Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

26 results about "Bastion host" patented technology

A bastion host is a special-purpose computer on a network specifically designed and configured to withstand attacks. The computer generally hosts a single application, for example a proxy server, and all other services are removed or limited to reduce the threat to the computer. It is hardened in this manner primarily due to its location and purpose, which is either on the outside of a firewall or in a demilitarized zone (DMZ) and usually involves access from untrusted networks or computers.

Public data fusion development platform

The invention discloses a public data fusion development platform which comprises a platform portal website, a business center, a capability support plate and an infrastructure layer. The platform web portal serves as a user layer to provide an external service window; the business center serves as a business layer and comprises an operation management system, a second-level development system and a competition management system which serve a first-level development subject, a second-level development subject and the public respectively. The capability supporting plate serves as a middle table layer and comprises a data management system, a resource management system, a privacy computing system and an operation and maintenance management system which are used for providing data management, resource scheduling, security computing and full-life-cycle operation and maintenance support for the service center; the infrastructure layer provides one or more infrastructures including a cloud resource pool, a privacy computing environment, a computing engine, containerization, a scheduling engine, intrusion protection, threat detection, a firewall, and a bastion host for the capability support section.
Owner:XIAMEN BIG DATA CO LTD

Data transmission method and related apparatus

The embodiment of the application provides a data transmission method and related device, which are applied to the field of communication. The method comprises the following steps: a first device logs in a bastion host through ssh; the first device receives and responds to a first operation for selecting a second device from a plurality of device identifiers, and establishes a communication connection with the second device through the bastion host. The first device receives a shortcut key command and sends the shortcut key command to a session management module of the bastion host. The bastion host converts the shortcut key command into a control command, and interacts with the second device according to the control command to obtain a service address of a server corresponding to the second device. The first device accesses the server according to the service address from the bastion host to download data in the second device or upload data to the second device through the server. In this way, the service address for file transmission is obtained on the bastion host through the shortcut key command, and file transmission is realized through the service address. This method is simple to operate, convenient for file transmission, small in resource occupation, and low in governance cost.
Owner:BEIJING WODONG TIANJUN INFORMATION TECH CO LTD +1

Intranet security operation and maintenance method and device based on bastion host, medium and program product

ActiveCN121619154ASecuring communicationEnd-to-end encryptionTrusted system
The embodiment of the invention provides an intranet security operation and maintenance method and device based on a bastion host, a medium and a program product, and relates to the technical field of operation and maintenance management. The method comprises the following steps: in response to a connection request actively initiated by a zero-trust proxy client, establishing an end-to-end encrypted application layer tunnel between a zero-trust proxy server and the zero-trust proxy client under the condition that bidirectional authentication is passed; acquiring context information corresponding to the operation and maintenance terminal, and determining a dynamic authorization strategy based on the context information; and performing operation and maintenance management and control on the operation and maintenance operation of the operation and maintenance terminal based on the dynamic authorization strategy, and transmitting operation and maintenance traffic generated between the operation and maintenance terminal and the intranet resource side through the application layer tunnel. According to the embodiment of the invention, the zero-trust system model taking the internal resource side as the active connection end is constructed, and the dynamic authorization strategy is generated by acquiring the related context information in real time, so that the security of internal network operation and maintenance is greatly improved.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Train network security protection method and system and storage medium

The invention provides a train network security protection method, a train network security protection system and a computer readable storage medium. The train network security protection method comprises the following steps: carrying out identity authentication on an external system, and identifying an equipment category and a corresponding port of the external system; in response to the fact that the equipment category of the external system is maintenance equipment, starting a bastion host function; and in response to the fact that the equipment category of the external system is communication equipment, based on the configuration of the corresponding port, starting a security audit and intrusion detection function or a firewall function, the starting of the security audit and intrusion detection function or the firewall function comprising analysis of a message of a train-specific protocol and control data thereof. According to the train network safety protection method, multiple safety protection functions can be achieved at the same time, the number of safety devices and the size of a train communication network are reduced, analysis of a train special protocol is achieved, and therefore more efficient protection is achieved in a rail transit vehicle-mounted network.
Owner:CRRC ZHUZHOU ELECTRIC LOCOMOTIVE RESEARCH INSTITUTE CO LTD

