Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

88 results about "Bastion host" patented technology

A bastion host is a special-purpose computer on a network specifically designed and configured to withstand attacks. The computer generally hosts a single application, for example a proxy server, and all other services are removed or limited to reduce the threat to the computer. It is hardened in this manner primarily due to its location and purpose, which is either on the outside of a firewall or in a demilitarized zone (DMZ) and usually involves access from untrusted networks or computers.

Authority hierarchical control method based on dynamic desensitization and real-time monitoring and operation and maintenance bastion host system

The embodiment of the invention discloses an authority hierarchical control method based on dynamic desensitization and real-time monitoring and an operation and maintenance bastion host system.According to the embodiment of the invention, by integrating a database firewall and a dual-mode desensitization engine and combining authority hierarchical control and real-time semantic analysis, the data security and operation compliance in an operation and maintenance scene are remarkably improved, and the operation and maintenance security is improved. The dynamic desensitization rewrites a query statement in real time according to a user role, and limits exposure of original data; static desensitization is performed to pre-generate an isolated copy, so that direct access to a production library is reduced; based on semantic analysis and a rule engine, the response time is shortened to be within 1 second; the static desensitization library supports direct use of development and testing, and the permission application process is reduced; a rule base is dynamically updated through an Attention-GRU-Adaboost model, and the adaptability to a novel attack mode is improved.
Owner:CENTURY LONGMAI TECH

Multi-protocol integration method and device, equipment, storage medium and program product

The invention relates to a multi-protocol integration method and device, equipment, a storage medium and a program product, which are applied to a bastion host, and the bastion host comprises a communication port. The method comprises the following steps: firstly, receiving a first access request generated based on a first protocol and sent by each client through a communication port, then, determining target equipment needing to be accessed by each client according to the first access request, then, determining a second protocol supported by each target equipment based on preset configuration of each target equipment, and finally, sending the second protocol to the client through the communication port. And converting each first access request based on the first protocol and the second protocol, determining a second access request of each client, and accessing the corresponding target device through the second access request. By adopting the method, the number of communication ports can be reduced, so that the network attack surface is reduced, potential security holes and threats are reduced, and the access security of the target equipment is improved.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Power grid dispatching cloud platform access authentication method, device and equipment based on bastion host, storage medium and program product

The invention relates to a power grid dispatching cloud platform access authentication method, device and equipment based on a bastion host, a storage medium and a program product, and relates to the technical field of information security. According to the method, the security risk existing when the power grid dispatching cloud platform is remotely accessed can be reduced, and the operation information is efficiently stored. The method comprises the following steps: sending an access request of a current user to a configured OTP server, so that the OTP server generates a password and a detection token according to the access request; the method comprises the following steps: acquiring a user name of a current user, receiving a password and a detection token returned by an OTP server, packaging and sending the user name, the password and the detection token to a bastion host, verifying the detection token by the bastion host according to the user name, and sending the password to the OTP server by the bastion host under the condition that the verification of the detection token is passed, the OTP server verifies the password password; and logging in the bastion host under the condition that the password verification is passed, and accessing the power grid dispatching cloud platform through the bastion host.
Owner:CHINA SOUTHERN POWER GRID COMPANY

Bastion host sensitive data identification method based on large model

The invention relates to the technical field of information security, and discloses a bastion host sensitive data identification method based on a large model, comprising the following steps: preprocessing unstructured data collected by a bastion host, pre-training the large model, and after the preprocessing is completed, identifying the sensitive data of the bastion host; a dynamic knowledge graph is constructed for storing and managing sensitive entities and relationships thereof, the dynamic knowledge graph is updated according to new data monitored in real time, pruning and lightweight processing are performed on a pre-trained large model based on sensitive data features in the dynamic knowledge graph, and the sensitive entities and the relationships between the sensitive entities are stored and managed. And fusing entity features extracted from the dynamic knowledge graph with semantic features output by the model, then identifying and classifying sensitive data, and dynamically adjusting an interception threshold according to a classification result after identification and classification are completed. According to the method, the technical scheme of dynamically adjusting the interception threshold is adopted, accurate classification of sensitive data is achieved, and the defect that complex and changeable data features are difficult to process through a fixed threshold is overcome.
Owner:北京建恒信安科技有限公司

