instance corresponding to the virtual desktop of each business window is configured in this way.
[0027] In some embodiments of the present application, the access scenario of the virtual desktop of the business window is defined, including:
[0028] Access scenarios include virtual desktop access of a single business window and virtual desktop access of multiple business windows. Virtual desktop access of multiple business windows involves the interaction of virtual desktops of different business windows.
[0029] Through operation monitoring and data flow tracking, virtual desktop access of a single business window and virtual desktop access of multiple business windows can be identified.
[0030] In some embodiments of the present application, a dynamic monitoring strategy is set according to the control content and access scenario, including:
[0031] For virtual desktop access of a single business window, dynamic monitoring of virtual desktop access is performed according to the preset monitoring strategy;
[0032] For virtual desktop access of multiple business windows, the control content includes the single window content and the interactive content between windows. The single window content index and the interactive content index are extracted. The monitoring cycle is determined by the number of multiple business windows. The monitoring intensity in each monitoring cycle is calculated based on the single window content and the interactive content between windows. The monitoring strategy of the next monitoring cycle is adjusted based on the monitoring intensity in the previous monitoring cycle.
[0033] in, For the The monitoring intensity under each monitoring cycle is Respectively The number of single-window content indicators and interactive content indicators in each monitoring cycle, , Respectively Single window content indicators and The weight of each interactive content indicator, Respectively The first monitoring cycle Single window content indicators and Interactive content indicators, For the The third constant under a monitoring cycle.
[0034] Correspondingly, the present application also provides a firewall-based bank virtual desktop remote access control system, including:
[0035] The first module is used to obtain banking business content, divide the bank virtual desktop according to the banking business content, and obtain virtual desktops of different business windows;
[0036] The second module is used to analyze the security information of the virtual desktop of each service window to determine the security level of the virtual desktop of each service window, and configure the firewall instance based on the security level of the virtual desktop of the service window;
[0037] The third module is used to receive remote access requests from bank personnel. The firewall instance checks the remote access requests. After the check passes, the firewall instance releases the remote access request for the virtual desktop.
[0038] The fourth module is used for monitoring the control content of remote access by the firewall instance during the remote access process of the virtual desktop of the business window, defining the access scenario of the virtual desktop of the business window, and setting a dynamic monitoring strategy according to the control content and access scenario.
[0039] Compared with the prior art, the present invention has the following beneficial effects:
[0040] 1. Analyze the security information of the virtual desktop of each business window to determine the security level of the virtual desktop of each business window, set up the firewall instance of each virtual desktop in a targeted manner, provide targeted protection for each virtual desktop, and improve the reliability of the firewall instance.
[0041] 2. Define the access scenarios of the virtual desktops of the business windows, and adopt different security monitoring strategies for single virtual desktops and multiple virtual desktops to improve the security of remote access. Set dynamic monitoring strategies based on the control content and access scenarios, and adjust the security monitoring strategies based on the interaction between multiple virtual desktops, which improves the security and adaptability of remote access control of bank virtual desktops and ensures the security of remote access control. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 A flowchart of a firewall-based bank virtual desktop remote access control method proposed by the present invention;
[0043] Figure 2 The present invention is a schematic diagram of the structure of a firewall-based bank virtual desktop remote access control system. DETAILED DESCRIPTION
[0044] The technical solutions in the embodiments of the present invention will be described clearly and completely below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all the embodiments.
[0045] Reference Figure 1 , a remote access control method for bank virtual desktop based on firewall, comprising the following steps,
[0046] Step S101, obtaining banking service content, dividing the banking virtual desktop according to the banking service content, and obtaining virtual desktops of different service windows.
[0047] In this embodiment, the banking business content includes but is not limited to deposits, loans, transfers, payments, financial management, customer service, etc. Based on these business contents, the bank virtual desktop is divided to form different business window virtual desktops.
