Security protection method and device for bastion host of sensor application and medium
By deploying a perception agent in the bastion host and using large model components for real-time analysis and dynamic policy adjustment, the problems of configuration complexity and insufficient internal defense capabilities of traditional bastion hosts are solved. This effectively blocks complex or disguised malicious operations and improves the security of enterprise operation and maintenance data.
Patent Information
- Application Number
- CN202511004020.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-21
- Publication Date
- 2025-11-18
AI Technical Summary
Traditional bastion hosts are complex to configure and manage and have limited ability to protect against internal personnel, making it difficult to effectively block complex or disguised malicious operations, leading to data security risks within enterprises.
Deploy a perception agent in the bastion host to perform initial authentication and virtual space creation. Combine the perception agent with large model components for re-authentication and behavior monitoring. Analyze user traffic and logs in real time and dynamically adjust security policies to block abnormal behavior.
It enables real-time monitoring and intelligent management of user behavior, and can promptly identify and block complex or disguised malicious operations, thereby improving the security protection capabilities of enterprise operation and maintenance data.
Smart Images

Figure CN120979694A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network operation and maintenance technology, and in particular to a method, device and medium for bastion host security protection of a sensing entity application. Background Technology
[0002] A bastion host, also known as a jump server or network operations auditing system, is a critical security control device in network operations and maintenance. It acts as the sole entry point and security audit gateway for operations and maintenance personnel to access internal network resources (such as servers, network devices, databases, etc.).
[0003] In a typical bastion host, operations and maintenance personnel connect to the bastion host via client software or a browser. The bastion host performs permission checks on the user's submitted operation requests based on preset security policies and user role information. Once the user's operation request passes the permission check, the bastion host proxies the user to the target device to complete the operation. The target device returns the operation result to the bastion host, which then returns the operation result to the operations and maintenance personnel. This method has the following drawbacks: 1. Complex configuration and management: Bastion hosts require complex configuration and management, including account management, access control, and security policy settings. Improper configuration may lead to security vulnerabilities or access problems.
[0004] 2. Limited protection against internal personnel: Bastion hosts primarily prevent unauthorized access and manipulation of the database by external personnel through authentication and authorization controls. However, their protection against authorized internal personnel is relatively weak. If internal personnel intentionally engage in malicious operations, the bastion host may not be able to prevent it in a timely and effective manner.
[0005] 3. Limitations in High-Risk Command Identification: While bastion hosts can monitor and record the operational behavior of maintenance personnel and block dangerous or unauthorized operations, their ability to identify high-risk commands remains limited. Complex or disguised malicious operations may be difficult for bastion hosts to detect and block in a timely manner. Summary of the Invention The purpose of this invention is to propose a bastion host system, device, and medium for sensing applications, which solves the technical problem that traditional bastion hosts cannot block complex or disguised malicious operations, leading to security risks to enterprise internal data.
[0006] Specifically, the present invention provides a bastion host security protection method for a sensing agent application, comprising the following steps: S1. Deploy the perception agent in the bastion host; S2. User information is input into the sensor, and the sensor obtains the policy component to perform preliminary authentication of the user information; S3. After initial authentication is passed, the sensor opens up the user's virtual space; S4. Re-authenticate based on user information in the virtual space. If authentication is successful, the user logs in to the bastion host successfully. S5. The perception entity calls the bastion host proxy component to allow users to access applications. S6. The sensor acquires user behavior; S7. If abnormal user behavior occurs, interrupt user access and update the policy component.
[0007] A storage medium that stores instructions and data for implementing a bastion host security protection method for a sensing agent application.
[0008] A bastion host security protection device for a perception application includes: a processor and a storage medium; the processor loads and executes instructions and data in the storage medium to implement a bastion host security protection method for a perception application.
[0009] The beneficial effects provided by this invention are: using the sensing entity as the operation and maintenance hub, opening up an isolated space for users, performing large-scale model analysis on real-time traffic, logs and external interface data, and deeply integrating the sensing entity with various components to achieve dynamic adjustment of security policies and real-time perception of security threats, enabling intelligent configuration and management, and achieving comprehensive security protection and threat perception of enterprise operation and maintenance data. Attached Figure Description
[0010] Figure 1 This is a schematic diagram of the method process of the present invention; Figure 2 This is a schematic diagram illustrating the principle of the method of the present invention; Figure 3 A schematic diagram of the hardware device operation according to an embodiment of the present invention. Detailed Implementation
[0011] To make the objectives, technical solutions, and advantages of the present invention clearer, the embodiments of the present invention will be further described below with reference to the accompanying drawings.