RAG-based bastion host intelligent operation guidance method and system

The invention discloses a bastion host intelligent operation guidance method and system based on RAG, and the method comprises the following steps: carrying out the partitioning processing of a bastion host operation document, constructing an operation document knowledge base and a vector database, and improving the semantic consistency of the document content; creating a chat window, and proposing an original natural language operation query; according to the method, the original natural language operation query is optimized and reconstructed to obtain a semantic optimization result of frame structuring, and the original natural language operation query is converted into an operation query vector, so that oral language content and semantic ambiguity of the operation query are effectively reduced, and standardized query content is provided for generation of operation guidance; therefore, the accuracy of operation guidance generation can be improved. Similarity retrieval is carried out, through a two-step retrieval method, the retrieval difficulty is reduced, the retrieval effect is improved, and context information with high semantic correlation is provided for generation of operation guidance; and inputting the retrieval content and the operation query into a dialogue model, and generating an operation instruction and a command instruction.
Owner:BEIJING LONGERSEC TECH CO LTD +1

Character command processing method based on bastion host, bastion host and storage medium

The invention relates to a bastion host-based character command processing method, a bastion host and a storage medium, and the method comprises the steps: after establishing SSH channels between the bastion host and a target client and between the bastion host and a target server, analyzing character data transmitted in the SSH channels through employing an SSH protocol analysis engine, and obtaining an original character stream inputted by the target client; synchronizing the context of the target server by using the shadow terminal, simulating the execution of the target server based on the original character stream to generate simulated echoes, and determining a corresponding target command; comparing the original character stream with the simulated echoes by using a dual-channel checker to obtain a comparison result; and determining a release decision or an interception decision by using a decision maker based on the comparison result. Through the target command identification method and device, the problems of low identification accuracy and existence of misinformation and missing information in related technologies are solved, misjudgment and missing judgment are eliminated, the target command identification integrity is ensured, and the identification accuracy is improved.
Owner:ZHEJIANG QIZHI TECH CO LTD

A method and system for real-time transmission of audit data through a bastion host

The present invention relates to the field of operation and maintenance technologies, and discloses a method and system for real-time transmission of audit data through a bastion host, which can realize real-time transmission of audit data to the interface display based on the scenario of a remote operation and maintenance system. To solve the problem that in some scenarios when using the bastion host remote operation and maintenance system, the operation and maintenance audit events recorded by the engine protocol proxy are obtained only after the session ends, resulting in the inability to timely transmit the operation and maintenance events to the business interface for display. Through the method of transmitting data via syslog, the present invention can, when remotely operating and maintaining the system through the bastion host, transmit information such as the audited command statements and videos in real time to the interface for output, and does not affect the real-time monitoring and warning capabilities of the bastion host, alleviating the technical problem in the prior art that the risk cannot be timely known due to untimely synchronization of audit data.
Owner:CHENGDU DBAPP SECURITY

Host security protection method and system, electronic equipment and program product

The invention discloses a security protection method and system for a host, electronic equipment and a program product. The method is applied to a host security product in a cloud environment, and comprises the following steps: monitoring an authentication password set on a host, the authentication password being used for performing security protection on the host; the security performance index of the authentication password is determined, and the security performance index is used for representing the security protection intensity of the authentication password on the host; and if the safety performance index of the authentication password is lower than the index threshold value, calling the bastion host in the cloud environment to modify the authentication password. The technical problem that safety protection cannot be effectively carried out on the host is solved.
Owner:HANGZHOU ALICLOUD FEITIAN INFORMATION TECH CO LTD

