Bastion host file access control method and apparatus, computer device, medium, and product

WO2026200079A1PCT designated stage Publication Date: 2026-10-01CHINA TELECOM CLOUD TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/142475
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-26
Filing Date
2025-12-15
Publication Date
2026-10-01

Smart Images

  • Figure CN2025142475_01102026_PF_FP_ABST
    Figure CN2025142475_01102026_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to a bastion host file access control method and apparatus, a computer device, a medium, and a product. The method comprises: on the basis of attribute feature information carried by a current file access operation received by a bastion host, matching to the current file access operation an access control rule conforming to an access security standard; on the basis of behavior feature information carried by the current file access operation, determining a file access permission of the current file access operation under the access control rule; and, on the basis of the file access permission, performing access control on the current file access operation.
Need to check novelty before this filing date? Find Prior Art

Description

Bastion host file access control methods, devices, computer equipment, media and products

[0001] Related applications

[0002] This application claims priority to Chinese patent application filed on March 26, 2025, with application number CN202510364699.8, entitled "Bastion Host File Access Control Method, Apparatus, Computer Equipment, Media and Product", the entire contents of which are incorporated herein by reference. Technical Field

[0003] This application relates to the field of information security technology, and in particular to a bastion host file access control method, apparatus, computer equipment, computer-readable storage medium, and computer program product. Background Technology

[0004] With the continuous development of technology, enterprise internal file management and access control have faced unprecedented challenges, which has led to the increasingly widespread application of bastion hosts. As a permission management and auditing system based on cloud computing and network security technologies, bastion hosts provide a secure and reliable remote access and management method by centrally managing and controlling user access permissions, and have become an indispensable security component for enterprises.

[0005] Currently, file access control on bastion hosts typically uses blacklists or whitelists to evaluate file access operations and ensure they meet security standards. However, because the contents of blacklists or whitelists are relatively fixed, the file access control mechanism cannot meet the security assessment requirements of complex scenarios, which can easily lead to access control errors. Therefore, current file access control on bastion hosts has significant limitations. Summary of the Invention

[0006] Therefore, it is necessary to provide a bastion host file access control method, apparatus, computer equipment, computer-readable storage medium, and computer program product that reduces the limitations of bastion host file access control in response to the above-mentioned technical problems.

[0007] Firstly, this application provides a bastion host file access control method, including:

[0008] Based on the attribute feature information carried by the current file access operation received by the bastion host, access control rules that conform to access security standards are matched for the current file access operation;

[0009] Based on the behavioral characteristic information carried by the current file access operation, determine the file access permissions of the current file access operation under the access control rules;

[0010] Access control is performed on the current file access operation based on the file access permissions.

[0011] Secondly, this application also provides a bastion host file access control method apparatus, comprising:

[0012] The matching module is used to match access control rules that conform to access security standards for the current file access operation based on the attribute feature information carried by the current file access operation received by the bastion host.

[0013] The determination module is used to determine the file access permissions of the current file access operation under the access control rules based on the behavioral feature information carried by the current file access operation;

[0014] The access control module performs access control on the current file access operation based on the file access permissions.

[0015] Thirdly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:

[0016] Based on the attribute feature information carried by the current file access operation received by the bastion host, access control rules conforming to access security standards are matched for the current file access operation; based on the behavioral feature information carried by the current file access operation, the file access permissions of the current file access operation under the access control rules are determined; and access control is performed on the current file access operation based on the file access permissions.

[0017] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, performs the following steps:

[0018] Based on the attribute feature information carried by the current file access operation received by the bastion host, access control rules conforming to access security standards are matched for the current file access operation; based on the behavioral feature information carried by the current file access operation, the file access permissions of the current file access operation under the access control rules are determined; and access control is performed on the current file access operation based on the file access permissions.

[0019] Fifthly, this application also provides a computer program product, including a computer program that, when executed by a processor, performs the following steps:

[0020] Based on the attribute feature information carried by the current file access operation received by the bastion host, access control rules conforming to access security standards are matched for the current file access operation; based on the behavioral feature information carried by the current file access operation, the file access permissions of the current file access operation under the access control rules are determined; and access control is performed on the current file access operation based on the file access permissions.

[0021] The aforementioned bastion host file access control method, device, computer equipment, computer-readable storage medium, and computer program product, firstly, after the bastion host receives a current file access operation, match access control rules conforming to access security standards to the current file access operation based on the attribute feature information carried by the current file access operation. This dynamically matches access control rules conforming to access security standards based on the specific attribute features of the current file access operation. Then, based on the behavioral feature information carried by the current file access operation, it determines the file access permissions of the current file access operation under the access control rules. This achieves the goal of determining the specific access permissions of the current file access operation to the bastion host based on the behavioral features of the current file access operation, and ultimately performs access control on the current file access operation through file access permissions. Since the file access permissions of the current file access operation are... The file access operation's attribute and behavioral characteristics are flexibly determined through the combined effect of these characteristics. This allows for dynamic setting of specific access permissions that conform to security standards, relying on multi-dimensional features of the current file access operation during bastion host file access control. This enables file access permissions to adapt to the security assessment needs of complex scenarios. Ultimately, access control is based on file access permissions, rather than relying solely on a single-dimensional blacklist or whitelist mechanism. Therefore, it overcomes the technical shortcomings of blacklists or whitelists, which, due to their relatively fixed content, cannot match the security assessment needs of complex scenarios, leading to access control errors. Thus, it reduces the limitations of bastion host file access control. Attached Figure Description

[0022] To more clearly illustrate the technical solutions in the embodiments of this application or the conventional technology, the drawings used in the description of the embodiments or the conventional technology will be briefly introduced below. Obviously, the drawings described below are only embodiments of this application. For those skilled in the art, other drawings can be obtained based on the disclosed drawings without creative effort.