[0012] Before formally describing the present invention, a general description of the solution of the present invention will be given first to facilitate understanding.
[0013] Please refer to Figures 1-2 The present invention provides a bastion host security protection method for a sensing entity application, comprising:
[0014] S1. Deploy the perception agent in the bastion host; S2. User information is input into the sensor, and the sensor obtains the policy component to perform preliminary authentication of the user information; S3. After initial authentication is passed, the sensor opens up the user's virtual space; S4. Re-authenticate based on user information in the virtual space. If authentication is successful, the user logs in to the bastion host successfully. S5. The perception entity calls the bastion host proxy component to allow users to access applications. S6. The sensor acquires user behavior; S7. If abnormal user behavior occurs, interrupt user access and update the policy component.
[0015] It should be noted that the process after step S2 and before step S3 includes: S2A, storing user information in the virtual space. The user data includes: user traffic data, logs, and API information.
[0016] It should be noted that the re-authentication in step S4 is completed using the large model component of the perceptron.
[0017] It should be noted that multiple users can be included simultaneously, and multiple users can use different independent virtual spaces.
[0018] It should be noted that step S7 is as follows: S71. The sensor calls the audit component to audit user access behavior and obtain audit results; S72. The sensor synchronously acquires data from the application agent component and synchronously inputs it into the large model component; S73. If the audit results are abnormal or the application agent component data is abnormal, the perception entity will interrupt the connection between the user and the bastion host and update the user information to the policy component at the same time.
[0019] In one embodiment, the perception agent in this invention acts as an intermediary agent module between the data within the bastion host and the user. It serves as the intelligent decision-making hub and is essentially an AI agent with real-time learning and dynamic response capabilities. Its core functions include: Environmental awareness: Real-time collection of data such as user behavior, network traffic, logs, and API calls; Strategy execution: Invoke the strategy component / large model component to perform risk assessment; Dynamic isolation: Creates an independent virtual space (VM) for each user, enabling operation sandboxing; Collaborative control: Link audit components and proxy components to implement blocking or policy updates.
[0020] As one embodiment, the policy component is used to verify user information, specifically user account information. The user enters their account-related information through the bastion host's login page, and this information is first transmitted to the sensing entity in this invention.
[0021] The policy component's review mechanism for user account information includes: 1. Static policy matching: Verifies account permission validity period, IP whitelist, etc.; 2. Dynamic risk assessment: Compare login time / geographical location for anomalies, etc.; 3. Threat intelligence linkage: Check whether the device is associated with a known malicious IP database (pass / reject / requires secondary authentication, etc.); Alternatively, the following mechanisms can also be used, such as: Context-aware authentication: If a user logs in from an unfamiliar location, trigger an SMS verification code or biometric authentication. Behavioral baseline comparison: Compare the user's historical login patterns (such as input speed and operating habits).
[0022] As one embodiment, the large model component is used for analysis in two phases: the re-authentication phase in step S4 and the application proxy phase in step S7. The input data for its analysis includes: user traffic stored in the virtual space (such as protocol type, port access frequency, etc.), logs (such as historical operation instructions, number of errors, etc.), and API information (such as sensitive interfaces called, frequency, etc.).
[0023] The re-authentication phase in step S4 includes anomaly detection, intent identification, and security determination. Specifically: Anomaly detection includes temporal analysis and semantic analysis. Temporal analysis refers to detecting sensitive ports that are frequently accessed within a short period of time after login. Semantic analysis refers to parsing whether the user's API parameters contain sensitive paths, such as / etc / passwd.
[0024] Intent identification includes using NLP models to identify the potential malicious intent of operation commands in logs, such as disguising rm -rf / * as a backup script.sh.
[0025] Security determination is a comprehensive assessment of anomaly detection results and intent recognition results. If either anomaly detection result or intent recognition result has a problem, such as a user frequently accessing sensitive ports or having potential malicious intent, then re-authentication will fail.
[0026] The analysis of the large model components in the application agent stage of step S6 includes the application agent component data such as real-time traffic / command flow / file transfer records during the application agent period.