Public data fusion development platform

The invention discloses a public data fusion development platform which comprises a platform portal website, a business center, a capability support plate and an infrastructure layer. The platform web portal serves as a user layer to provide an external service window; the business center serves as a business layer and comprises an operation management system, a second-level development system and a competition management system which serve a first-level development subject, a second-level development subject and the public respectively. The capability supporting plate serves as a middle table layer and comprises a data management system, a resource management system, a privacy computing system and an operation and maintenance management system which are used for providing data management, resource scheduling, security computing and full-life-cycle operation and maintenance support for the service center; the infrastructure layer provides one or more infrastructures including a cloud resource pool, a privacy computing environment, a computing engine, containerization, a scheduling engine, intrusion protection, threat detection, a firewall, and a bastion host for the capability support section.
Owner:XIAMEN BIG DATA CO LTD

Data processing method and device, storage medium and electronic equipment

The invention discloses a data processing method and device, a storage medium and electronic equipment. Relates to the field of financial science and technology, and the method comprises the following steps: obtaining device information of a plurality of devices in a device management platform through a bastion host, the device information at least comprising device parameter information and first user identity information corresponding to the devices; comparing second user identity information in the bastion host with the first user identity information to obtain a target user list; and performing data change processing on the identity information corresponding to the target user list through the bastion host to obtain a processing result. Through the method and the device, the problem of relatively low processing efficiency of the user data caused by management of the user data of the equipment based on a manual mode in related technologies is solved.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

A bastion host security protection system based on intelligent risk identification

The present invention relates to the technical field of bastion hosts, and specifically relates to a bastion host security protection system based on intelligent risk recognition, including: a storage module for real-time retrieval of the operation logs of the bastion host and storage of the operation logs of the bastion host; a retrieval module for retrieving the operation logs of the bastion host from the storage module and forwarding the retrieved operation logs of the bastion host to the detection module; By obtaining the historical operation logs of the bastion host, the present invention performs data cleaning on the historical operation logs of the bastion host to obtain high-value reference logs, further comprehensively analyzes according to the cleaned historical operation logs of the bastion host, digitally detects the abnormal changes in the operation state of the bastion host, finally creates a trend chart based on the monitoring results, and determines the security of the current operation state of the bastion host according to the trend of the trend chart, bringing an effective and relatively accurate predictive fault and risk monitoring and protection effect to the bastion host.
Owner:中电云(武汉)网络技术股份有限公司

Character command processing method based on bastion host, bastion host and storage medium

The present application relates to a character command processing method based on a bastion host, a bastion host and a storage medium, wherein the method comprises: after establishing SSH channels between the bastion host and the target client and target server respectively, utilizing an SSH protocol parsing engine to parse the character data transmitted in the SSH channel to obtain the original character stream input by the target client; utilizing a shadow terminal to synchronize the context of the target server, and simulating the execution of the target server based on the original character stream to generate a simulated echo, and determining the corresponding target command; utilizing a dual-channel checker to compare the original character stream and the simulated echo to obtain a comparison result; utilizing a decision maker to determine a release decision or an interception decision based on the comparison result. Through the present application, the problems in the related art that lead to low recognition accuracy, false positives and missed reports are solved, false positives and missed reports are eliminated, the integrity of target command recognition is ensured, and recognition accuracy is improved.
Owner:ZHEJIANG QIZHI TECH CO LTD

An identity authentication method and device based on a commercial cipher algorithm