Identity authentication method, device and equipment, and computer storage medium

The application discloses an identity authentication method, device and equipment and a computer storage medium. The method is applied to a bastion host and comprises the following steps: obtaining a user account; sending a biological identification request to a server, so that the server randomly generates a user credential code, sends the user credential code to a terminal device, the terminal device collects first target biological information, compares the first target biological information with prestored biological information, obtains a first target biological identification result, marks a target mark corresponding to the first target biological identification result in the user credential code, obtains a target user credential code, encrypts the target user credential code, obtains an encrypted user credential code, sends the encrypted user credential code to the server, the server decrypts the encrypted user credential code, and obtains the target user credential code; and in the case that the target mark in the target user credential code is a first mark, receiving identity authentication passing information sent by the server. The security of server resources is improved.
Owner:CHINA MOBILE GROUP ANHUI +1

Security access method, device and equipment based on bastion host and storage medium

The invention provides a security access method and device based on a bastion host, equipment and a storage medium, and is applied to the technical field of information security, and the method applied to first equipment which cannot directly perform identity verification with the bastion host comprises the following steps: sending a login request to the bastion host through second equipment according to an access operation of a user, the second equipment is user equipment which is authenticated by the bastion host identity of the same user; if the forwarded login failure signal is received, generating a first verification request according to the user credential and a validity verification factor corresponding to the second equipment, and sending the first verification request to the second equipment; and receiving verification result information fed back by the identity verification server and forwarded by the second equipment, logging in the bastion host under the condition that the verification is passed, and establishing access connection with the target access server. According to the method and the device, the user password does not need to be input in the bastion host, so that the login of the user equipment which cannot directly log in the bastion host is ensured, the user experience is improved, and the information security is improved.
Owner:CHINA MOBILE GROUP JIANGSU +1

Data desensitization method based on bastion host operation and maintenance and computer program product

The invention provides a data desensitization method based on bastion host operation and maintenance, a computer program product, electronic equipment and a storage medium, and the method comprises the steps: obtaining communication traffic of bastion host operation and maintenance; analyzing the communication flow to obtain standardized format data; inputting the standardized format data into a pre-constructed large model for sensitive data identification to obtain sensitive data and a corresponding sensitive degree; querying a pre-constructed permission desensitization strategy mapping table according to the sensitive data and the corresponding sensitive degree to obtain a desensitization strategy; and desensitizing the sensitive data according to the desensitization strategy. By implementing the application, accurate classification and identification of sensitive data can be realized, different desensitization strategies can be carried out according to different protocol types, various fine-grained desensitization can be realized, desensitization can be carried out according to operation and maintenance rights, and the desensitization process is more flexible and controllable.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Anti-misoperation method for bastion fortress and computer program product

The invention provides an anti-misoperation method for a bastion fortress, a computer program product, electronic equipment and a storage medium, and the method comprises the steps: obtaining an input command; intercepting the input command according to a fortress session agent; performing risk level evaluation on the intercepted input command to obtain a risk level corresponding to the input command; performing safe second-reading buffer processing on the input command according to the risk level, and creating a countdown task; and executing the countdown task, and completing the issuing process of the input command. By implementing the application, the operation can be buffered through safe second reading, misoperation is effectively prevented, the real-time control capability of the execution process is improved, an isolation layer is established between command identification and execution, interruptible and delayed release of high-risk operation is ensured, and the flexible control of the operation is improved.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Remote operation and maintenance method, system and device, storage medium and program product

