Fortress machine file access control method, device, computer equipment, medium and product
By dynamically matching access control rules in the bastion machine and generating permissions based on the attributes and behavioral characteristics information of file access operations, the problem that the bastion machine file access control cannot adapt to complex scenarios is solved, and more efficient security evaluation and precise control are achieved.
Patent Information
- Application Number
- CN202510364699.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2045-03-26
AI Technical Summary
The existing bastion machine file access control mechanism relies on blacklists or whitelists of fixed content, and cannot adapt to the security assessment needs in complex scenarios, resulting in access control errors.
After the fortress receives the file access operation, it dynamically matches the access control rules based on its attributes and behavioral feature information, generates file access permissions, and combines multi-dimensional feature information for access control.
It realizes flexible security assessment of file access operations in complex scenarios, reduces the limitations of access control, and improves the accuracy and security of access control.
Smart Images

Figure CN119892509B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular, to a method, device, computer device, computer-readable storage medium, and computer program product for controlling file access of a bastion host. Background Art
[0002] With the continuous development of technology, file management and access control within enterprises have also faced unprecedented challenges, which has made the application of bastion hosts more and more extensive. Among them, as a privilege management and auditing system based on cloud computing and network security technology, the bastion host provides a secure and reliable remote access and management method by centrally managing and controlling user access rights, and has become an indispensable security component of enterprises.
[0003] Currently, in the process of controlling file access of a bastion host, the file access operation is usually evaluated through a set blacklist or whitelist mechanism to ensure that the file access operation meets security standards. However, due to the relatively fixed content in the blacklist or whitelist, the file access control mechanism cannot match the evaluation requirements for operation security in complex scenarios, which may lead to access control errors. Therefore, the current limitations of controlling file access of a bastion host are high. Summary of the Invention
[0004] Based on this, in view of the above technical problems, it is necessary to provide a method, device, computer device, computer-readable storage medium, and computer program product for controlling file access of a bastion host that reduces the limitations of controlling file access of a bastion host.
[0005] In a first aspect, the present application provides a method for controlling file access of a bastion host, including:
[0006] Matching an access control rule that meets the access security standard for the current file access operation according to the attribute feature information carried by the current file access operation received by the bastion host;
[0007] Determining the file access permission of the current file access operation under the access control rule according to the behavior feature information carried by the current file access operation;
[0008] Performing access control on the current file access operation according to the file access permission.
[0009] In one of the embodiments, the attribute feature information includes operation time limit information; the step of matching an access control rule that meets the access security standard for the current file access operation according to the attribute feature information carried by the current file access operation received by the bastion host includes:
[0010] Construct preset access control rules that comply with security access standards for each historical file access operation;
[0011] Filter multiple preset access control rules to obtain multiple candidate access control rules within the valid time period indicated by the operation time limit information;
[0012] Extract the access control rules from the multiple candidate access control rules.
[0013] In one embodiment, the extracting the access control rules from the multiple candidate access control rules includes:
[0014] Rank the multiple candidate access control rules according to the operation risk information of each historical file access operation to obtain a ranking result;
[0015] Extract the access control rules from the multiple candidate access control rules according to the ranking result.
[0016] In one embodiment, the behavior feature information includes behavior location information, behavior object information, and behavior type information; the determining the file access permission of the current file access operation under the access control rules according to the behavior feature information carried by the current file access operation includes:
[0017] Detect the behavior permissions of the current file access operation in the access control rules in sequence according to the behavior location information, the behavior object information, and the behavior type information;
[0018] Generate the file access permission of the current file access operation under the access control rules according to multiple behavior permissions.
[0019] In one embodiment, the access control rules include multiple access control lists; the generating the file access permission of the current file access operation under the access control rules according to multiple behavior permissions includes:
[0020] Selection step: Select a target access control list from the multiple access control lists;
[0021] Detect the behavior permission matching result of the current file access operation under the target access control list according to the multiple behavior permissions;
[0022] Return to execute the selection step until all access control lists are selected as the target access control list to obtain the file access result commonly corresponding to multiple behavior permission matching results;
[0023] Generate the file access permission according to the result type of the file access result.
[0024] In one embodiment, the access control of the current file access operation according to the file access permission includes:
[0025] When the file access permission has access permission for the current file access operation, detect the behavior anomaly value of the current file access operation;
[0026] If the behavior anomaly value is greater than the preset behavior reference value, perform access control on the current file access operation according to the behavior verification result of the current file access operation;
[0027] If the behavior anomaly value is less than or equal to the preset behavior reference value, allow the current file access operation to be executed.
[0028] In a second aspect, the present application further provides a bastion host file access control method device, including:
[0029] A matching module, configured to match an access control rule that meets the access security standard for the current file access operation according to the attribute feature information carried by the current file access operation received by the bastion host;
[0030] A determination module, configured to determine the file access permission of the current file access operation under the access control rule according to the behavior feature information carried by the current file access operation;
[0031] An access control module, which performs access control on the current file access operation according to the file access permission.
[0032] In a third aspect, the present application further provides a computer device, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0033] Match an access control rule that meets the access security standard for the current file access operation according to the attribute feature information carried by the current file access operation received by the bastion host; determine the file access permission of the current file access operation under the access control rule according to the behavior feature information carried by the current file access operation; perform access control on the current file access operation according to the file access permission.
[0034] In a fourth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the following steps are implemented:
[0035] Based on the attribute feature information carried by the current file access operation received by the bastion host, match an access control rule that complies with the access security standard for the current file access operation; determine the file access permission of the current file access operation under the access control rule according to the behavior feature information carried by the current file access operation; perform access control on the current file access operation according to the file access permission.
[0036] In a fifth aspect, the present application further provides a computer program product, including a computer program, which when executed by a processor implements the following steps:
[0037] Based on the attribute feature information carried by the current file access operation received by the bastion host, match an access control rule that complies with the access security standard for the current file access operation; determine the file access permission of the current file access operation under the access control rule according to the behavior feature information carried by the current file access operation; perform access control on the current file access operation according to the file access permission.