[0023] Figure 1 is a flowchart illustrating a bastion host file access control method in one embodiment;

[0024] Figure 2 is a flowchart illustrating the bastion host file access control method in another embodiment;

[0025] Figure 3 is a flowchart of the isolated forest algorithm of the bastion host file access control method in another embodiment;

[0026] Figure 4 is a schematic diagram of the structure of the bastion host file management system of the bastion host file access control method in one embodiment;

[0027] Figure 5 is a control flowchart of the bastion host file access control method in another embodiment;

[0028] Figure 6 is a structural block diagram of the bastion host file access control device;

[0029] Figure 7 is an internal structure diagram of a computer device in one embodiment. Detailed Implementation

[0030] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0031] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0032] First, it should be understood that with the rapid development of information technology and the deepening of digital transformation, enterprise file management and access control are facing unprecedented challenges. On the one hand, frequent network attacks and data breaches pose significant risks to enterprise information security. On the other hand, internal access needs are becoming increasingly complex, and traditional access control mechanisms are no longer sufficient to meet the high control requirements of current complex scenarios. In the process of bastion host file access control, traditional access control mechanisms typically control file access operations through blacklists or whitelists. For example, blacklists and whitelists in a single dimension are typically as follows: 1) A blacklist denies access to a specific file while allowing access to other files; 2) A whitelist allows access to a specific file while denying access to other files. However, the above access control mechanisms have certain limitations in file access control. Currently, bastion host file access control relies primarily on single-dimensional blacklist or whitelist mechanisms, lacking fine-grained control over access behavior and risk assessment, as well as in-depth analysis of user behavior patterns. This is particularly problematic when dealing with complex access rules, risk assessments, and operational auditing, making it difficult to meet increasingly complex security needs. For example, it's difficult to implement file deletion operations on specific directories for file access operations under a particular IP address, while simultaneously denying other file operations outside of that IP address and directory, such as uploads and downloads. In other words, because the contents of blacklists or whitelists are relatively fixed, file access control mechanisms cannot match the security assessment requirements of complex scenarios, leading to frequent access control errors. Therefore, there is an urgent need for a bastion host file access control method that reduces the limitations of traditional bastion host file access control.

[0033] In one embodiment, as shown in Figure 1, a bastion host file access control method is provided. This embodiment uses the method applied to a terminal as an example. The terminal is equipped with a bastion host file management system. The terminal includes, but is not limited to, personal computers, laptops, smartphones, and tablets. The bastion host file management system includes a matching module, a determining module, and an access control module. The matching module is used to match access control rules that conform to access security standards for the current file access operation based on the attribute feature information carried by the current file access operation received by the bastion host. The determining module is used to determine the file access permissions of the current file access operation under the access control rules based on the behavioral feature information carried by the current file access operation. The access control module is used to perform access control on the current file access operation according to the file access permissions. The information interaction between the configuration module and the access control module relies on the multi-dimensional attribute characteristics of the current file access operation. This dynamically sets specific access permissions that conform to security access standards for the current file access operation, enabling access control to be completed within the constraints of file access permissions that adapt to the security assessment needs of complex scenarios. This overcomes the technical shortcomings of access control mechanisms that cannot match the security assessment needs of complex scenarios due to the relatively fixed content of blacklists or whitelists, thus easily leading to access control errors. Therefore, it reduces the limitations of bastion host file access control. This method can also be applied to servers and systems including terminals and servers, and is implemented through the interaction between terminals and servers. In this embodiment, the method includes steps 202 to 206. Wherein:

[0034] Step 202: Based on the attribute feature information carried by the current file access operation received by the bastion host, match the current file access operation with access control rules that conform to access security standards.

[0035] It should be noted that the following are explanations of relevant technical terms in the bastion host file access control process: 1) Bastion Host: A permission management and auditing system based on cloud computing and network security technologies. It provides a secure and reliable remote access and management method by centrally managing and controlling user access permissions, and can audit and record user operations; 2) User and Entity Behavior Analytics (UEBA): A network security technology designed to detect abnormal activity and potential threats by analyzing the behavioral patterns of users and entities. UEBA technology typically uses anomaly detection algorithms to establish behavioral baselines for users and entities and monitor their activities in real time. By identifying abnormal patterns that deviate from normal behavior, it can effectively detect abnormal events; 3) SSH File Transfer Protocol (SFTP): A secure file transfer protocol that runs on top of the SSH protocol. It uses encryption and password hash functions to protect data integrity and authenticates both the server and the user, providing secure, reliable, and easily configurable file transfer functionality; 4) File Transfer Protocol (SFTP) FTP (File Transfer Protocol): This is a communication protocol used to transfer files between remote devices and servers on local LANs or wide area networks (WANs). It facilitates the transfer of files from one computer to another by providing access to directories or folders on remote computers, and allows the transfer of software, data, or text files between different types of computers. It is understandable that in the process of implementing bastion host file access control, if there are problems such as handling complex access rules, risk assessment, and operation auditing, the above technologies or environments can be used in combination.

[0036] It should be noted that the current file access operation is for accessing the bastion host, that is, accessing the bastion host's file management system. This can be understood as the bastion host acting as an intermediary management point; accessing the bastion host's file management system essentially means accessing files on other systems or servers through the bastion host. Specifically, this can be done by running scripts or command lines on the bastion host to upload or delete specified files on a remote server. For example, in one feasible implementation, the current file access operation is initiated by device A, and the bastion host, acting as an intermediary, receives the current file access operation. If access is permitted, the current file access operation deletes the file on device B. Here, A and B are different devices.