[0048] In some embodiments of the present application, the bank virtual desktop is divided according to the banking business content to obtain virtual desktops of different business windows, including:
[0049] Split the banking business content into multiple business types, determine the interactive content between business types, and build an interactive relationship diagram between all business types;
[0050] The interaction relationship diagram is split according to the business type to form a plurality of specific interaction relationship diagrams, and each business type and the specific interaction relationship diagram corresponding to the business type are used as the virtual desktop of the business window.
[0051] In this embodiment, the business types include deposit business, loan business, transfer business and financial management business, etc. The interactive content between business types is the circulation and interaction between different businesses. For example, the loan business virtual desktop can request the deposit business virtual desktop to provide customer deposit information. Through virtualization technology, the physical firewall is logically divided into multiple virtual systems, each virtual system is equivalent to an independent firewall device, with its own software and hardware resources, including interfaces, routing tables and security policies. Then, independent system resources and security policies are allocated to each virtual system to achieve effective isolation and utilization of resources, while ensuring the security of each virtual system. The existing firewall supervision only has simple monitoring, for example, browser AAA is added to the whitelist, and browser AAA completes web pop authentication, and then the computer is physically connected to the external network. Only browser AAA and VPN can access the network. VPN is also in the whitelist. Through VPN authentication, the domain control computer accesses the virtual desktop in the row through VPN. In addition, browser AAA can also access the network, so browser AAA needs to be customized, such as disabling the address input bar so that it cannot access the external network to ensure security.
[0052] Step S102 : Analyze the security information of the virtual desktop of each service window to determine the security level of the virtual desktop of each service window, and configure the firewall instance based on the security level of the virtual desktop of the service window.
[0053] In this embodiment, security information analysis is performed on the virtual desktop of each business window, including data sensitivity, information asset value, and interaction status. Based on these analysis results, the security level of each business window virtual desktop is determined. Based on the security level of the business window virtual desktop, a corresponding firewall instance is configured. The firewall instance should be able to implement different levels of access control rules according to different security levels.
[0054] In some embodiments of the present application, the security information of the virtual desktop of each service window is analyzed to determine the security level of the virtual desktop of each service window, including:
[0055] Security information includes data categories, historical security records, data information assets, and interactions with business windows;
[0056] Conduct a multi-dimensional sensitivity assessment of all data categories involved in the virtual desktop of the business window to determine the sensitivity of all data categories in the virtual desktop of each business window;
[0057] Evaluate the value of the data and information assets involved in the virtual desktop of the business window to determine the value of the data and information assets;
[0058] The historical security records record the security incidents and incident handling situations that have occurred in the business window in the past, match the security incidents and incident handling situations, and determine the risk factor of the business window based on the security incidents and the corresponding incident handling situations;
[0059] Calculate the interaction index of each business window based on the interaction status of the business window and the specific interaction relationship diagram;
[0060] The security level of the virtual desktop of the business window is determined by the sensitivity of all data categories, the value of data information assets, the risk factor of the business window and the interaction index of the business window.
[0061] In this embodiment, the sensitivity of the data types processed by different business windows varies. For example, customer identity information, transaction records, account passwords, etc. are highly sensitive data, while some public promotional information, product introductions, etc. are less sensitive. Evaluate the sensitivity of the data based on the risk that may be caused by data leakage or abuse. Evaluate the value of the information assets involved in the business window to the bank, including economic value, legal compliance value, etc. Investigate whether the business window has had security incidents in the past, and whether the handling and prevention measures of the incidents are appropriate, and determine the risk factor of the business window. Interaction situations include data flow, dependencies, and isolation measures.
[0062] In some embodiments of the present application, the interaction index of each service window is calculated according to the interaction status of the service window and the specific interaction relationship diagram, including:
[0063] The nodes corresponding to each business window and the data flow frequency, dependency strength and isolation level between the nodes are marked on the specific interaction relationship diagram according to the interaction of the business windows. The length and weight of the edges between the nodes on the specific interaction relationship diagram are defined according to the data flow frequency, dependency strength and isolation level.