[0027] Correspondingly, its analysis strategy differs slightly from that of the re-authentication stage. For example, it uses window functions to detect sudden high-risk operation sequences in real-time traffic, or it associates the current operation with the data from the login stage (such as directly accessing the core database after login). The specific analysis strategy is mainly reflected in real-time performance.
[0028] As one example, the auditing component is used to audit user access behavior. Traditional bastion host auditing often passively records operation logs, relies on regular expression rules to match high-risk commands, and the auditing is delayed (post-event tracing).
[0029] The audit component in this invention employs proactive behavior modeling and dynamic baseline comparison. Specifically, the process is as follows: Establish baselines for individual user behavior (such as frequently used command sets and access periods), and use GANs to generate adversarial examples to train an anomaly detection model; User operation commands are vectorized and embedded, and then input into the anomaly detection model. The anomaly detection model compares the deviation value with the baseline value. If the deviation value exceeds the preset value, an alarm is generated. Furthermore, if privilege escalation or data leakage is detected, the session is immediately frozen and the forensic image is preserved and updated to the policy component.
[0030] Please see Figure 3 , Figure 3 This is a schematic diagram of the hardware device in operation according to an embodiment of the present invention. The hardware device specifically includes: a bastion host security protection device 401 for a sensing agent application, a processor 402, and a storage medium 403.
[0031] A bastion host security protection device 401 for a sensing agent application: The bastion host security protection device 401 for a sensing agent application implements the bastion host security protection method for a sensing agent application.
[0032] Processor 402: The processor 402 loads and executes the instructions and data in the storage medium 403 to implement the bastion host security protection method for the sensor application.
[0033] Storage medium 403: The storage medium 403 stores instructions and data; the storage medium 403 is used to implement the bastion host security protection method of the sensing entity application.
[0034] The beneficial effects of this invention are: using the sensing entity as the operation and maintenance hub, opening up an isolated space for users, performing large-scale model analysis on real-time traffic, logs, and external interface data, and deeply integrating the sensing entity with various components to achieve dynamic adjustment of security policies and real-time perception of security threats, enabling intelligent configuration and management, and achieving comprehensive security protection and threat perception of enterprise operation and maintenance data.
[0035] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A bastion host security protection method for a sensing agent application, characterized in that: Includes the following steps: S1. Deploy the perception agent in the bastion host; S2. User information is input into the sensor, and the sensor obtains the policy component to perform preliminary authentication of the user information; S3. After initial authentication is passed, the sensor opens up the user's virtual space; S4. Re-authenticate based on user information in the virtual space. If authentication is successful, the user logs in to the bastion host successfully. S5. The perception entity calls the bastion host proxy component to allow users to access applications. S6. The sensor acquires user behavior; S7. If abnormal user behavior occurs, interrupt user access and update the policy component.
2. The bastion host security protection method for a sensing agent application as described in claim 1, characterized in that: After step S2 and before step S3, the following steps are also included: S2A, storing user information in virtual space.
3. The bastion host security protection method for a sensing agent application as described in claim 2, characterized in that: The user data includes: user traffic data, logs, and API information.
4. The bastion host security protection method for a sensing agent application as described in claim 1, characterized in that: The re-authentication in step S4 is completed using a large model component of the perceptron.
5. The bastion host security protection method for a sensing agent application as described in claim 1, characterized in that: Users can include multiple users simultaneously, with each user using a different independent virtual space.
6. The bastion host security protection method for a sensing agent application as described in claim 4, characterized in that: Step S7 is as follows: S71. The sensor calls the audit component to audit user access behavior and obtain audit results; S72. The sensor synchronously acquires data from the application agent component and synchronously inputs it into the large model component; S73. If the audit results are abnormal or the application agent component data is abnormal, the perception entity will interrupt the connection between the user and the bastion host and update the user information to the policy component at the same time.
7. A storage medium, characterized in that: The storage medium stores instructions and data to implement a bastion host security protection method for a sensing entity application as described in any one of claims 1 to 6.
8. A bastion host security protection device for a sensing agent application, characterized in that: include: A processor and a storage medium; the processor loads and executes instructions and data in the storage medium to implement a bastion host security protection method for a sensing agent application as described in any one of claims 1 to 6.