The invention provides a remote operation and maintenance method, system and device, a storage medium and a program product, and the remote operation and maintenance method applied to a bastion host comprises the steps: building encrypted session channels between the bastion host and an operation and maintenance end and between the bastion host and a target terminal; receiving an operation and maintenance instruction data frame sent by an operation and maintenance end through the encrypted session channel; forwarding the operation and maintenance instruction data frame to a target terminal; and receiving an execution result data frame returned by the target terminal, and sending the execution result data frame to the operation and maintenance terminal. According to the method, unified operation and maintenance control of a single set of protocols on a heterogeneous system is realized by constructing a three-section communication architecture of a unified protocol layer, a system adaptation layer and a protocol agent layer in a cooperative manner, and the problem of protocol and system deep coupling caused by independently developing an adaptation plug-in for each operating system in a traditional scheme is solved.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Bastion host operation instruction border crossing behavior identification and control method

InactiveCN122019324AHardware monitoringRisk quantificationBorder crossing
The invention provides a bastion host operation instruction border crossing behavior identification and control method, which comprises the following steps of: extracting an input value of a current operation instruction and a security boundary value preset by a system through a bastion host operation log, and synchronously acquiring a CPU occupancy rate, a memory usage amount and a running task number of a target host; analyzing the incidence relation among the CPU occupancy rate, the memory usage amount and the number of running tasks according to the host resource state data and the task load data, and identifying whether the host is in a light-load running state or a heavy-load running state currently to obtain a host load level; and according to the operation instruction input value, the security boundary value and the host load level, calculating the deviation degree of the operation instruction input value and the security boundary by adopting a dynamic risk quantification algorithm, and adjusting a risk weight coefficient in combination with the host load level to obtain a boundary crossing risk level.
Owner:CHINA SOUTHERN POWER GRID DIGITAL GRID GROUP (GUANGDONG) CO LTD

Implementation method and device of audit playback of a bastion

The present disclosure provides an implementation method and device for audit playback of a bastion host, wherein the method comprises: obtaining a pseudo login shell script for calling screen recording software; configuring a user login session to be bound to the pseudo login shell script; and automatically creating a directory and recording a monitoring record file through the pseudo login shell script. The present disclosure can highly restore the user operation site, ensure the integrity of each file and record, and improve the flexibility of file organization mode and the positioning efficiency.
Owner:BEIJING TTSF TECH

Security situation assessment method and device, equipment and storage medium

The invention discloses a security situation assessment method and device, equipment and a storage medium, and relates to the technical field of network security. The method comprises the following steps: acquiring host information of a to-be-evaluated host; generating a black box evaluation instruction based on the host information, sending the black box evaluation instruction to an external scanning agent node, and obtaining a black box scanning result fed back by the external scanning agent node; generating a white-box evaluation instruction based on the host information, sending the white-box evaluation instruction to a bastion host agent node, sending an inspection program to the to-be-evaluated host by the bastion host agent node according to the white-box evaluation instruction, and obtaining a white-box scanning result fed back by the to-be-evaluated host; and generating a security situation assessment report based on the black box scanning result and the white box scanning result. The comprehensiveness and efficiency of security situation assessment can be improved.
Owner:SANGFOR TECH INC

User resource management method, system, device and storage medium

This application provides a user resource management method, system, device, and storage medium. In this embodiment, when a bastion host manages user resources across VPC environments, it can request a network channel between the bastion host and an unbound VPC from a management service node deployed in a private network. The management service node can respond to the bastion host's request and establish a network channel between the bastion host and the unbound VPC using private network interface technology. In this way, the bastion host can manage user resources in other VPCs across VPC environments based on this network channel, realizing cross-VPC user resource management by the bastion host. Furthermore, since both the bastion host and the management service node are located in a private network, the devices involved in the aforementioned cross-VPC user resource management by the bastion host do not need to be exposed to the public network, reducing the public network exposure of the process and helping to improve the security of user resources in the VPC environment.
Owner:ALIBABA CLOUD COMPUTING CO LTD