[0064] The degree centrality, closeness centrality and betweenness centrality of each node on the specific interaction relationship graph are calculated through graph theory algorithms, and the degree centrality, closeness centrality and betweenness centrality are normalized. The interaction index of each business window is calculated by integrating degree centrality, closeness centrality and betweenness centrality.
[0065] in, For the The interaction index of a business window, Respectively The interaction weights of degree centrality, closeness centrality and betweenness centrality of each business window, Respectively The degree centrality, closeness centrality and betweenness centrality of each business window, express The maximum value in For the The first constant corresponding to a business window.
[0066] In this embodiment, data flow frequency (measures the frequency of data flow between different virtual desktops. It can be calculated by monitoring network traffic, data transmission events or data access logs, considering whether the data flows in one direction or two directions, and the main direction of data flow), dependency strength (measures the degree of dependence of one virtual desktop on another virtual desktop. It can be determined by analyzing service calls, resource sharing or functional dependencies) and isolation level (evaluates the degree of isolation between virtual desktops, including network isolation, storage isolation, computing resource isolation, etc.). Network centrality is a set of indicators used to quantify the importance of nodes in a network. In the context of virtual desktop interaction, it can be used to identify which virtual desktops play a central role in the interaction network. By calculating the centrality indicators of virtual desktops in the interaction network (such as degree centrality, closeness centrality, betweenness centrality, etc.), it is possible to identify which desktops have higher interaction activity or influence. This is of great significance for understanding the interaction mode between virtual desktops and optimizing the interaction process.
[0067] In this embodiment, the length and weight of the edge between nodes on the specific interaction relationship diagram are defined according to the frequency of data flow, the strength of dependency, and the isolation level, and the edge is established according to the interaction between virtual desktops (such as data exchange, user switching, etc.). The weight and length of the edge can be determined based on factors such as the frequency of interaction, the amount of data, or the required time. When building a network, the frequency of data flow, the strength of dependency, and the isolation level should be comprehensively considered. For example, shorter edges may be established between desktops with a high frequency of data flow; desktops with a high strength of dependency may have a greater weight; and desktops with a high isolation level may have fewer edges or lower weights.
[0068] In this embodiment, degree centrality: calculate the degree of each node (virtual desktop), that is, the number of edges directly connected to it. The higher the degree, the higher the interactive activity of the desktop.
[0069] Closeness centrality: Calculate the average length of the shortest path from each node to other nodes in the network. The shorter the average length, the better the accessibility of the desktop in the network and the greater the influence on other desktops.
[0070] Betweenness centrality: Calculates the number of nodes that each node passes through as the shortest path in the network. The more times, the stronger the intermediary role of the desktop in the network, and the more important it is to the interaction of other desktops.
[0071] In this embodiment, express , , The maximum value in is the correction of the sum of degree centrality, closeness centrality and betweenness centrality. The first constant is to balance the size of the correction function.
[0072] In some embodiments of the present application, the security level of the virtual desktop of the business window is determined by the sensitivity of all data categories, the value of data information assets, the risk coefficient of the business window and the interaction index of the business window, including:
[0073] in, For the The security level of the virtual desktop of each business window, For the The risk factor of each business window, Respectively The sensitivity of the data category of each business window and the value of the data information asset are combined with their respective weights. Respectively The sensitivity of the data categories of each business window and the value of data information assets, For the The adjustment coefficient of a business window, represents the adjustment coefficient obtained by the interactive index mapping, For the The second constant corresponding to the service window, [] is the rounding symbol.
[0074] In this embodiment, the security level of the virtual desktop is determined by comprehensively considering the sensitivity of all data categories, the value of data information assets, the risk factor of the business window, and the interaction index of the business window. It is to balance the size of the security level.