PendingCN122640127AAlgorithmSession key
The application discloses an identity authentication method and device based on commercial cryptographic algorithms, which is applied to a bastion host operation and maintenance scene, and relies on SM2, SM3 and SM4 commercial cryptographic algorithms, and realizes high-security and high-performance two-way identity authentication. The method strictly follows the core process of GB / T 15843.3-2023 standard, and the standard is optimized and enhanced in multiple dimensions through commercial cryptographic algorithms, including true random number hardware generation, SM2 signature verification enhancement, SM3 session key derivation, SM4 transmission encryption and other steps, to make up for the lack of standard original protection and complete two-way identity authentication. The application strengthens the commercial cryptographic algorithm set of hardware devices, and is deeply integrated with the optimized standard, effectively solves the problems of private key leakage, performance bottleneck and standard protection short board of the existing scheme, meets the compliance requirements of equal protection and secret evaluation, and provides a reliable identity access solution for remote operation and maintenance of the bastion host.
Owner:TOEC ANCHEN INFORMATION TECH

Data transmission method and related apparatus

The embodiment of the application provides a data transmission method and related device, which are applied to the field of communication. The method comprises the following steps: a first device logs in a bastion host through ssh; the first device receives and responds to a first operation for selecting a second device from a plurality of device identifiers, and establishes a communication connection with the second device through the bastion host. The first device receives a shortcut key command and sends the shortcut key command to a session management module of the bastion host. The bastion host converts the shortcut key command into a control command, and interacts with the second device according to the control command to obtain a service address of a server corresponding to the second device. The first device accesses the server according to the service address from the bastion host to download data in the second device or upload data to the second device through the server. In this way, the service address for file transmission is obtained on the bastion host through the shortcut key command, and file transmission is realized through the service address. This method is simple to operate, convenient for file transmission, small in resource occupation, and low in governance cost.
Owner:BEIJING WODONG TIANJUN INFORMATION TECH CO LTD +1

Operation and maintenance management method and system for automatically and uniformly managing nodes of bastion host

Disclosed is an operation and maintenance method and system for automatically and uniformly managing nodes of bastion host. No matter distribution of user permission, daily deployment of machine monitoring and network monitoring or batch management of daily operation and maintenance, the operation and maintenance method and system can be abstracted as follows: master control dispatches a Master of a certain area node to issue and execute a certain task, and unified management is naturally achieved; the design concept can be continued subsequently. A Master host in the node serves as a master controller of the node, and related contents including a tool script library, a crontab task and a configuration file are preset in a Redis of the node in advance; when a new machine is accessed to a certain node, the new machine is configured to perform Salt-Master access management of the node where the new machine is located, and the corresponding machine is controlled to complete the corresponding task through a takeover program; therefore, unified and automatic management is realized.
Owner:HANGZHOU PINGPONG INTELLIGENT TECH CO LTD

Bastion host system applied to remote operation and maintenance of supplier and remote operation and maintenance method

The invention relates to a bastion host system applied to remote operation and maintenance of a supplier and a remote operation and maintenance method, and the bastion host system comprises a portal arranged in an isolation area, and an extension assembly and a bastion host which are arranged in the same server. The portal comprises a first service module and a first encryption channel module; the first service module is connected with the first encryption channel module and is used for providing static resources and processing service data; the first encryption channel module is connected with the expansion component and is used for building an encryption channel with the fortress under the cooperation of the expansion component; according to the encrypted channel and the web access request, the supplier is allowed to remotely access the bastion host; the problems of high security management and control cost and low maintenance efficiency caused by security risks in related technologies are solved; only static resources are provided on the portal, and the interactive data can only be acquired through an encryption channel, so that the data security is improved, and data leakage is prevented.
Owner:ZHEJIANG QIZHI TECH CO LTD

Data sandbox local area networking structure with high security

The utility model relates to the technical field of data sandboxes, and provides a data sandbox local area networking structure with high safety, which comprises local area network core equipment and a plurality of local area user terminals which are in spatial physical isolation layout with the local area network core equipment, the local area network core equipment comprises a server, a first switch, a bastion host, a management terminal and a second switch; the first switch is respectively connected with the server, the bastion host, the management terminal and the second switch; the second switch is respectively connected with a plurality of local user terminals; the local user terminal adopts computer equipment with an external data interface removed or blocked, and the management terminal is provided with the external data interface. By adopting physical isolation and a bastion host, a computer with an external data interface removed or blocked is adopted for a local user terminal, so that the risk of internal data leakage is reduced, and the data security is improved.
Owner:ZHONGKE TONGLIAN (BEIJING) TECHNOLOGY CO LTD