Safety control system and method for business office fortress machine

The invention relates to the technical field of business office safety, and discloses a business office fortress machine safety control system and method, and the system comprises a construction module which is used for constructing a virtual operation environment for the office of external personnel, and accessing a virtual desktop through a physical terminal to carry out the office operation; the first generation module is used for carrying out real-time video recording on the office operation of the virtual desktop through the bastion host, intercepting an operation image frame on the virtual desktop, generating an operation image set and generating an operation state coefficient; the second generation module is used for capturing and analyzing transmission data between the virtual desktop and the server according to the pre-deployed packet capturing equipment, and generating a data state coefficient according to an analysis result; the control module is used for judging whether intervention is carried out or not according to the operation state coefficient and the data state coefficient, if yes, an intervention strategy is generated, an intervention instruction is issued, operation auditing reliability and data transmission behavior monitoring accuracy are improved, and business office safety is improved.
Owner:NINGXIA XINTONG NETWORK TECH CO LTD

Automatic network disconnection equipment for computer network security protection

ActiveCN224191947UImprove security protection efficiencyQuick physical barrierSubstation remote connection/disconnectionSecuring communicationBastion hostServer
The utility model belongs to the technical field of network security protection, and particularly relates to an automatic network disconnection device for computer network security protection, which comprises a software mainboard, a bastion host linkage network disconnection module electrically installed at the top of the software mainboard, an anti-DDoS system module electrically installed on one side of the bastion host linkage network disconnection module, and an anti-DDoS system module electrically installed on the other side of the software mainboard. The bottom of the software mainboard is fixedly provided with a hardware mainboard, the top of the hardware mainboard is electrically provided with a PCI slot, a bastion host is linked with a network disconnection module to terminate a session and isolate a server during abnormal login, and then an anti-DDoS system module is utilized to enable the quantity to exceed a threshold value to automatically switch and clean nodes. According to the method, the server can be isolated when the computer network logs in abnormally, so that the security protection efficiency of the computer network is improved, then the RJ-45 interface is controlled to be switched on and off through the PCI slot, then physical isolation of the internal network and the external network is achieved through the partition card, the computer network can be quickly and physically blocked, and thus the security of computer network protection is improved.
Owner:JIANGSU JISHEN INFORMATION TECH CO LTD

Methods and systems for users to access web applications

A method and system for accessing a web application (1201) accessible through a web interface includes: a user device (136) requesting access to the web application (1201) and granting the user device (136) access to the web application (1201); a bastion host orchestrator (160) creating an HTTPS bastion host (1031) based on a request from an infrastructure system (150); the user device (136) sending a request to an application router (102); the application router (102) routing the request to the HTTPS bastion host; the HTTPS bastion host rewriting the request into a rewritten request and sending the rewritten request to the web application (1201); the HTTPS bastion host (1031) receiving a response from the web application (1201); the HTTPS bastion host rewriting the response into a rewritten response and sending the rewritten response to the application router (102), and the application router (102) routing the rewritten response to the user device (136).
Owner:OVH

Sensitive information leakage early warning method and device for bastion host and storage medium

The invention discloses a sensitive information leakage early warning method and device for a bastion host and a storage medium, and belongs to the field of data security. The method comprises the steps that multi-modal data monitored by a bastion host are acquired, and the multi-modal data comprise operation and maintenance video data, system log data and network flow data; based on a pre-constructed deep learning model, performing feature layer weighted fusion on the multi-modal data to obtain a fusion feature vector which corresponds to the multi-modal data and is strongly associated with the sensitive information; based on a pre-constructed sensitive information rule base, matching the fusion feature vectors to identify target sensitive information in the multi-modal data; and triggering an early warning mechanism under the condition of detecting that the target sensitive information has a leakage sign. The leakage risk of sensitive information can be reduced.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Bastion host access control method and device based on multi-service architecture