[0075] In some embodiments of the present application, a firewall instance is configured based on the security level of the virtual desktop of the service window, including:
[0076] The rule template of the firewall instance is defined according to the security level of the virtual desktop of the business window. The rule template includes access control rules, traffic filtering rules and transmission encryption rules. The security levels of the virtual desktops of different business windows correspond to different levels of access control rules, traffic filtering rules and transmission encryption rules. The firewall instance corresponding to the virtual desktop of each business window is configured in this way.
[0077] In this embodiment, the higher the security level of the virtual desktop of the business window, the more complex the corresponding rule template and the higher the requirements. Access control rules are used to determine which users or devices have access to specific resources or services. In the context of a virtual desktop, these rules can control which users or IP addresses can access the virtual desktop and what operations they can perform (such as reading, writing, executing, etc.). Traffic filtering rules are used to monitor and filter network traffic in and out of the virtual desktop. These rules can be configured based on traffic type (such as HTTP, FTP, SMTP, etc.), source address, destination address, port number and other conditions. Transmission encryption rules are used to ensure that data transmitted between the virtual desktop and the client is encrypted to prevent data from being stolen or tampered with during transmission. Each type of rule has a level quantification to distinguish the security level of rules at different levels.
[0078] Step S103, receiving a remote access request from a bank employee, the firewall instance checks the remote access request, and after the check passes, the firewall instance releases the remote access request for the virtual desktop.
[0079] In this embodiment, bank personnel connect to the bank's internal network through remote access and access the corresponding business window virtual desktop. The firewall instance receives the remote access request and checks the request. The firewall instance should verify the legitimacy of the remote access request, including the source IP address of the request, identity authentication information, etc. If the request complies with the firewall rules, access is allowed; otherwise, access is denied and a log is recorded. In order to improve security, a multi-factor identity authentication method can be used, such as a combination of passwords, dynamic passwords, biometrics, etc. When the remote access request passes the inspection of the firewall instance, the firewall instance releases the remote access request for the virtual desktop. During the remote access process, the firewall instance continuously monitors the control content of the remote access.
[0080] Step S104, during the remote access process of the virtual desktop of the service window, the firewall instance monitors the control content of the remote access, defines the access scenario of the virtual desktop of the service window, and sets a dynamic monitoring strategy according to the control content and the access scenario.
[0081] In this embodiment, the firewall instance should record all operations during remote access, including access time, visitor identity, access operation type, etc. At the same time, real-time monitoring and alarms should be performed for sensitive operations, such as large transfers, password changes, etc. In order to ensure the integrity and confidentiality of data, data encryption and transmission encryption technologies can be used. Dynamic monitoring strategies are implemented for the two scenarios of virtual desktops of a single business window and virtual desktop interactions of multiple business windows.
[0082] In some embodiments of the present application, the access scenario of the virtual desktop of the business window is defined, including:
[0083] Access scenarios include virtual desktop access of a single business window and virtual desktop access of multiple business windows. Virtual desktop access of multiple business windows involves the interaction of virtual desktops of different business windows.
[0084] Through operation monitoring and data flow tracking, virtual desktop access of a single business window and virtual desktop access of multiple business windows can be identified.
[0085] In this embodiment, an operation monitoring system is deployed in a virtual desktop environment to capture the user's cross-window operation behavior in real time. Data flow tracking technology, such as data tagging, data flow diagram, etc., is used to track the user's data flow in the virtual desktop environment. By analyzing the data flow, it is determined whether the user has performed data interaction between multiple business windows.