[0037] It should be noted that attribute feature information is used to characterize the attribute features of the current file access operation. Specifically, it can include the operation effective time, operation expiration time, and operation risk level. Among them, the operation effective time refers to the specific time when the current file access operation begins to take effect, the operation expiration time refers to the specific time when the current file access operation ends to take effect, and the operation risk level refers to the specific risk level of the current file access operation. For example, in one feasible method, if the attribute feature information carries the field "1", it means that the operation risk level of the current file access operation is level 1; if the attribute feature information carries the field "2", it means that the operation risk level of the current file access operation is level 2; and if the attribute feature information carries the field "3", it means that the operation risk level of the current file access operation is level 3. The higher the operation risk level, the higher the risk of the file access operation.

[0038] It should be noted that access control rules are used to characterize the permissions and conditions for file access through the bastion host. Specifically, they can be used to allow a specified IP address to delete files in a specific file directory. It can be understood that if the current file access operation is restricted by the access control rules, then the access control process of the bastion host files is in compliance with security standards. It can also be understood that access control rules can be generated on the spot or set in advance, and can be retrieved by indexing the attribute characteristics of the current file access operation.

[0039] As an example, step 202 includes: extracting attribute feature information from the current file access operation received by the bastion host, and using the attribute feature information as an index to match access control rules that conform to security standards for the current file access operation.

[0040] Step 204: Determine the file access permissions under the access control rules for the current file access operation based on the behavioral characteristic information carried by the current file access operation.

[0041] It should be noted that behavioral characteristic information is used to characterize the operation behavior of the current file access operation. Specifically, it can include the operation source address, operation path, and operation type. The operation source address refers to the IP address of the device initiating the current file access operation, which can be xxx.xxx.x.xx. The operation path refers to the specific address to be accessed by the current file access operation, which can be / data / public / 1.txt. The operation type refers to the method of the current file access operation, which can be read, write, delete, or append. It can be understood that to achieve fine-grained control over file operations, multiple file access permissions can be set in the access control rules. Then, during the bastion host's file access control process, the appropriate specific file access permissions can be flexibly determined and applied according to the specific behavioral characteristics of each file access operation. File access permissions refer to the detailed permission regulations for file access through the bastion host. For example, file access permissions can reveal which users or roles can read, write, execute, or delete files.

[0042] As an example, step 204 includes: extracting behavioral feature information from the current file access operation, and using the preset file access permissions in the access control rules that match the behavioral feature information as the file access permissions for the current file access operation.

[0043] It is understandable that multiple preset file access permissions can be set in the access control rules. Each preset file access permission has a behavioral baseline feature. Then, by comparing the behavioral feature of the current file access operation with multiple behavioral baseline features, and if the behavioral feature and the behavioral baseline feature match, the preset file access permission corresponding to the behavioral baseline feature is used as the file access permission of the current file access operation.

[0044] Step 206: Perform access control on the current file access operation based on file access permissions.

[0045] It should be noted that file access permissions can be used to determine whether the current file access operation is allowed.

[0046] As an example, step 206 includes: performing the current file access operation under the file access permissions, or denying the current file access operation based on the file access permissions.

[0047] In the aforementioned bastion host file access control method, after the bastion host receives a current file access operation, it first matches access control rules conforming to access security standards to the current file access operation based on the attribute feature information carried by the current file access operation. This dynamically matches access control rules conforming to access security standards based on the specific attribute features of the current file access operation. Then, based on the behavioral feature information carried by the current file access operation, it determines the file access permissions of the current file access operation under the access control rules. This achieves the goal of determining the specific access permissions of the current file access operation to the bastion host based on its behavioral features. Finally, access control is performed on the current file access operation through the file access permissions. Since the file access permissions of the current file access operation are based on the attribute feature information of the current file access operation... The access control mechanism is flexibly determined through the combined effect of behavioral feature information. This allows for dynamic setting of specific access permissions that conform to security access standards, relying on multi-dimensional feature information of the current file access operation. This enables file access permissions to be adapted to the security assessment needs of complex scenarios. Ultimately, access control for the current file access operation is completed based on file access permissions, rather than relying solely on a single-dimensional blacklist or whitelist mechanism. Therefore, it overcomes the technical shortcomings of blacklists or whitelists, which, due to their relatively fixed content, cannot match the security assessment needs of complex scenarios, leading to access control errors. Thus, it reduces the limitations of bastion host file access control.

[0048] In one embodiment, as shown in Figure 2, the attribute feature information includes operation timeliness information; based on the attribute feature information carried by the current file access operation received by the bastion host, access control rules conforming to access security standards are matched for the current file access operation, including:

[0049] Step 302: Build a preset access control rule that conforms to the security access standard for each historical file access operation.