[0038] For the above-mentioned bastion host file access control method, device, computer device, computer-readable storage medium, and computer program product, first, after the bastion host receives a current file access operation, according to the attribute feature information carried by the current file access operation, an access control rule that complies with the access security standard is matched for the current file access operation, so as to dynamically match an access control rule that complies with the access security standard through the specific attribute features of the current file access operation. Furthermore, according to the behavior feature information carried by the current file access operation, the file access permission of the current file access operation under the access control rule is determined, thus achieving the purpose of determining the specific access permission for the current file access operation to access the bastion host through the behavior features of the current file access operation. Finally, access control is performed on the current file access operation according to the file access permission. Since the file access permission of the current file access operation is flexibly determined under the joint action of the attribute feature information and behavior feature information of the current file access operation, during the process of accessing and controlling the bastion host file, the purpose of dynamically setting specific access permissions that comply with the security access standard for the current file access operation depending on the multi-dimensional feature information of the current file access operation is achieved. Furthermore, the file access permission can be adapted to the evaluation requirements for operation security in complex scenarios. Finally, based on the file access permission, the access control of the current file access operation is completed, rather than relying solely on a single-dimensional blacklist or whitelist mechanism for bastion host file access control. Therefore, the technical defect that the access control mechanism cannot match the evaluation requirements for operation security in complex scenarios due to the relatively fixed content in the blacklist or whitelist, resulting in errors in access control, is overcome. Therefore, the limitation of performing bastion host file access control is reduced. Brief Description of the Drawings
[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0040] Figure 1 It is a flowchart showing the process of the bastion host file access control method in one embodiment;
[0041] Figure 2 It is a flowchart showing the process of the bastion host file access control method in another embodiment;
[0042] Figure 3 It is a flowchart showing the working process of the isolation forest algorithm of the bastion host file access control method in another embodiment;
[0043] Figure 4 It is a schematic diagram showing the structure of the bastion host file management system of the bastion host file access control method in one embodiment;
[0044] Figure 5 It is a control flowchart showing the bastion host file access control of the bastion host file access control method in another embodiment;
[0045] Figure 6 It is a block diagram showing the structure of the bastion host file access control device;
[0046] Figure 7 It is an internal structure diagram of a computer device in one embodiment. Detailed Description of the Embodiments
[0047] In order to make the purpose, technical solutions and advantages of the present application clearer and more understandable, the following will further describe the present application in detail in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0048] First of all, it should be understood that with the rapid development of information technology and the deepening of digital transformation, file management and access control within enterprises are facing unprecedented challenges. On the one hand, network attacks and data leakage incidents occur frequently, bringing huge risks to the information security of enterprises. On the other hand, the access requirements within enterprises are becoming increasingly complex, and traditional access control mechanisms are no longer able to meet the high control requirements in existing complex scenarios. During the process of implementing bastion host file access control, traditional access control mechanisms usually control file access operations through the set blacklist or whitelist mechanisms. For example, the black and white lists in a single dimension are usually as follows: 1) The blacklist rejects a certain file operation while allowing other file operations; 2) The white list allows a certain file operation while rejecting other file operations. However, the above access control mechanisms have certain limitations in file access control, mainly relying on the single-dimensional blacklist or whitelist mechanisms, lacking fine-grained control and risk ability assessment of access behaviors, and also lacking in-depth analysis of user behavior patterns. Especially when dealing with issues such as complex access rules, risk assessment, and operation auditing, it is difficult to meet the increasingly complex security requirements. For example, it is difficult to implement the operation of deleting specific file directories for file access operations under a certain IP address, and at the same time, other file operations such as uploading and downloading outside this IP address and this file directory will be rejected. That is, due to the relatively fixed content in the blacklist or whitelist, the file access control mechanism cannot match the evaluation requirements for operation security in complex scenarios, which in turn makes it prone to access control errors. Therefore, there is an urgent need for a bastion host file access control method that reduces the limitations of bastion host file access control.
[0049] In one embodiment, as Figure 1As shown, a method for access control of bastion host files is provided. In this embodiment, an example is given where this method is applied to a terminal. The terminal is provided with a bastion host file management system. The terminal includes, but is not limited to, personal computers, laptop computers, smart phones, tablet computers, etc. The bastion host file management system includes a matching module, a determination module, and an access control module. The matching module is used to match an access control rule that meets the access security standard for the current file access operation according to the attribute feature information carried by the current file access operation received by the bastion host. The determination module is used to determine the file access permission of the current file access operation under the access control rule according to the behavior feature information carried by the current file access operation. The access control module is used to perform access control on the current file access operation according to the file access permission. Through the information interaction among the matching module, the determination module, and the access control module, depending on the multi-dimensional attribute features of the specific current file access operation, the purpose of dynamically setting specific access permissions that meet the security access standard for the current file access operation is achieved. Furthermore, the current file access operation can complete the access control of the current file access operation under the limitation of the file access permission that adapts to the evaluation requirements of operation security in complex scenarios, thereby overcoming the technical defect that since the content in the blacklist or whitelist is relatively fixed, the access control mechanism cannot match the evaluation requirements of operation security in complex scenarios, and thus it is easy to have the situation of access control errors. Therefore, the limitation of performing bastion host file access control is reduced. This method can also be applied to a server, and can also be applied to a system including a terminal and a server, and is implemented through the interaction between the terminal and the server. In this embodiment, the method includes the following steps 202 to step 206. Among them:
[0050] Step 202: Match an access control rule that meets the access security standard for the current file access operation according to the attribute feature information carried by the current file access operation received by the bastion host.