[0086] In some embodiments of the present application, a dynamic monitoring strategy is set according to the control content and access scenario, including:
[0087] For virtual desktop access of a single business window, dynamic monitoring of virtual desktop access is performed according to the preset monitoring strategy;
[0088] For virtual desktop access of multiple business windows, the control content includes the single window content and the interactive content between windows. The single window content index and the interactive content index are extracted. The monitoring cycle is determined by the number of multiple business windows. The monitoring intensity in each monitoring cycle is calculated based on the single window content and the interactive content between windows. The monitoring strategy of the next monitoring cycle is adjusted based on the monitoring intensity in the previous monitoring cycle. in, For the The monitoring intensity under each monitoring cycle is Respectively The number of single-window content indicators and interactive content indicators in each monitoring cycle, , Respectively Single window content indicators and The weight of each interactive content indicator, Respectively The first monitoring cycle Single window content indicators and Interactive content indicators, For the The third constant under a monitoring cycle.
[0089] In this embodiment, for the virtual desktop access of a single business window, a set of monitoring strategies is preset according to the importance and sensitivity of the business window, including monitoring indicators (such as the number of logins, operation frequency, data transmission volume, etc.), monitoring thresholds, and monitoring time intervals. The data of virtual desktop access is collected in real time and compared with the preset monitoring strategy. If it is found that the data exceeds the preset threshold or the behavior pattern does not match the normal pattern, an alarm is triggered and further analysis and investigation are carried out. According to the monitoring results, the monitoring strategy is dynamically adjusted to adapt to changes in the business window and potential security threats.
[0090] In this embodiment, the operations and contents within each business window are monitored, such as file access, application usage, data input, etc. Data exchange and interaction between different business windows are monitored, such as file transfer, message delivery, etc. Specific indicators are extracted for the single window content and the interactive content between windows, such as operation frequency, data transmission volume, number of interactions, etc. These indicators should be able to fully reflect the activity and potential security risks of virtual desktop access. Determine an appropriate monitoring cycle based on the number and complexity of multiple business windows. The monitoring cycle should be short enough to detect abnormal behavior in a timely manner; at the same time, it should be long enough to avoid generating too much monitoring data and processing burden. Based on the single window content and the interactive content indicators between windows, the monitoring intensity under each monitoring cycle is calculated. The monitoring intensity can reflect the activity level and potential risks of virtual desktop access in the current monitoring cycle.
[0091] In this embodiment, for virtual desktop access of multiple business windows, the monitoring strategy includes monitoring indicators and alarm mechanisms. The greater the monitoring intensity, the higher and more severe the requirements for monitoring indicators and alarm mechanisms, and vice versa.
[0092] In this embodiment, Indicates the correction of the average value of the interactive content index to the average value of the single window content index. It exists to balance the correction function.
[0093] Correspondingly, the present application also provides a firewall-based bank virtual desktop remote access control system, such as Figure 2 As shown, including
[0094] The first module is used to obtain banking business content, divide the bank virtual desktop according to the banking business content, and obtain virtual desktops of different business windows;
[0095] The second module is used to analyze the security information of the virtual desktop of each service window to determine the security level of the virtual desktop of each service window, and configure the firewall instance based on the security level of the virtual desktop of the service window;
[0096] The third module is used to receive remote access requests from bank personnel. The firewall instance checks the remote access requests. After the check passes, the firewall instance releases the remote access request for the virtual desktop.
[0097] The fourth module is used for monitoring the control content of remote access by the firewall instance during the remote access process of the virtual desktop of the business window, defining the access scenario of the virtual desktop of the business window, and setting a dynamic monitoring strategy according to the control content and access scenario.
[0098] Compared with the prior art, the present invention has the following beneficial effects:
[0099] 1. Analyze the security information of the virtual desktop of each business window to determine the security level of the virtual desktop of each business window, set up the firewall instance of each virtual desktop in a targeted manner, provide targeted protection for each virtual desktop, and improve the reliability of the firewall instance.
[0100] 2. Define the access scenarios of the virtual desktops of the business windows, and adopt different security monitoring strategies for single virtual desktops and multiple virtual desktops to improve the security of remote access. Set dynamic monitoring strategies based on the control content and access scenarios, and adjust the security monitoring strategies based on the interaction between multiple virtual desktops, which improves the security and adaptability of remote access control of bank virtual desktops and ensures the security of remote access control.