[0050] It should be noted that, to improve the efficiency of file access control on the bastion host, a build module can be deployed in the bastion host file management system. This build module can construct multiple preset access control rules. For example, in one feasible approach, any preset access control rule can be understood as a blacklist or whitelist constructed by the build module. The blacklist can be called an enhanced blacklist, and the whitelist an enhanced whitelist. During the construction of the enhanced blacklist or enhanced whitelist, the operation characteristic information of historical file access operations can be referenced. This operation characteristic information includes operation timeliness information and operation information. Furthermore, by analyzing the operation path, operation type, operation risk level, operation source IP, operation effective time, and operation expiration time of historical file access operations, it can be understood that the operation characteristic information of file access operations can also be called metadata. Through the aforementioned operation characteristic information of historical file access operations, more granular access control can be performed on each historical file access operation. Multiple historical file access operations can be statistically analyzed within the same observation period. Specifically, the operation characteristic information of historical file operations can be described in Table 1, as shown below:

[0051] During the set observation period, the system can continuously monitor and record users' file operation behavior, including information such as operation time, frequency, operation type, and operation source IP. Based on the operation characteristics of different historical file access operations, multiple preset control rules that comply with security access standards can be constructed.

[0052] As an example, step 302 includes: obtaining multiple operation feature information for each historical file access operation, generating preset access control rules that conform to access security standards for each historical file access operation based on the multiple operation feature information, and obtaining multiple preset access control rules.

[0053] Step 304: Filter multiple preset access control rules to obtain multiple candidate access control rules located within the valid time period of the operation time information identifier.

[0054] It should be noted that candidate access control rules are used to characterize access control rules that are waiting to be used as the current file access operation. It can be understood that since the construction of multiple preset access control rules is carried out by refining the operation feature information of historical file access operations, the selection of multiple preset access control rules can be completed by the time consistency between the effective time period of the current file access operation identified by multiple preset access control rules and operation failure information.

[0055] As an example, step 304 includes: extracting the preset valid time periods corresponding to each of the multiple preset access control rules, selecting the access valid time period from the multiple preset valid time periods according to the valid time period identified by the operation failure information, and using the preset access control rule to which the access valid time period belongs as a candidate access control rule.

[0056] Step 306: Extract access control rules from multiple candidate access control rules.

[0057] It should be noted that, based on the access control precision of the bastion host file management system for the current file access operation, any candidate access control rule from multiple candidate access control rules can be extracted as the access control rule. The candidate access control rules include allow access control rules and deny access control rules. Allow access control rules correspond to whitelists, and deny access control rules correspond to blacklists. For example, in one implementable method, one allow access control rule and one deny access control rule can be randomly selected from multiple candidate access control rules as the access control rules.

[0058] As an example, step 306 includes: randomly selecting one allow access control rule and one deny access control rule from multiple candidate access control rules as access control rules.

[0059] In one feasible approach, it is assumed that the constructed enhanced blacklist and whitelist include: 1) Blacklist 1: (1) Deny access to the bastion host file management system from IP address xxx.xxx.1.100 or xxx.xxx.1.1-xxx.xxx.1.20 or xx.0.0.0 / xx, and refuse to perform upload and delete operations on path / data / secure or / file / *.txt between June 1, 2024 and June 9, 2024. The risk level of this operation is 5, and its operation characteristics are as follows: 1. Type: Blacklist; 2. File operation path: / data / secure, / file / *.txt; 3. File operation type: upload, delete; 4. Operation risk level: 5; 5. Operation source IP: 192.168.1.100, xxx.xxx.1.1-xxx.xxx.1.20, xx.0.0.0 / xx; 6. Effective time: 2024-06-01 00:00:00; 7. Expiration time: 2024-06-09 23:59:59; 2) Whitelist 1: (2) Allows users to log in to the bastion host file management system from IP address xxx.xxx.1.30-xxx.xxx.1.50, and to perform upload, download and delete operations on the path / data / public from June 10, 2024 to June 30, 2024. The risk level of this operation is 4. The operation characteristics are as follows: 1. Type: Whitelist; 2. File operation path: / data / public; 3. File operation type: upload, download, delete; 4. Operation risk level: 4; 5. Operation source IP: xxx.xxx.1.30-xxx.xxx.1.50; 6. Effective time: 2024-06-10 00:00:00; 7. Expiration time: 2024-06-30 23:59:59; 3) Blacklist 2, (2) Allows users to log in to the bastion host file management system from IP address xxx.xxx.1.30-xxx.xxx.1.50, and to perform upload, download and delete operations on the path / data / public between June 10, 2024 and June 30, 2024. The risk level of this operation is 4.The configuration is as follows: 1. Type: Whitelist; 2. File operation path: / data / public; 3. File operation type: upload, download, delete; 4. Operation risk level: 4; 5. Operation source IP: xxx.xxx.1.30-xxx.xxx.1.50; 6. Effective time: 2024-06-10 00:00:00; 7. Expiration time: 2024-06-30 23:59:59; The filtering results of the enhanced blacklist and whitelist can be illustrated as follows: 1) Assuming the effective period of the operation validity information identifier is between 2024-06-01 00:00:00 and 2024-06-09 23:59:59, since whitelist 1 has not yet expired, it will not be used as an access control rule; 2) Assuming the effective period of the operation validity information identifier is between 2024-06-10 3) Assuming the effective period of the operation validity information identifier is between 00:00:00 on 2024-06-20 and 23:59:59, blacklist 1 will not be used as an access control rule because it expires, while whitelist 1 will be used as an access control rule because it expires.

[0060] In this embodiment, during the process of matching access control rules for the current file access operation, multiple preset access control rules conforming to security access standards are first constructed based on the construction module. Then, the effective time period identified by the operation failure information is used to filter among the multiple preset access control rules. Finally, access control rules are flexibly extracted from the multiple preset access control rules based on the access control requirement level. This allows for more refined access control levels to match access control rules conforming to security access standards for the current file access operation. Therefore, while reducing the limitations of bastion host file access control, it lays the foundation for improving the accuracy of bastion host file access control.