Method and management method for accessing business database

The application discloses a business database access method and management and control method, and belongs to the field of data security. The method comprises the following steps: a client obtains channel configuration information of a target database through a bastion host, wherein the channel configuration information comprises channel address information between the bastion host and the target database; the client sends a first access request to the bastion host based on the channel address information, wherein the first access request carries the channel address information and an access condition; and the client receives an access result meeting the access condition, which is obtained by the bastion host from the target database based on the channel address information.
Owner:CHINA MOBILE GROUP ZHEJIANG +1

Intranet security operation and maintenance method and device based on bastion host, medium and program product

The embodiment of the invention provides an intranet security operation and maintenance method and device based on a bastion host, a medium and a program product, and relates to the technical field of operation and maintenance management. The method comprises the following steps: in response to a connection request actively initiated by a zero-trust proxy client, establishing an end-to-end encrypted application layer tunnel between a zero-trust proxy server and the zero-trust proxy client under the condition that bidirectional authentication is passed; acquiring context information corresponding to the operation and maintenance terminal, and determining a dynamic authorization strategy based on the context information; and performing operation and maintenance management and control on the operation and maintenance operation of the operation and maintenance terminal based on the dynamic authorization strategy, and transmitting operation and maintenance traffic generated between the operation and maintenance terminal and the intranet resource side through the application layer tunnel. According to the embodiment of the invention, the zero-trust system model taking the internal resource side as the active connection end is constructed, and the dynamic authorization strategy is generated by acquiring the related context information in real time, so that the security of internal network operation and maintenance is greatly improved.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Train network security protection method and system and storage medium

The invention provides a train network security protection method, a train network security protection system and a computer readable storage medium. The train network security protection method comprises the following steps: carrying out identity authentication on an external system, and identifying an equipment category and a corresponding port of the external system; in response to the fact that the equipment category of the external system is maintenance equipment, starting a bastion host function; and in response to the fact that the equipment category of the external system is communication equipment, based on the configuration of the corresponding port, starting a security audit and intrusion detection function or a firewall function, the starting of the security audit and intrusion detection function or the firewall function comprising analysis of a message of a train-specific protocol and control data thereof. According to the train network safety protection method, multiple safety protection functions can be achieved at the same time, the number of safety devices and the size of a train communication network are reduced, analysis of a train special protocol is achieved, and therefore more efficient protection is achieved in a rail transit vehicle-mounted network.
Owner:CRRC ZHUZHOU ELECTRIC LOCOMOTIVE RESEARCH INSTITUTE CO LTD

Identity authentication method, device and equipment, and computer storage medium

The application discloses an identity authentication method, device and equipment and a computer storage medium. The method is applied to a bastion host and comprises the following steps: obtaining a user account; sending a biological identification request to a server, so that the server randomly generates a user credential code, sends the user credential code to a terminal device, the terminal device collects first target biological information, compares the first target biological information with prestored biological information, obtains a first target biological identification result, marks a target mark corresponding to the first target biological identification result in the user credential code, obtains a target user credential code, encrypts the target user credential code, obtains an encrypted user credential code, sends the encrypted user credential code to the server, the server decrypts the encrypted user credential code, and obtains the target user credential code; and in the case that the target mark in the target user credential code is a first mark, receiving identity authentication passing information sent by the server. The security of server resources is improved.
Owner:CHINA MOBILE GROUP ANHUI +1

Security access method, device and equipment based on bastion host and storage medium