[0051] It should be noted that during the process of bastion host file access control, the explanations of relevant technical terms are as follows: 1) Bastion host: It is a privilege management and auditing system based on cloud computing and network security technologies. By centrally managing and controlling users' access privileges, it provides a secure and reliable remote access and management method, and can audit and record users' operations; 2) User and Entity Behavior Analytics (UEBA): It is a network security technology aimed at detecting abnormal activities and potential threats by analyzing the behavior patterns of users and entities. UEBA technology usually uses anomaly detection algorithms to establish the behavior baselines of users and entities, and monitors their activities in real time. By identifying abnormal patterns that deviate from normal behavior, it can effectively complete the detection of abnormal events; 3) SSH File Transfer Protocol (SFTP): It is a secure file transfer protocol that runs on top of the SSH protocol, uses encryption and cryptographic hash functions to protect the integrity of data, and authenticates the server and users, providing a secure, reliable and easy-to-configure file transfer function; 4) File Transfer Protocol (FTP): It is a communication protocol used to transfer files between remote devices and servers on networks such as local LAN or wide area network WAN. By providing access to directories or folders on remote computers, it assists in transferring files from one computer to another, and allows software, data or text files to be transferred between different types of computers. It can be understood that during the process of bastion host file access control, if problems such as dealing with complex access rules, risk assessment and operation auditing are faced, the above technologies or environments can be comprehensively utilized to achieve.
[0052] It should be noted that the current file access operation is used to access the bastion host, that is, to access the bastion host file management system. It can be understood that since the bastion host itself serves as an intermediary management point, accessing the bastion host file management system is essentially accessing files on other systems or servers through the bastion host. Specifically, it can be to upload or delete specified files on a remote server by running scripts or command lines on the bastion host. For example, in an implementable manner, the current file access operation is sent by device A, and the bastion host receives the current file access operation as an intermediary. When access is allowed, the current file access operation deletes files on device B, where A and B are different devices.
[0053] It should be noted that the attribute feature information is used to characterize the attribute features of the current file access operation, which can specifically be the operation effective time, the operation expiration time, and the operation risk level, etc. Among them, the operation effective time refers to the specific time point when the current file access operation starts to take effect, the operation expiration time refers to the specific time point when the current file access operation ends to take effect, and the operation risk level refers to the specific risk level of the current file access operation. For example, in an implementable manner, if the attribute feature information carries the field "1", it indicates that the operation risk level of the current file access operation is level 1; if the attribute feature information carries the field "2", it indicates that the operation risk level of the current file access operation is level 2; if the attribute feature information carries the field "3", it indicates that the operation risk level of the current file access operation is level 3. Among them, the higher the operation risk level, the higher the risk of the file access operation can be indicated.
[0054] It should be noted that the access control rule is used to characterize the permissions and conditions for file access through the bastion host. Specifically, it can be that a specified IP address is allowed to perform the operation of deleting files on a specific file directory. It can be understood that if the current file access operation is under the restriction of the access control rule, the process of accessing and controlling the bastion host files complies with the security standard. It can be understood that the access control rule can be generated instantaneously or pre-set, and is obtained by querying with the attribute features of the current file access operation as the index.
[0055] As an example, step 202 includes: extracting the attribute feature information from the current file access operation received by the bastion host, and using the attribute feature information as the index to match an access control rule that complies with the security standard for the current file access operation.
[0056] Step 204, determine the file access permission of the current file access operation under the access control rule according to the behavior feature information carried by the current file access operation.
[0057] It should be noted that the behavioral characteristic information is used to characterize the operation behavior of the current file access operation, which can specifically be the operation source address, operation path, operation type, etc. Among them, the operation source address refers to the device IP address that initiates the current file access operation, which can specifically be xxx.xxx.x.xx, the operation path refers to the specific address to be accessed by the current file access operation, which can specifically be / data / public / 1.txt, and the operation type refers to the way of the current file access operation, which can specifically be read, write, delete, append, etc. It can be understood that to achieve fine-grained control of file operations, multiple file access permissions can be set in the access control rules. Then, during the process of file access control by the bastion host, the specific file access permissions adapted to each file access operation can be flexibly determined and applied according to the specific behavioral characteristics of each file access operation. Among them, the file access permission refers to the detailed permission regulations for file access through the bastion host. For example, through the file access permission, it can be known which users or roles can read, write, execute, or delete files.
[0058] As an example, step 204 includes: extracting behavioral characteristic information in the current file access operation, and taking the preset file access permission that matches the behavioral characteristic information in the access control rule as the file access permission of the current file access operation.
[0059] It can be understood that multiple preset file access permissions can be set in the access control rule. Among them, each preset file access permission has a behavioral benchmark characteristic. Then, by comparing the behavioral characteristics of the current file access operation with multiple behavioral benchmark characteristics, and when the behavioral characteristics and the behavioral benchmark characteristics are compared and are consistent, the preset file access permission corresponding to the behavioral benchmark characteristic is taken as the file access permission of the current file access operation.
[0060] Step 206, perform access control on the current file access operation according to the file access permission.
[0061] It should be noted that based on the file access permission, it can be determined whether to allow the execution of the current file access operation.
[0062] As an example, step 206 includes: executing the current file access operation under the file access permission, or refusing to execute the current file access operation according to the file access permission.
[0063] In the above method for file access control of the bastion host, first, after the bastion host receives the current file access operation, according to the attribute feature information carried by the current file access operation, an access control rule that meets the access security standard is matched for the current file access operation. Thus, through the specific attribute features of the current file access operation, an access control rule that meets the access security standard is dynamically matched. Furthermore, according to the behavior feature information carried by the current file access operation, the file access permission of the current file access operation under the access control rule is determined. Thereby, the purpose of determining the specific access permission for the current file access operation to access the bastion host through the behavior features of the current file access operation is achieved. Finally, access control is performed on the current file access operation through the file access permission. Since the file access permission of the current file access operation is flexibly determined under the joint action of the attribute feature information and the behavior feature information of the current file access operation, during the process of performing access control on the bastion host files, the purpose of dynamically setting a specific access permission that meets the security access standard for the current file access operation depending on the multi-dimensional feature information of the current file access operation is achieved. Furthermore, the file access permission can be adapted to the evaluation requirements for operation security in complex scenarios. Finally, based on the file access permission, the access control of the current file access operation is completed, rather than relying only on a single-dimensional blacklist or whitelist mechanism for bastion host file access control. Therefore, the technical defect that the access control mechanism cannot match the evaluation requirements for operation security in complex scenarios due to the relatively fixed content in the blacklist or whitelist, and thus it is prone to access control errors is overcome. Therefore, the limitation of performing bastion host file access control is reduced.