[0061] In one embodiment, extracting access control rules from multiple candidate access control rules includes:

[0062] Based on the operational risk information of each historical file access operation, multiple candidate access control rules are prioritized to obtain a priority ranking result; based on the priority ranking result, access control rules are extracted from the multiple candidate access control rules.

[0063] It should be noted that since different candidate access control rules provide different access permissions, multiple candidate access control rules can be sorted to avoid access control conflicts. For example, in one feasible approach, the sorting module of the bastion host file management system extracts the operation risk information of blacklists and whitelists during the sorting process to determine the operation risk level of each historical file access operation, and ranks the blacklists and whitelists with higher risk levels first. Understandably, if the same operation risk level occurs, the system will prioritize processing the whitelist to reduce processing load. At the same time, the sorting module dynamically manages the effective blacklists and whitelists based on the effective and expiration times of historical file access operations, removing expired blacklists and whitelists and adding effective blacklists and whitelists to ensure that only blacklists and whitelists within their validity period are effective. That is, the preset access control rules have been filtered through operation validity information to obtain access control rules within their validity period. Finally, the sorting module will output the effective blacklists and whitelists sorted from high to low risk levels, so that the bastion host file management system can extract one or more blacklists and whitelists to be finally input into the decision module of the bastion host file management system based on the effective blacklists and whitelists sorted from high to low.

[0064] As an example, multiple candidate access control rules are sorted once according to the operation risk level corresponding to the operation risk information of each historical file access operation, resulting in a first sorting result. If a first target access control rule and a second target access control rule with the same risk level are detected in the first sorting result, then the first target access control rule and the second target access control rule are sorted a second time according to the rule identifiers corresponding to their respective rules, resulting in a second sorting result. This second sorting result is used as the priority ranking result for multiple candidate access control rules. If a first target access control rule and a second target access control rule with the same risk level are not detected in the first sorting result, then the first sorting result is used as the priority ranking result. Here, the first target access control rule and the second target access control rule are different candidate access control rules.

[0065] In this embodiment, during the process of extracting access control rules from candidate access control rules, the operation risk information of each historical file access operation is first used to prioritize multiple candidate access control rules to obtain a priority ranking result. Finally, access control rules are extracted from multiple candidate access control rules according to the priority ranking result, thereby assigning different priorities to multiple candidate access control rules. Thus, when matching access control rules, the priority of the rules can be used to avoid decision conflicts when using access control rules to make subsequent access control decisions. Therefore, this lays the foundation for improving the control accuracy of bastion host file access control.

[0066] In one embodiment, the behavioral characteristic information includes behavioral location information, behavioral object information, and behavioral type information; based on the behavioral characteristic information carried by the current file access operation, determining the file access permissions of the current file access operation under the access control rules includes:

[0067] Based on the behavior location information, behavior object information, and behavior type information, the behavior permissions of the current file access operation under the access control rules are checked sequentially; based on multiple behavior permissions, the file access permissions of the current file access operation under the access control rules are generated.

[0068] It should be noted that, in determining file access permissions for the current file access operation, to improve the granularity of access control, multi-level behavioral feature information can be set to determine the behavioral permissions of the current file access operation. For example, in one feasible approach, the behavioral location information can be the operation path, the behavioral object information can be the operation source IP address, and the behavioral type information can specifically be the operation type. Therefore, the workflow of the decision module of the bastion host file management system can be as follows: The decision module first assumes that the multiple access control rules obtained (all valid blacklists and whitelists) are within the valid time period identified by the current file access operation. Then, it determines whether file operations from that source IP are allowed based on the sourceIps in the blacklist and whitelist. Next, it matches the file operation path based on the paths in the blacklist and whitelist to determine whether file operations under that path are allowed. Then, it matches the file operation type based on the operations in the blacklist and whitelist to determine whether file operations of that type are allowed. In other words, the blacklist denies the operation, and the whitelist allows the operation.

[0069] As an example, based on the behavior location information, the first behavior permission of the current file access operation under the access control rule is detected; based on the behavior object information, the second behavior permission of the current file access operation under the access control rule is detected; based on the behavior type information, the third behavior permission of the current file access operation under the access control rule is detected; by integrating the first behavior permission, the second behavior permission, and the third behavior permission, the file access permission of the current file access operation under the access control rule is obtained.

[0070] In this embodiment, multi-level detection of the behavior permissions of the current file access operation under the access control rules is performed by using behavioral feature information from multiple dimensions. Relying on multiple different behavior permissions that conform to the access control rules, the file access permissions of the current file access operation under the access control rules are completed. This ensures that the current file access operation still meets the security access standards in a more refined security assessment dimension. Therefore, it lays the foundation for improving the control security of bastion host file access control and reducing the control limitations of bastion host file access control.

[0071] In one embodiment, the access control rule includes multiple access control lists; based on multiple behavioral permissions, it generates file access permissions for the current file access operation under the access control rule, including:

[0072] Selection steps: Select the target access control list from multiple access control lists; based on multiple behavior permissions, check the behavior permission matching results of the current file access operation under the target access control list; return to execute the selection steps until all access control lists are selected as the target access control list, and obtain the file access result corresponding to the multiple behavior permission matching results; generate file access permissions based on the result type of the file access result.