[0101] Those skilled in the art will appreciate that the accompanying drawings are merely schematic diagrams of a preferred implementation scenario, and the modules or processes in the accompanying drawings are not necessarily required for implementing the present invention.
[0102] Those skilled in the art will appreciate that the modules in the system in the implementation scenario can be distributed in the system of the implementation scenario according to the implementation scenario description, or can be changed accordingly and located in one or more systems different from the implementation scenario. The modules in the above implementation scenario can be combined into one module, or can be further split into multiple submodules.
[0103] The above description is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any technician familiar with the technical field can make equivalent replacements or changes according to the technical scheme and inventive concept of the present invention within the technical scope disclosed by the present invention, which should be covered by the protection scope of the present invention.
Claims
1. A remote access control method for bank virtual desktop based on firewall, characterized in that: include, Obtain banking business content, divide the bank virtual desktop according to the banking business content, and obtain virtual desktops of different business windows; Analyze the security information of the virtual desktop of each service window to determine the security level of the virtual desktop of each service window, and configure the firewall instance based on the security level of the virtual desktop of the service window; After receiving the remote access request from the bank staff, the firewall instance checks the remote access request. If the request passes the check, the firewall instance releases the remote access request to the virtual desktop. During the remote access process of the virtual desktop of the business window, the firewall instance monitors the control content of the remote access, defines the access scenario of the virtual desktop of the business window, and sets a dynamic monitoring strategy according to the control content and access scenario; in, The bank virtual desktop is divided according to the banking business content to obtain virtual desktops of different business windows, including: Split the banking business content into multiple business types, determine the interactive content between business types, and build an interactive relationship diagram between all business types; The interaction relationship diagram is split according to the business type to form multiple specific interaction relationship diagrams, and each business type and the specific interaction relationship diagram corresponding to the business type are used as the virtual desktop of the business window; Analyze the security information of the virtual desktop of each business window to determine the security level of the virtual desktop of each business window, including: Security information includes data categories, historical security records, data information assets, and interactions with business windows; Conduct a multi-dimensional sensitivity assessment of all data categories involved in the virtual desktop of the business window to determine the sensitivity of all data categories in the virtual desktop of each business window; Evaluate the value of the data and information assets involved in the virtual desktop of the business window to determine the value of the data and information assets; The historical security records record the security incidents and incident handling situations that have occurred in the business window in the past, match the security incidents and incident handling situations, and determine the risk factor of the business window based on the security incidents and the corresponding incident handling situations; Calculate the interaction index of each business window based on the interaction status of the business window and the specific interaction relationship diagram; The security level of the virtual desktop of the business window is determined by the sensitivity of all data categories, the value of data information assets, the risk factor of the business window and the interaction index of the business window.
2. The firewall-based bank virtual desktop remote access control method according to claim 1 is characterized in that: The interaction index of each business window is calculated based on the interaction status of the business window and the specific interaction relationship diagram, including: The nodes corresponding to each business window and the data flow frequency, dependency strength and isolation level between the nodes are marked on the specific interaction relationship diagram according to the interaction of the business windows. The length and weight of the edges between the nodes on the specific interaction relationship diagram are defined according to the data flow frequency, dependency strength and isolation level. The degree centrality, closeness centrality and betweenness centrality of each node on the specific interaction relationship graph are calculated through graph theory algorithms, and the degree centrality, closeness centrality and betweenness centrality are normalized. The interaction index of each business window is calculated by integrating degree centrality, closeness centrality and betweenness centrality. Among them, B i is the interaction index of the ith business window, α1 i , α2 i , α3 i are the interaction weights of degree centrality, closeness centrality and betweenness centrality of the ith business window, respectively, Q1 i 、Q2 i 、Q3 i are the degree centrality, closeness centrality and betweenness centrality of the ith business window, max(α1 i Q1 i α2 i Q2 i α3 i Q3 i ) represents α1 i Q1 i , α2 i Q2 i , α3 i Q3 i The maximum value in k i is the first constant corresponding to the i-th service window.