The invention provides a security access method and device based on a bastion host, equipment and a storage medium, and is applied to the technical field of information security, and the method applied to first equipment which cannot directly perform identity verification with the bastion host comprises the following steps: sending a login request to the bastion host through second equipment according to an access operation of a user, the second equipment is user equipment which is authenticated by the bastion host identity of the same user; if the forwarded login failure signal is received, generating a first verification request according to the user credential and a validity verification factor corresponding to the second equipment, and sending the first verification request to the second equipment; and receiving verification result information fed back by the identity verification server and forwarded by the second equipment, logging in the bastion host under the condition that the verification is passed, and establishing access connection with the target access server. According to the method and the device, the user password does not need to be input in the bastion host, so that the login of the user equipment which cannot directly log in the bastion host is ensured, the user experience is improved, and the information security is improved.
Owner:CHINA MOBILE GROUP JIANGSU +1

Operation and Maintenance Processing Method, Device, Computer Equipment and Medium Based on a Bastion Host

The present application relates to an operation and maintenance processing method, device, computer device, storage medium, and computer program product based on a bastion host. The method includes: when receiving a proxy program startup request, starting a bastion host JDBC proxy program in the bastion host based on command line startup parameters; calling the bastion host JDBC proxy program based on database configuration information to load a database JDBC driver corresponding to an operation and maintenance database server; when a database client calls a proxy driver to send an operation and maintenance connection request to the bastion host JDBC proxy program, establishing a communication connection between the database client and the operation and maintenance database server based on the bastion host JDBC proxy program; receiving an operation instruction from the database client based on the proxy driver; when it is determined based on the bastion host JDBC proxy program that the operation instruction is a first preset instruction, and the bastion host JDBC proxy program obtains an operation result of the operation instruction from the operation and maintenance database server based on the database JDBC driver, forwarding the operation result to the database client.
Owner:HUNAN UNIV

Data desensitization method based on bastion host operation and maintenance and computer program product

The invention provides a data desensitization method based on bastion host operation and maintenance, a computer program product, electronic equipment and a storage medium, and the method comprises the steps: obtaining communication traffic of bastion host operation and maintenance; analyzing the communication flow to obtain standardized format data; inputting the standardized format data into a pre-constructed large model for sensitive data identification to obtain sensitive data and a corresponding sensitive degree; querying a pre-constructed permission desensitization strategy mapping table according to the sensitive data and the corresponding sensitive degree to obtain a desensitization strategy; and desensitizing the sensitive data according to the desensitization strategy. By implementing the application, accurate classification and identification of sensitive data can be realized, different desensitization strategies can be carried out according to different protocol types, various fine-grained desensitization can be realized, desensitization can be carried out according to operation and maintenance rights, and the desensitization process is more flexible and controllable.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

High-risk command identification method and device of bastion host, computer equipment and storage medium

The invention relates to a high-risk command recognition method and device of a bastion host, computer equipment and a storage medium, and the method comprises the steps: loading a user-defined rule corresponding to target equipment to an output state processor of a character module based on a configuration file after a session is started; echoed data corresponding to a last command input by a user client is transmitted to an output state processor; in the output state processor, matching is carried out according to the echo data, the user-defined rule and a preset built-in rule, and session state conversion is carried out according to a matching result so as to enter a corresponding session state; and when entering the corresponding session state and determining that the current command input by the user client is submitted, carrying out high-risk command identification on the current command. Through the method and the device, the problem of low accuracy of high-risk command identification in related technologies is solved, and accurate session state switching is realized, so that the accuracy of high-risk command identification is maintained, and the command control capability of the bastion host is improved.
Owner:ZHEJIANG QIZHI TECH CO LTD

A method for starting a desktop operation and maintenance client of a bastion host

The present invention relates to the technical field of bastion hosts, and discloses a method for starting a desktop operation and maintenance client of a bastion host. The method uses the bastion host launcher as an HTTP client, and the bastion host launcher, the asset access client, and the asset access server use the asset access signature token as the request body, and interact using the HTTP protocol to complete the startup of the desktop operation and maintenance client, solving the technical problems in the prior art that when using the URL protocol launcher to start the desktop operation and maintenance client, the interaction is not friendly, the URL is too long leading to service anomalies, the startup error log cannot be transmitted, and the security is insufficient.
Owner:BEIJING LONGERSEC TECH CO LTD +1