[0073] It should be noted that when access control rules include multiple access control lists, generating file access permissions for the current file access operation under the access control rule through multi-dimensional behavioral permission detection under the same access control rule inevitably leads to permission decision conflicts. These multiple access control lists may have different permissions or conditions, specifically multiple blacklists, multiple whitelists, or combinations of blacklists and whitelists. Understandably, for processing efficiency, in the event of permission decision conflicts, the multiple access control lists can be sorted based on their priority and list type. For example, if multiple blacklists and whitelists have different decisions for the same file operation, the allow decision from the whitelist and the deny decision from the blacklist will be prioritized. If other decisions (such as the deny decision from the whitelist and the allow decision from the blacklist) conflict, the decision that appears earlier in the list will be prioritized to resolve the conflict.

[0074] As an example, the selection steps are as follows: Select the target access control list from multiple access control lists; based on multiple behavior permissions, check the behavior permission matching results of the current file access operation under the target access control list; return to execute the selection steps until all access control lists are selected as the target access control list, and obtain the file access result corresponding to the multiple behavior permission matching results; generate file access permissions based on the result type of the file access result.

[0075] In one feasible approach, if the file access result is of the type of allow decision made by a whitelist or deny decision made by a blacklist, then the file access result is generated directly; if the file access result is not of the above type, then the file access result is generated after confirming that all access control lists have been selected as the target access control lists.

[0076] In this embodiment, for complex access control scenarios with multiple access control lists, this embodiment sequentially selects any one of the multiple access control lists as the target access control list. It then uses multiple behavioral permissions to detect the matching results of the current file access operation's behavioral permissions under the target access control list. Finally, after obtaining the file access result corresponding to the matching results of multiple behavioral permissions, it generates file access permissions based on the result type of the file access result. This achieves a comprehensive determination of the file access permissions of the current file access operation under the access control rules, using both the first dimension of multiple access control rules and the second dimension of different behavioral permissions under the same access control rule. Therefore, it further reduces the limitations of bastion host file access control and improves the security of bastion host file access control.

[0077] In one embodiment, access control is performed on the current file access operation based on file access permissions, including:

[0078] If the file access permissions allow for the current file access operation, detect any abnormal behavior values ​​for the current file access operation. If the abnormal behavior value is greater than a preset behavior baseline value, then access control is applied to the current file access operation based on the behavior verification result. If the abnormal behavior value is less than or equal to the preset behavior baseline value, then the current file access operation is allowed.

[0079] It should be noted that, combined with entity behavior analysis technology, the bastion host can establish behavioral baselines through in-depth analysis of daily user and device behavior. When the system detects abnormal behavior that deviates from the baseline, it can automatically adjust access permissions or trigger alarms, thereby providing higher security and flexibility. This technology can not only identify threats not covered by regular rules, but also improve the system's sensitivity and response speed through anomaly detection mechanisms, better protecting the enterprise's information security. In particular, the detection of abnormal behavior for file access operations can be implemented based on anomaly detection algorithms. For example, in one feasible approach, users' file operation behavior can be continuously monitored and recorded during a set observation period, including information such as operation time, frequency, operation type, and operation source IP. During the observation period, an initial baseline of user behavior is established using the Isolation Forest algorithm, and the baseline is continuously improved after the observation period. This baseline is used to evaluate outliers in the current file access operation. The workflow of the Isolation Forest algorithm is shown in Figure 3: 1) Randomly select a subset from the dataset; 2) Build the forest: 1. Randomly select a feature; 2. Randomly select a split point between the minimum and maximum values ​​of the feature; 3. Divide the data into two parts according to the selected split point; 4. Recursively repeat this process for each part until the stopping condition is met.

[0080] It should be noted that the decision-making process of the decision-making module has been demonstrated in the above example, and will not be repeated here. On the other hand, after the decision-making module approves the operation on the blacklist and whitelist, it will also initiate anomaly detection and calculate anomaly scores for the approved operations. For example, in one feasible approach, the average path length h(x) of the current file access operation in the isolated forest is first calculated using the following formula: s(x, n)=2{-E(h(x))c(n)}

[0081] Where s(x, n) is the behavior anomaly value, c(n) is the standardization constant, and E(h(x)) is the average path length. After calculating the behavior anomaly value of the current file access operation, the final access control result for the current file access operation is obtained based on the relationship between the behavior anomaly value and the preset behavior baseline value. For example, assuming the preset behavior baseline value is 0.9, if the behavior anomaly value is 0.8, the current file access operation is allowed; if the behavior anomaly value is 1, the current file access operation is denied.

[0082] As an example, given that the current file access operation has the necessary permissions, the average path length of the current file access operation in the isolated forest is detected, and behavioral anomalies of the current file access operation are detected based on the average path length. If the behavioral anomaly is greater than a preset behavioral benchmark, behavioral verification is performed on the current file access operation to obtain the behavioral verification result, and access control for the current file access operation is implemented based on the behavioral verification result. The specific method for performing behavioral verification on the current file access operation can be to require the user to perform secondary verification by entering an SMS verification code. If the behavioral anomaly is less than or equal to the preset behavioral benchmark, the current access operation is allowed to be executed.

[0083] In one feasible approach, the bastion host file management system can also deploy an audit module to audit the access control process of file access operations. For example, the audit module's recorded results could be: "User 2024-06-15 14:00:00 was allowed to submit a request to delete the file / data / public / 1.txt from IP address xxx.xxx.1.35. This operation is risk level 4. It was executed without any anomaly detection records, and the execution result was successful." By deploying the audit module, audit information can be recorded, which may include metadata, anomaly detection results, decision results, operation results, and operation risk levels. Through the audit module, every file operation can be recorded and analyzed in detail, facilitating post-event traceability and security auditing.