[0064] In one embodiment, as Figure 2 shown, the attribute feature information includes operation timeliness information; according to the attribute feature information carried by the current file access operation received by the bastion host, matching an access control rule that meets the access security standard for the current file access operation includes:
[0065] Step 302, constructing a preset access control rule that meets the security access standard for each historical file access operation.
[0066] It should be noted that, in order to improve the efficiency of file access control in the bastion host, a construction module can be deployed in the bastion host file management system. Multiple preset access control rules can be constructed through the construction module. For example, in an implementable manner, any preset access control rule can be understood as a blacklist or a whitelist constructed by the construction module. Among them, the blacklist can be called an enhanced blacklist, and the whitelist can be called an enhanced whitelist. In the process of constructing the enhanced blacklist or the enhanced whitelist, the operation characteristic information of historical file access operations can be referred to. The operation characteristic information includes operation time limit information and operation information. Furthermore, through the operation path, operation type, operation risk level, operation source IP, operation effective time, and operation expiration time of historical file access operations, it can be understood that the operation characteristic information of file access operations can also be called metadata. Through the above operation characteristic information of historical file access operations, more detailed access control can be performed on each historical file access operation. Among them, multiple historical file access operations can be statistically obtained within the same observation period. Specifically, the operation characteristic information of historical file operations can be described as Table 1, and Table 1 is shown as follows:
[0067]
[0068] Among them, within the set observation period, the file operation behaviors of users can be continuously monitored and recorded, which can specifically include information such as operation time, frequency, operation type, and operation source IP, so as to construct multiple preset control rules that meet the security access standards according to the operation characteristic information of different historical file access operations.
[0069] As an example, step 302 includes: obtaining multiple operation characteristic information of each historical file access operation, and generating a preset access control rule that meets the access security standard for each historical file access operation according to the multiple operation characteristic information, so as to obtain multiple preset access control rules.
[0070] Step 304, screening the multiple preset access control rules to obtain multiple candidate access control rules within the effective time period identified by the operation time limit information.
[0071] It should be noted that the candidate access control rules are used to represent the access control rules waiting to be used for the current file access operation. It can be understood that since the multiple preset access control rules are constructed by refining the operation characteristic information of historical file access operations, the screening of the multiple preset access control rules can be completed through the time consistency between the multiple preset access control rules and the effective time period of the current file access operation identified by the operation expiration information.
[0072] As an example, step 304 includes: extracting the preset valid time periods corresponding to multiple preset access control rules, selecting an access valid time period from the multiple preset valid time periods according to the valid time period indicated by the operation failure information, and using the preset access control rule to which the access valid time period belongs as a candidate access control rule.
[0073] Step 306, extracting an access control rule from the multiple candidate access control rules.
[0074] It should be noted that based on the access control accuracy of the current file access operation in the bastion host file management system, any candidate access control rule in the multiple candidate access control rules can be extracted as the access control rule. Among them, the candidate access control rules include an allow access control rule and a deny access control rule. The allow access control rule corresponds to a whitelist, and the deny access control rule corresponds to a blacklist. For example, in an implementable manner, a allow access control rule and a deny access control rule can be randomly selected from the multiple candidate access control rules as the access control rule.
[0075] As an example, step 306 includes: randomly selecting an allow access control rule and a deny access control rule from the multiple candidate access control rules as the access control rule.
[0076] In an implementable manner, assume that the constructed enhanced black and white list includes: 1) Blacklist 1: (1) Reject logins to the bastion host file management system from IP addresses xxx.xxx.1.100 or xxx.xxx.1.1 - xxx.xxx.1.20 or xx.0.0.0 / xx, and perform upload and delete operations on the paths / data / secure or / file / *.txt during the period from June 1, 2024 to June 9, 2024. The risk level of this operation is 5. Among them, the operation characteristic information is as follows: 1. Type: Blacklist; 2. File operation path: / data / secure, / file / *.txt; 3. File operation type: upload, delete; 4. Operation risk level: 5; 5. Operation source IP: 192.168.1.100, xxx.xxx.1.1 - xxx.xxx.1.20, xx.0.0.0 / xx; 6. Effective time: 2024-06-01 00:00:00; 7. Expiration time: 2024-06-09 23:59:59; 2) Whitelist 1: (2) Allow logins to the bastion host file management system from IP addresses xxx.xxx.1.30 - xxx.xxx.1.50, and perform upload, download, and delete operations on the path / data / public during the period from June 10, 2024 to June 30, 2024. The risk level of this operation is 4. Among them, the operation characteristic information is as follows: 1. Type: Whitelist; 2. File operation path: / data / public; 3. File operation type: upload, download, delete; 4. Operation risk level: 4; 5. Operation source IP: xxx.xxx.1.30 - xxx.xxx.1.50; 6. Effective time: 2024-06-10 00:00:00; 7. Expiration time: 2024-06-30 23:59:59; 3) Blacklist 2, (2) Allow logins to the bastion host file management system from IP addresses xxx.xxx.1.30 - xxx.xxx.1.50, and perform upload, download, and delete operations on the path / data / public during the period from June 10, 2024 to June 30, 2024. The risk level of this operation is 4.Constructed as follows: 1. Type: whitelist; 2. File operation path: / data / public; 3. File operation types: upload, download, delete; 4. Operation risk level: 4; 5. Operation source IP: xxx.xxx.1.30 - xxx.xxx.1.50; 6. Effective time: 2024-06-10 00:00:00; 7. Expiration time: 2024-06-30 23:59:59. The screening results of the enhanced black and white list can be illustrated by the following parallel examples: 1) Suppose the effective period indicated by the operation time limit information is within the period from 2024-06-01 00:00:00 to 2024-06-09 23:59:59. Since Whitelist 1 has not reached the effective time, Whitelist 1 is not used as the access control rule. 2) Suppose the effective period indicated by the operation time limit information is within the period from 2024-06-10 00:00:00 to 2024-06-19 23:59:59. Since Blacklist 1 has reached the expiration time, Blacklist 1 is not used as the access control rule. And since Whitelist 2 has reached the effective time, Whitelist 2 is used as the access control rule. 3) Suppose the effective period indicated by the operation time limit information is within the period from 2024-06-20 00:00:00 to 2024-06-30 23:59:59. Since Blacklist 2 has reached the expiration time, Blacklist 2 is not used as the access control rule.