Network security maintenance bastion host

The utility model discloses a network security maintenance bastion host, which belongs to the technical field of bastion hosts, and comprises a bastion host main body, a boss is fixedly connected to one side of the outer surface of the bastion host main body, and a plurality of uniformly distributed Ethernet ports are formed in one side, far away from the bastion host main body, of the outer surface of the boss. A power supply socket is formed in a position, far away from the boss, of one side of the outer surface of the bastion host main body. Through the arrangement of the dustproof mechanism, two dustproof covers are driven to rotate away from each other by moving a convex block, then a network cable is inserted into the Ethernet port, and then a sliding plate is driven by a first spring, so that the two dustproof covers rotate close to each other, and meanwhile, the network cable is located in a semicircular groove; according to the bastion host, the two dustproof covers are arranged, so that one end of the network cable and the Ethernet port are sealed in the two dustproof covers, dust is prevented from being accumulated at the position where the network cable is inserted into the Ethernet port, normal use of the bastion host is ensured, and the use effect of the bastion host is improved.
Owner:任晓峰 +3

Security protection method and device for bastion host of sensor application and medium

The invention relates to the technical field of network operation and maintenance, and discloses a bastion host security protection method and device for sensor application, and a medium, and the method comprises the steps: deploying a sensor in a bastion host; user information is input into the perception body, and the perception body obtains the strategy component to perform preliminary authentication on the user information; after the preliminary authentication is passed, the perception body opens up a virtual space of the user; re-authentication is carried out based on user information in the virtual space, and if authentication succeeds, the user successfully logs in the bastion host; the perception body calls the bastion host agent component for the user to perform application access; the perception body obtains a user behavior; and if the user behavior is abnormal, interrupting the user access, and updating the policy component. According to the invention, intelligent configuration and management can be completed, and comprehensive safety protection and threat perception of enterprise operation and maintenance data are realized.
Owner:WUHAN ZIRUI DONGCHUANG TECHNOLOGY CO LTD

Anti-misoperation method for bastion fortress and computer program product

The invention provides an anti-misoperation method for a bastion fortress, a computer program product, electronic equipment and a storage medium, and the method comprises the steps: obtaining an input command; intercepting the input command according to a fortress session agent; performing risk level evaluation on the intercepted input command to obtain a risk level corresponding to the input command; performing safe second-reading buffer processing on the input command according to the risk level, and creating a countdown task; and executing the countdown task, and completing the issuing process of the input command. By implementing the application, the operation can be buffered through safe second reading, misoperation is effectively prevented, the real-time control capability of the execution process is improved, an isolation layer is established between command identification and execution, interruptible and delayed release of high-risk operation is ensured, and the flexible control of the operation is improved.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Permission hierarchical control method and operation and maintenance bastion system based on dynamic desensitization and real-time monitoring

An embodiment of the present invention discloses a permission hierarchical control method and an operation and maintenance bastion host system based on dynamic desensitization and real-time monitoring. The embodiment of the present invention significantly improves data security and operational compliance in operation and maintenance scenarios by integrating a database firewall and a dual-mode desensitization engine, combining permission hierarchical control and real-time semantic analysis. Dynamic desensitization rewrites query statements in real time according to user roles to limit the exposure of original data; static desensitization pre-generates isolated copies to reduce direct access to production libraries; based on semantic analysis and rule engines, the response time is shortened to within 1 second; the static desensitization library supports direct use in development and testing, reducing the permission application process; and the rule library is dynamically updated through the Attention-GRU-Adaboost model to improve adaptability to new attack patterns.
Owner:CENTURY LONGMAI TECH