[0084] In this embodiment, UEBA technology, based on anomaly detection algorithms, continuously learns and analyzes the normal behavior patterns of file access operations and establishes a dynamic behavior baseline. This allows for the pre-setting of preset behavior benchmark values, enabling the bastion host file management system to identify abnormal behaviors that deviate from the normal pattern. This provides more accurate threat detection and risk assessment capabilities. Specifically, based on the relationship between the abnormal behavior value and the preset behavior benchmark value, it determines whether to perform behavior verification on the current file access operation. Furthermore, it adds a secondary verification mechanism when the security of the file access operation is not high, thereby maximizing the security of bastion host file control.

[0085] In one feasible approach, referring to Figure 4, which is a schematic diagram of the structure of a bastion host file management system, the bastion host file management system includes a construction module, a sorting module, a decision module, and an auditing module. The construction module can be used to construct an enhanced blacklist and whitelist and establish an initial baseline of user behavior through the isolated forest algorithm. The sorting module can be used to sort the blacklist and whitelist in descending order of risk level to obtain an effective blacklist and whitelist. The decision module can make blacklist and whitelist decisions and perform anomaly scoring calculations when operations are permitted. The auditing module is used to record audit operation information and results.

[0086] In one feasible approach, referring to Figure 5, which is a control flowchart representing file access control of a bastion host, the input file operation to be decided can be understood as the current file access operation. The sourcelps list is used to represent behavior object information, the paths list is used to represent behavior path information, and the operations list is used to represent behavior type information. After multi-level behavior permission detection, a selection step is executed: The selection step involves selecting a target access control list from multiple access control lists; detecting the behavior permission matching result of the current file access operation under the target access control list based on multiple behavior permissions; returning to the selection step until all access control lists are selected as target access control lists, obtaining the file access result corresponding to multiple behavior permission matching results; generating file access permissions based on the result type of the file access result; detecting behavior anomalies of the current file access operation if the file access permissions are sufficient for the current file access operation; if the behavior anomaly value is greater than a preset behavior benchmark value, access control is applied to the current file access operation based on the behavior verification result; if the behavior anomaly value is less than or equal to the preset behavior benchmark value, the current file access operation is allowed to execute. Finally, the audit module monitors the access control process in real time.

[0087] It is understood that the following technical effects can be achieved based on this embodiment: 1) Enhanced security and flexibility: Through the UEBA module, the system can identify and respond to threats not covered by conventional rules, dynamically adjust security policies, and improve response speed and detection sensitivity. It also provides user behavior pattern analysis, improving the system's ability to identify abnormal operations; 2) Fine-grained access control: Based on multi-dimensional metadata and risk levels, it allows for precise control and sorting optimization of complex access rules, enhancing the adaptability and accuracy of rule management. This ensures that a wide variety of operation requests are appropriately satisfied under secure conditions.

[0088] It should be understood that although the steps in the flowcharts of the above embodiments are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0089] Based on the same inventive concept, this application also provides a bastion host file access control device for implementing the bastion host file access control method described above. The solution provided by this device is similar to the solution described in the above method; therefore, the specific limitations in one or more bastion host file access control device embodiments provided below can be found in the limitations of the bastion host file access control method described above, and will not be repeated here.

[0090] In an exemplary embodiment, as shown in FIG6, a bastion host file access control device is provided, comprising: a matching module 401, a determining module 402, and an access control module 403, wherein:

[0091] The matching module 401 is used to match access control rules that conform to access security standards for the current file access operation based on the attribute feature information carried by the current file access operation received by the bastion host.

[0092] The determination module 402 is used to determine the file access permissions of the current file access operation under the access control rules based on the behavioral feature information carried by the current file access operation;

[0093] The access control module 403 is used to perform access control on the current file access operation according to the file access permissions.

[0094] In one embodiment, the attribute feature information includes operation timeliness information; the matching module 401 is further configured to:

[0095] For each historical file access operation, a preset access control rule conforming to the security access standard is constructed; multiple preset access control rules are filtered to obtain multiple candidate access control rules located within the valid time period of the operation time information identifier; the access control rule is extracted from the multiple candidate access control rules.

[0096] In one embodiment, the matching module 401 is further configured to:

[0097] Based on the operational risk information of each historical file access operation, the multiple candidate access control rules are prioritized to obtain a priority ranking result; based on the priority ranking result, the access control rule is extracted from the multiple candidate access control rules.

[0098] In one embodiment, the behavioral feature information includes behavioral location information, behavioral object information, and behavioral type information; the determining module 402 is further configured to:

[0099] Based on the behavior location information, the behavior object information, and the behavior type information, the behavior permissions of the current file access operation under the access control rule are detected sequentially; based on multiple behavior permissions, the file access permissions of the current file access operation under the access control rule are generated.

[0100] In one embodiment, the access control rules include multiple access control lists; the access control module 403 is further configured to:

[0101] Selection steps: Select a target access control list from the multiple access control lists; based on the multiple behavior permissions, detect the behavior permission matching result of the current file access operation under the target access control list; return to execute the selection steps until all access control lists are selected as the target access control list, and obtain the file access result corresponding to the multiple behavior permission matching results; generate the file access permission based on the result type of the file access result.

[0102] In one embodiment, the access control module 403 is further configured to:

[0103] If the file access permission is sufficient for the current file access operation, an abnormal behavior value of the current file access operation is detected. If the abnormal behavior value is greater than a preset behavior benchmark value, access control is applied to the current file access operation based on the behavior verification result. If the abnormal behavior value is less than or equal to the preset behavior benchmark value, the current file access operation is allowed to be executed.

[0104] The modules in the aforementioned bastion host file access control device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of a computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of each module.