[0077] In this embodiment, during the process of matching an access control rule for the current file access operation, first, multiple preset access control rules that meet the security access standards are constructed based on the construction module. Then, through the effective period indicated by the operation expiration information, screening is performed among the multiple preset access control rules. Finally, an access control rule is flexibly extracted from the multiple preset access control rules based on the access control requirement level, so that an access control rule that meets the security access standards can be matched for the current file access operation with a more refined access control level. Therefore, while reducing the control limitations of the bastion host file access control, it lays a foundation for improving the control accuracy of the bastion host file access control.
[0078] In one embodiment, extracting an access control rule from multiple candidate access control rules includes:
[0079] According to the operation risk information of each historical file access operation, perform a priority ranking on the multiple candidate access control rules to obtain a priority ranking result; according to the priority ranking result, extract an access control rule from the multiple candidate access control rules.
[0080] It should be noted that since the access rights provided by different candidate access control rules are different, in order to avoid access control conflicts, multiple candidate access control rules can be sorted. For example, in an implementable manner, during the sorting process of the bastion host file management system, the system will extract the operation risk information of the black and white lists to determine the operation risk level of each historical file access operation, and rank the black and white lists with higher risk levels in the front; it can be understood that if there are the same operation risk levels, to reduce the processing volume, the system will give priority to processing the white list; at the same time, the sorting module will dynamically manage the effective black and white lists according to the effective time and expiration time of the historical file access operations, remove the expired black and white lists, and add the newly effective black and white lists to ensure that only the black and white lists within the validity period will take effect, that is, the preset access control rules have been screened through the operation time limit information to obtain the access control rules within the validity period; finally, the sorting module will output the effective black and white lists sorted from high to low risk levels for the bastion host file management system to extract one or more black and white lists that are finally input to the decision-making module of the bastion host file management system according to the effective black and white lists sorted from high to low.
[0081] As an example, according to the operation risk levels corresponding to the operation risk information of each historical file access operation, multiple candidate access control rules are sorted once to obtain a primary sorting result. If it is detected that there are a first target access control rule and a second target access control rule with the same risk level in the primary sorting result, then according to the rule identifiers corresponding to the first target access control rule and the second target access control rule respectively, the first target access control rule and the second target access control rule are sorted again in the primary sorting result to obtain a secondary sorting result, and the secondary sorting result is used as the priority sorting result of the multiple candidate access control rules. If it is detected that there are no first target access control rule and second target access control rule with the same risk level in the primary sorting result, then the primary sorting result is used as the priority sorting result, where the first target access control rule and the second target access control rule are different candidate access control rules.
[0082] In this embodiment, during the process of extracting access control rules from candidate access control rules, first, relying on the operation risk information of each historical file access operation, the multiple candidate access control rules are sorted by priority to obtain a priority sorting result. Finally, according to the priority sorting result, access control rules are extracted from the multiple candidate access control rules, thereby assigning different priorities to the multiple candidate access control rules. Therefore, when matching access control rules, it can be based on the priority of the rules, which can avoid decision-making conflicts when making subsequent access control decisions using access control rules. Therefore, it further lays a foundation for improving the control accuracy of bastion host file access control.
[0083] In one embodiment, the behavior feature information includes behavior location information, behavior object information, and behavior type information; determining the file access permission of the current file access operation under the access control rule according to the behavior feature information carried by the current file access operation includes:
[0084] Detecting the behavior permissions of the current file access operation in the access control rule in sequence according to the behavior location information, behavior object information, and behavior type information; generating the file access permission of the current file access operation under the access control rule according to the multiple behavior permissions.
[0085] It should be noted that in the process of determining the file access permission of the current file access operation, in order to improve the precision of access control, multi-level behavior feature information can be set for the determination of the behavior permission of the current file access operation. For example, in an implementable manner, the behavior location information can be the operation path, the behavior object information can be the operation source IP address, and the behavior type information can specifically be the operation type. Then the working process of the decision-making module of the bastion host file management system can be as follows: The decision-making module first assumes that all the obtained multiple access control rules (all valid blacklists and whitelists) are within the valid time period identified by the current file access operation, and then determines whether to allow file operations from the source IP according to the sourceIps in the black and white lists. Then, it matches the path of the file operation according to the paths in the black and white lists to determine whether to allow file operations under this path. Then, it matches the type of the file operation according to the operations in the black and white lists to determine whether to allow file operations of this type; it can be understood that the blacklist rejects the operation, and the white list allows the operation.
[0086] As an example, detecting the first behavior permission of the current file access operation in the access control rule according to the behavior location information, detecting the second behavior permission of the current file access operation in the access control rule according to the behavior object information, and detecting the third behavior permission of the current file access operation in the access control rule according to the behavior type information; obtaining the file access permission of the current file access operation in the access control rule by integrating the first behavior permission, the second behavior permission, and the third behavior permission.
[0087] In this embodiment, through behavioral characteristic information in multiple different dimensions, multi-level detection is performed on the behavioral permissions of the current file access operation under the access control rules, and relying on multiple different behavioral permissions that conform to the access control rules, the file access permissions of the current file access operation under the access control rules are completed, so as to ensure that the current file access operation still conforms to the security access standard in a more refined security evaluation dimension. Therefore, it lays a foundation for improving the control security of the bastion host file access control and reducing the control limitations of the bastion host file access control simultaneously.