3. The firewall-based bank virtual desktop remote access control method according to claim 2 is characterized in that: The security level of the virtual desktop of the business window is determined by the sensitivity of all data categories, the value of data information assets, the risk factor of the business window and the interaction index of the business window, including: Among them, S i is the security level of the virtual desktop of the i-th business window, σ i is the risk coefficient of the i-th business window, β1 i , β2 i are the combined weights of the sensitivity of the data category and the value of the data information asset in the i-th business window, W1 i 、W2 i are the sensitivity of the data category and the value of the data information asset in the i-th business window, respectively, i is the adjustment coefficient of the ith business window, B i → i represents the adjustment coefficient obtained by the interactive index mapping, C i is the second constant corresponding to the ith service window, and [] is the rounding symbol.
4. The firewall-based bank virtual desktop remote access control method according to claim 1 is characterized in that: Configure firewall instances based on the security level of the virtual desktops in the business window, including: The rule template of the firewall instance is defined according to the security level of the virtual desktop of the business window. The rule template includes access control rules, traffic filtering rules and transmission encryption rules. The security levels of the virtual desktops of different business windows correspond to different levels of access control rules, traffic filtering rules and transmission encryption rules. The firewall instance corresponding to the virtual desktop of each business window is configured in this way.
5. The firewall-based bank virtual desktop remote access control method according to claim 1 is characterized in that: Define the access scenarios of the virtual desktop of the business window, including: Access scenarios include virtual desktop access of a single business window and virtual desktop access of multiple business windows. Virtual desktop access of multiple business windows involves the interaction of virtual desktops of different business windows. Through operation monitoring and data flow tracking, virtual desktop access of a single business window and virtual desktop access of multiple business windows can be identified.
6. The firewall-based bank virtual desktop remote access control method according to claim 5 is characterized in that: Set dynamic monitoring strategies based on control content and access scenarios, including: For virtual desktop access of a single business window, dynamic monitoring of virtual desktop access is performed according to the preset monitoring strategy; For virtual desktop access of multiple business windows, the control content includes the single window content and the interactive content between windows. The single window content index and the interactive content index are extracted. The monitoring cycle is determined by the number of multiple business windows. The monitoring intensity in each monitoring cycle is calculated based on the single window content and the interactive content between windows. The monitoring strategy of the next monitoring cycle is adjusted based on the monitoring intensity in the previous monitoring cycle. Among them, M j is the monitoring intensity in the jth monitoring cycle, n1 and n2 are the number of single-window content indicators and interactive content indicators in the jth monitoring cycle, respectively. are the weights of the a1th single window content index and the a2th interactive content index, respectively. are the a1th single window content index and a2th interactive content index in the jth monitoring cycle, respectively, and b j is the third constant in the jth monitoring cycle.
7. A bank virtual desktop remote access control system based on a firewall, characterized in that: The system is used to implement the firewall-based bank virtual desktop remote access control method as described in any one of claims 1 to 6, the system comprising: The first module is used to obtain banking business content, divide the bank virtual desktop according to the banking business content, and obtain virtual desktops of different business windows; The second module is used to analyze the security information of the virtual desktop of each service window to determine the security level of the virtual desktop of each service window, and configure the firewall instance based on the security level of the virtual desktop of the service window; The third module is used to receive remote access requests from bank personnel. The firewall instance checks the remote access requests. After the check passes, the firewall instance releases the remote access request for the virtual desktop. The fourth module is used for monitoring the control content of remote access by the firewall instance during the remote access process of the virtual desktop of the business window, defining the access scenario of the virtual desktop of the business window, and setting a dynamic monitoring strategy according to the control content and access scenario.
Citation Information
Patent Citations
Cloud data center service subnet security management method and system
CN105656916A