[0105] In an exemplary embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram is shown in Figure 7. The computer device includes a processor, memory, input / output interface, communication interface, display unit, and input device. The processor, memory, and input / output interface are connected via a system bus, and the communication interface, display unit, and input device are connected to the system bus via the input / output interface. The processor of the computer device provides computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The input / output interface of the computer device is used for exchanging information between the processor and external devices. The communication interface of the computer device is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements a bastion host file access control method. Those skilled in the art will understand that the structure shown in Figure 7 is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0106] In one embodiment, a computer device is also provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps in the above method embodiments.

[0107] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements the steps in the above method embodiments.

[0108] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above method embodiments.

[0109] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.

[0110] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0111] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this patent application should be determined by the appended claims.

Claims

1. A bastion host file access control method, characterized in that, The method includes: Based on the attribute feature information carried by the current file access operation received by the bastion host, access control rules that conform to access security standards are matched for the current file access operation; Based on the behavioral characteristic information carried by the current file access operation, determine the file access permissions of the current file access operation under the access control rules; Access control is performed on the current file access operation based on the file access permissions.

2. The method according to claim 1, characterized in that, The attribute feature information includes operation timeliness information; the step of matching access control rules that conform to access security standards for the current file access operation based on the attribute feature information carried by the current file access operation received by the bastion host includes: Build preset access control rules that conform to secure access standards for each historical file access operation; Multiple preset access control rules are filtered to obtain multiple candidate access control rules that are located within the valid time period of the operation validity information identifier; Extract the access control rule from the plurality of candidate access control rules.

3. The method according to claim 2, characterized in that, The step of extracting the access control rule from the plurality of candidate access control rules includes: Based on the operational risk information of each historical file access operation, the multiple candidate access control rules are prioritized to obtain a priority ranking result. Based on the priority ranking result, the access control rule is extracted from the plurality of candidate access control rules.

4. The method according to claim 1, characterized in that, The behavioral characteristic information includes behavioral location information, behavioral object information, and behavioral type information; determining the file access permissions of the current file access operation under the access control rules based on the behavioral characteristic information carried by the current file access operation includes: Based on the behavior location information, the behavior object information, and the behavior type information, the behavior permissions of the current file access operation in the access control rules are detected sequentially. Based on multiple behavioral permissions, generate the file access permissions for the current file access operation under the access control rules.

5. The method according to claim 4, characterized in that, The access control rules include multiple access control lists; The step of generating file access permissions for the current file access operation under the access control rules based on multiple behavioral permissions includes: Selection steps: Select the target access control list from the multiple access control lists; Based on the multiple behavioral permissions, detect the matching result of the behavioral permissions of the current file access operation under the target access control list; Return to the selection step until all access control lists are selected as the target access control list, and obtain the file access result corresponding to multiple behavior permission matching results; The file access permissions are generated based on the result type of the file access result.

6. The method according to claim 5, characterized in that, The access control of the current file access operation based on the file access permissions includes: If the file access permission is such that the current file access operation has the necessary access permission, detect abnormal values ​​in the behavior of the current file access operation; If the abnormal behavior value is greater than the preset behavior baseline value, then access control is performed on the current file access operation based on the behavior verification result of the current file access operation. If the abnormal behavior value is less than or equal to the preset behavior baseline value, then the current file access operation is allowed.

7. A bastion host file access control device, characterized in that, The device includes: The matching module is used to match access control rules that conform to access security standards for the current file access operation based on the attribute feature information carried by the current file access operation received by the bastion host. The determination module is used to determine the file access permissions of the current file access operation under the access control rules based on the behavioral feature information carried by the current file access operation; The access control module performs access control on the current file access operation based on the file access permissions.

8. The apparatus according to claim 7, characterized in that, The attribute feature information includes operation timeliness information; the matching module is also used for: For each historical file access operation, a preset access control rule conforming to the security access standard is constructed; multiple preset access control rules are filtered to obtain multiple candidate access control rules located within the valid time period of the operation time information identifier; the access control rule is extracted from the multiple candidate access control rules.

9. The apparatus according to claim 8, characterized in that, The matching module is also used for: Based on the operational risk information of each historical file access operation, the multiple candidate access control rules are prioritized to obtain a priority ranking result; based on the priority ranking result, the access control rule is extracted from the multiple candidate access control rules.

10. The apparatus according to claim 7, characterized in that, The behavioral feature information includes behavioral location information, behavioral object information, and behavioral type information; the determining module is further used for: Based on the behavior location information, the behavior object information, and the behavior type information, the behavior permissions of the current file access operation in the access control rules are detected sequentially. Based on multiple behavioral permissions, generate the file access permissions for the current file access operation under the access control rules.

11. The apparatus according to claim 10, characterized in that, The access control rules include multiple access control lists; the access control module is also used for: Selection steps: Select the target access control list from the multiple access control lists; based on the multiple behavior permissions, detect the behavior permission matching result of the current file access operation under the target access control list; Return to the selection step until all access control lists are selected as the target access control list, and obtain the file access result corresponding to multiple behavior permission matching results; generate the file access permission based on the result type of the file access result.

12. The apparatus according to claim 11, characterized in that, The access control module is also used for: If the file access permission is sufficient for the current file access operation, an abnormal behavior value of the current file access operation is detected. If the abnormal behavior value is greater than a preset behavior benchmark value, access control is applied to the current file access operation based on the behavior verification result. If the abnormal behavior value is less than or equal to the preset behavior benchmark value, the current file access operation is allowed to be executed.

13. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.

14. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.

15. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.