[0088] In one embodiment, the access control rules include multiple access control lists; generating the file access permissions of the current file access operation under the access control rules according to multiple behavioral permissions includes:
[0089] Selection step: Select a target access control list from multiple access control lists; according to multiple behavioral permissions, detect the matching result of the behavioral permissions of the current file access operation under the target access control list; return to execute the selection step until all access control lists are selected as the target access control list, and obtain the file access result corresponding to the multiple behavioral permission matching results; generate file access permissions according to the result type of the file access result.
[0090] It should be noted that in the case where the access control rules include multiple access control lists, through multi-dimensional behavioral permission detection under the same access control rules to generate the file access permissions of the current file access operation under the access control rules, it is inevitable that there will be permission decision conflict problems. Among them, the permissions or conditions of multiple access control lists are different. Multiple access control lists can specifically be multiple blacklists, multiple whitelists, or multiple lists composed of blacklists and whitelists. It can be understood that, for the consideration of processing efficiency, in the case of permission decision conflict problems, sorting can be performed based on the priorities and list types of multiple access control lists. For example, if multiple black and white lists have different decision results for the same file operation, the allow decision made by the whitelist and the deny decision made by the blacklist will be adopted first. If other decision results (such as the deny decision made by the whitelist and the allow decision made by the blacklist) conflict, the decision result ranked higher will be adopted first to resolve the conflict.
[0091] As an example, the selection step: Select a target access control list from multiple access control lists; according to multiple behavioral permissions, detect the matching result of the behavioral permissions of the current file access operation under the target access control list; return to execute the selection step until all access control lists are selected as the target access control list, and obtain the file access result corresponding to the multiple behavioral permission matching results; generate file access permissions according to the result type of the file access result.
[0092] In an implementable manner, if the result type of the file access result is: an allow decision made by the whitelist or a deny decision made by the blacklist, the file access result is directly generated. If the file access result is not the above result type, after confirming that all access control lists are selected as the target access control list, the file access result is generated.
[0093] In this embodiment, for the complex access control scenario of multiple access control lists, this embodiment sequentially selects any one of the multiple access control lists as the target access control list, and for the sake of multiple behavioral authorities, detects the behavioral authority matching result of the current file access operation under the target access control list. Finally, after obtaining the file access result jointly corresponding to the multiple behavioral authority matching results, according to the result type of the file access result, the file access permission is generated, thereby realizing the comprehensive determination of the file access permission of the current file access operation under the access control rule from the first dimension of multiple access control rules and the second dimension of different behavioral authorities of the same access control rule. Therefore, the limitations of the bastion host file access control are further reduced and the control security of the bastion host file access control is improved.
[0094] In one embodiment, access control over the current file access operation is performed according to the file access permission, including:
[0095] When the file access permission is that the current file access operation has access permission, the behavioral anomaly value of the current file access operation is detected; if the behavioral anomaly value is greater than the preset behavioral benchmark value, access control over the current file access operation is performed according to the behavioral verification result of the current file access operation; if the behavioral anomaly value is less than or equal to the preset behavioral benchmark value, the current file access operation is allowed to be executed:
[0096] It should be noted that in combination with the entity behavior analysis technology, the bastion host can also establish a behavior baseline through in-depth analysis of daily user and device behaviors, and when the system detects abnormal behaviors deviating from the baseline, it can automatically adjust the access permission or trigger an alarm, thereby providing higher security and flexibility. This technology can not only identify threats not covered by conventional rules, but also improve the sensitivity and response speed of the system through the anomaly detection mechanism, and better protect the information security of enterprises. Among them, the behavioral anomaly detection for file access operations can be implemented based on the anomaly detection algorithm. For example, in an implementable manner, within a set observation period, the file operation behaviors of users can be continuously monitored and recorded, including information such as operation time, frequency, operation type, and operation source IP. Within the set observation period, an initial baseline of user behavior is established through the isolation forest algorithm, and the baseline is continuously improved after the observation period. This baseline is used to evaluate the behavioral anomaly value of the current file access operation. The workflow of the isolation forest algorithm can be as Figure 3Shown as follows: 1) Randomly select a subset from the dataset; 2) Construct a forest: 1. Randomly select a feature, 2. Randomly select a splitting point between the minimum and maximum values of this feature, 3. Divide the data into two parts according to the selected splitting point, 4. Recursively repeat this process for each part until the stopping condition is met.
[0097] It should be noted that the decision-making process of the decision-making module has been shown in the above example, and will not be elaborated in this embodiment. On the other hand, after the decision-making module decides that the black and white list allows the operation, anomaly detection will also be started to calculate the anomaly score for the allowed operation. For example, in an implementable manner, first calculate the average path length h(x) of the current file access operation in the isolation forest, using the following formula:
[0098]
[0099] Where, is the behavior anomaly value, c(n) is the normalization constant, E(h(x)) is the average path length. Furthermore, after calculating the behavior anomaly value of the current file access operation, based on the size relationship between the behavior anomaly value and the preset behavior reference value, the final access control result for the current file access operation is obtained. For example, assuming that the preset behavior reference value is 0.9, if the behavior anomaly value is 0.8, then the current file access operation is allowed to be executed; if the behavior anomaly value is 1, then the execution of the current file access operation is rejected.
[0100] As an example, when the file access permission is that the current file access operation has access permission, detect the average path length of the current file access operation in the isolation forest, and detect the behavior anomaly value of the current file access operation based on the average path length; if the behavior anomaly value is greater than the preset behavior reference value, conduct behavior verification on the current file access operation to obtain a behavior verification result, and perform access control on the current file access operation through the behavior verification result. Among them, the specific method of conducting behavior verification on the current file access operation can be to require the user to perform secondary verification by inputting a SMS verification code; if the behavior anomaly value is less than or equal to the preset behavior reference value, then allow the execution of the current access operation.
[0101] In an implementable manner, the bastion host file management system can also deploy an audit module to audit the access control process of file access operations. For example, the record result of the audit module can be: allowing a user to submit a request to delete the / data / public / 1.txt file from the IP address xxx.xxx.1.35 at 14:00:00 on June 15, 2024. This operation has a risk level of 4, is executed, has no abnormal detection record, and the execution result is successful. By deploying the audit module, audit information can be recorded, specifically including metadata, abnormal detection results, decision results, operation results, operation risk levels, etc. Through the audit module, each file operation can be detailedly recorded and analyzed, facilitating post-event traceability and security audit.
[0102] In this embodiment, through UEBA technology based on an anomaly detection algorithm, continuously learn and analyze the normal behavior patterns of file access operations, and establish a dynamic behavior baseline, so as to preset a preset behavior benchmark value in advance, enabling the bastion host file management system to identify abnormal behaviors deviating from the normal mode, thereby providing more accurate threat detection and risk assessment capabilities. That is, according to the magnitude relationship between the behavior anomaly value and the preset behavior benchmark value, determine whether to perform behavior verification on the current file access operation, and add a secondary verification mechanism when the security of the file access operation is not high, thereby maximizing the security of bastion host file control.
[0103] In an implementable manner, referring to Figure 4 , Figure 4 To represent the structural schematic diagram of the bastion host file management system, where the bastion host file management system includes a construction module, a sorting module, a decision module, and an audit module. The construction module can be used to construct an enhanced black and white list and establish an initial baseline of user behavior through the isolation forest algorithm. The sorting module can be used to sort the effective black and white list in descending order of risk level. The decision module can make black and white list decisions and calculate anomaly scores when operations are allowed. The audit module is used to record audit operation information and results.
[0104] In an implementable manner, referring to Figure 5 , Figure 5It is a control flow chart for representing the file access control of the bastion host. Among them, the to-be-decided file operation input can be understood as the current file access operation. The sourcelps list is used to represent the behavior object information, the paths list is used to represent the behavior path information, and the operations list is used to represent the behavior type information. After multi-level behavior permission detection, the selection steps are executed: Selection steps: Select the target access control list from multiple access control lists; According to multiple behavior permissions, detect the behavior permission matching result of the current file access operation under the target access control list; Return to execute the selection steps until all access control lists are selected as the target access control list, and obtain the file access result corresponding to the multiple behavior permission matching results; Generate file access permissions according to the result type of the file access result. When the file access permission is that the current file access operation has access permission, detect the behavior anomaly value of the current file access operation; If the behavior anomaly value is greater than the preset behavior benchmark value, perform access control on the current file access operation according to the behavior verification result of the current file access operation; If the behavior anomaly value is less than or equal to the preset behavior benchmark value, allow the current file access operation to be executed. Finally, the audit module detects the access control process in real time.
[0105] It can be understood that based on this embodiment, the following technical effects can be achieved: 1) Higher security and flexibility: Through the UEBA module, the system can identify and respond to threats not covered by conventional rules, dynamically adjust security policies, improve response speed and detection sensitivity. Provide user behavior pattern analysis to improve the system's ability to identify abnormal operations; 2) Fine-grained access control: Based on multi-dimensional metadata and risk levels, it allows precise control and sorting optimization of complex access rules, enhancing the adaptability and accuracy of rule management. Enabling a wide variety of operation requests to be appropriately satisfied under security guarantees.
[0106] It should be understood that although the steps in the flow charts involved in the above embodiments are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flow charts involved in the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or alternately with at least a part of other steps or steps or stages in other steps.
[0107] Based on the same inventive concept, an embodiment of the present application further provides a bastion host file access control device for implementing the above-mentioned bastion host file access control method. The implementation solution provided by this device for solving problems is similar to the implementation solution described in the above method. Therefore, the specific limitations in one or more embodiments of the bastion host file access control device provided below can refer to the limitations on the bastion host file access control method in the above text, and will not be repeated here.
[0108] In an exemplary embodiment, as Figure 6 shown, a bastion host file access control device is provided, including: a matching module 401, a determination module 402, and an access control module 403, where:
[0109] The matching module 401 is configured to match an access control rule that meets the access security standard for the current file access operation according to the attribute feature information carried by the current file access operation received by the bastion host;
[0110] The determination module 402 is configured to determine the file access permission of the current file access operation under the access control rule according to the behavior feature information carried by the current file access operation;
[0111] The access control module 403 is configured to perform access control on the current file access operation according to the file access permission.
[0112] In one of the embodiments, the attribute feature information includes operation time limit information; the matching module 401 is further configured to:
[0113] Construct a preset access control rule that meets the security access standard for each historical file access operation; screen multiple preset access control rules to obtain multiple candidate access control rules within the effective time period identified by the operation time limit information; extract the access control rule from the multiple candidate access control rules.
[0114] In one of the embodiments, the matching module 401 is further configured to:
[0115] Perform priority sorting on the multiple candidate access control rules according to the operation risk information of each historical file access operation to obtain a priority sorting result; extract the access control rule from the multiple candidate access control rules according to the priority sorting result.
[0116] In one of the embodiments, the behavior feature information includes behavior location information, behavior object information, and behavior type information; the determination module 402 is further configured to:
[0117] According to the behavior location information, the behavior object information, and the behavior type information, sequentially detect the behavior permissions of the current file access operation in the access control rules; generate the file access permissions of the current file access operation under the access control rules according to multiple behavior permissions.
[0118] In one embodiment, the access control rules include multiple access control lists; the access control module 403 is further configured to:
[0119] Selection step: Select a target access control list from the multiple access control lists; according to the multiple behavior permissions, detect the behavior permission matching result of the current file access operation under the target access control list; return to execute the selection step until all access control lists are selected as the target access control list, and obtain the file access result corresponding to the multiple behavior permission matching results; generate the file access permissions according to the result type of the file access result.
[0120] In one embodiment, the access control module 403 is further configured to:
[0121] When the file access permissions are that the current file access operation has access permissions, detect the behavior anomaly value of the current file access operation; if the behavior anomaly value is greater than the preset behavior reference value, perform access control on the current file access operation according to the behavior verification result of the current file access operation; if the behavior anomaly value is less than or equal to the preset behavior reference value, allow the current file access operation to be executed.
[0122] Each module in the above bastion host file access control device can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor in the computer device in hardware form or independent of it, or stored in the memory in the computer device in software form, so that the processor can call and execute the operations corresponding to the above modules.
[0123] In an exemplary embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as Figure 7As shown. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit, and an input device. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface, the display unit, and the input device are connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a mobile cellular network, NFC (Near Field Communication), or other technologies. The computer program, when executed by the processor, implements a method for controlling file access of a bastion host. Those skilled in the art can understand, Figure 7 The structure shown in is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0124] In one embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the above method embodiments are implemented.
[0125] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, the steps in the above method embodiments are implemented.
[0126] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by the processor, the steps in the above method embodiments are implemented.
[0127] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.
[0128] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.
[0129] The above-described embodiments merely represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. A method for file access control of a bastion host, characterized in that, The method includes: Based on the attribute feature information carried by the current file access operation received by the bastion host, matching an access control rule that complies with the access security standard for the current file access operation; Based on the behavior feature information carried by the current file access operation, determining the file access permission of the current file access operation under the access control rule; Performing access control on the current file access operation according to the file access permission; The behavior feature information includes behavior location information, behavior object information, and behavior type information; the determining the file access permission of the current file access operation under the access control rule according to the behavior feature information carried by the current file access operation includes: sequentially detecting the behavior permissions of the current file access operation under the access control rule according to the behavior location information, the behavior object information, and the behavior type information; generating the file access permission of the current file access operation under the access control rule according to multiple behavior permissions; The access control rule includes multiple access control lists; the generating the file access permission of the current file access operation under the access control rule according to multiple behavior permissions includes: a selection step: selecting a target access control list from the multiple access control lists; detecting the behavior permission matching result of the current file access operation under the target access control list according to the multiple behavior permissions; returning to execute the selection step until all access control lists are selected as the target access control list, obtaining a file access result commonly corresponding to multiple behavior permission matching results; generating the file access permission according to the result type of the file access result; The performing access control on the current file access operation according to the file access permission includes: when the file access permission is that the current file access operation has access permission, detecting the behavior anomaly value of the current file access operation; if the behavior anomaly value is greater than a preset behavior reference value, performing access control on the current file access operation according to the behavior verification result of the current file access operation; if the behavior anomaly value is less than or equal to the preset behavior reference value, allowing the current file access operation to be executed, where the behavior anomaly value is calculated using the following formula: ; wherein, is the behavior outlier value, is the normalization constant, is the average length of the current file access operation in the isolation forest.
2. The method according to claim 1, wherein The attribute feature information includes operation time limit information; the matching an access control rule that complies with the access security standard for the current file access operation based on the attribute feature information carried by the current file access operation received by the bastion host includes: Constructing a preset access control rule that complies with the access security standard for each historical file access operation; Filtering multiple preset access control rules to obtain multiple candidate access control rules located within the effective time period identified by the operation time limit information; Extracting the access control rule from the multiple candidate access control rules.
3. The method according to claim 2, wherein The extracting the access control rule from the multiple candidate access control rules includes: Prioritize the multiple candidate access control rules according to the operation risk information of each of the historical file access operations to obtain a prioritization result; Extract the access control rule from the multiple candidate access control rules according to the prioritization result.
4. A bastion host file access control device, characterized in that, The device includes: A matching module, configured to match an access control rule that meets the access security standard for the current file access operation according to the attribute feature information carried by the current file access operation received by the bastion host; A determination module, configured to determine the file access permission of the current file access operation under the access control rule according to the behavior feature information carried by the current file access operation; An access control module, configured to perform access control on the current file access operation according to the file access permission; The behavior feature information includes behavior location information, behavior object information, and behavior type information; determining the file access permission of the current file access operation under the access control rule according to the behavior feature information carried by the current file access operation includes: sequentially detecting the behavior permissions of the current file access operation under the access control rule according to the behavior location information, the behavior object information, and the behavior type information; generating the file access permission of the current file access operation under the access control rule according to multiple behavior permissions; The access control rule includes multiple access control lists; generating the file access permission of the current file access operation under the access control rule according to multiple behavior permissions includes: a selection step: selecting a target access control list from the multiple access control lists; detecting the behavior permission matching result of the current file access operation under the target access control list according to the multiple behavior permissions; returning to execute the selection step until all access control lists are selected as the target access control list to obtain a file access result commonly corresponding to multiple behavior permission matching results; generating the file access permission according to the result type of the file access result; Performing access control on the current file access operation according to the file access permission includes: when the file access permission is that the current file access operation has access permission, detecting the behavior anomaly value of the current file access operation; if the behavior anomaly value is greater than a preset behavior reference value, performing access control on the current file access operation according to the behavior verification result of the current file access operation; if the behavior anomaly value is less than or equal to the preset behavior reference value, allowing the current file access operation to be executed, where the behavior anomaly value is calculated using the following formula: ; Among them, is the behavioral outlier value, is the normalization constant, is the average length of the current file access operation in the isolation forest.
5. The device according to claim 4, wherein The attribute feature information includes operation timeliness information; matching an access control rule that meets the access security standard for the current file access operation according to the attribute feature information carried by the current file access operation received by the bastion host includes: Construct a preset access control rule that complies with the access security standard for each historical file access operation; screen multiple preset access control rules to obtain multiple candidate access control rules within the valid time period identified by the operation time limit information; extract the access control rule from the multiple candidate access control rules.
6. The device according to claim 5, characterized in that, The extracting the access control rule from the multiple candidate access control rules includes: According to the operation risk information of each historical file access operation, perform a priority ranking on the multiple candidate access control rules to obtain a priority ranking result; according to the priority ranking result, extract the access control rule from the multiple candidate access control rules.
7. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method described in any one of claims 1 to 3.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the method described in any one of claims 1 to 3.
9. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps of the method described in any one of claims 1 to 3.
Citation Information
Patent Citations
Equipment access permission control method and device and bastion host
CN109492376A