The invention relates to a bastion host access control method and device based on a multi-service architecture. The method comprises the following steps: completing authentication with a client according to a request; after the authentication is passed, obtaining session access traffic; the session access traffic is integrated with an authentication credential generated after the authentication is passed; judging whether the current session access flow belongs to an SSH session or an SFTP session; when the first service belongs to the SSH session, based on the authentication credential, enabling the first service to establish an SSH communication link with the character assets accessed by the user through the second service; processing the current session access traffic; when the first service belongs to the SFTP session, based on the authentication credential, enabling the first service to establish an SFTP communication link with the character assets accessed by the user through the third service; processing the current session access traffic; the problem that the SSH session and the SFTP session influence each other in the prior art is solved, decoupling access of the two sessions is achieved, and direct mutual influence between the two sessions is avoided.
Owner:ZHEJIANG QIZHI TECH CO LTD

Power grid dispatching cloud platform access authentication method and device based on a bastion host, equipment, storage medium and program product

The application relates to a bastion machine-based power grid dispatching cloud platform access authentication method and device, equipment, a storage medium and a program product, and relates to the technical field of information security. The method can reduce the security risks existing when remotely accessing the power grid dispatching cloud platform, and efficiently stores operation information. The method comprises the following steps: sending an access request of a current user to a configured OTP server, so that the OTP server generates a password password and a detection token according to the access request; obtaining a username of the current user, and receiving the password password and the detection token returned by the OTP server; the username, the password password and the detection token are packaged and sent to a bastion machine, the bastion machine verifies the detection token according to the username, in the case that the detection token verification is passed, the bastion machine sends the password password to the OTP server, and the OTP server verifies the password password; in the case that the password password verification is passed, the bastion machine is logged in, and the power grid dispatching cloud platform is accessed through the bastion machine.
Owner:CHINA SOUTHERN POWER GRID COMPANY

Operation and maintenance method, system and equipment, computer program product and storage medium

PendingCN122069158ASecuring communicationPrivate networkEndpoint security
The embodiment of the invention provides an operation and maintenance method, system and device, a computer program product and a storage medium. A bastion host created for a user is in communication connection with a server in an endpoint security service used by the user, so that the bastion host can break through the isolation limitation of a virtual private network by virtue of the cross-virtual private network traffic forwarding capability of the endpoint security service, and the security of the user is improved. The operation and maintenance instruction can be transmitted to any cloud asset in any virtual private network of a user in a barrier-free manner so as to carry out resource operation and maintenance. Therefore, in the embodiment of the invention, under the condition that asset operation and maintenance need to be carried out on the plurality of virtual private networks of the user, the operation and maintenance instruction for any cloud asset in any virtual private network of the target user can be processed in a centralized manner through one bastion host, and the bastion host does not need to be independently deployed in each virtual private network, so that the operation and maintenance of the cloud assets in the virtual private networks of the target user are facilitated. And the use cost of the bastion host can be effectively saved.
Owner:ALIBABA CLOUD COMPUTING CO LTD

Information system operation and maintenance management method and system based on bastion host and artificial intelligence

The invention relates to the technical field of information system operation and maintenance management, in particular to an information system operation and maintenance management method and system based on a bastion host and artificial intelligence, and the method comprises the steps: obtaining a keyboard tapping interval time record, a mouse moving position record and a screen operation area stay duration record in real time; extracting an operation speed change value from the track offset metric value, performing combined calculation on the operation speed change value and a staying duration record of the screen operation area, and evaluating a ratio record related to the relevance between the operation speed change and the staying duration extension according to the time sequence change; and applying an exception identification rule to the user operation behavior record according to the risk level label, adjusting and updating a critical value adjustment standard according to the record, and adjusting the identification sensitivity through a loop optimization process to obtain an optimized critical value combination. According to the method, the dynamic association between the operation speed change and the interface stay duration can be captured in a complex scene, so that accurate behavior anomaly recognition is realized, and the management accuracy and practicability are improved.
Owner:GUANGDONG POWER GRID CO LTD INFORMATION CENT

Intranet host operation and maintenance method

PendingCN121750296ASecuring communicationReverse proxyBastion host
The embodiment of the invention provides an intranet host operation and maintenance method which is used for solving the problems that in the prior art, a normal exposure surface exists, the risk of transversely permeating all resources exists when attacks happen, and severe network security threats exist. The reverse proxy server receives the operation and maintenance request sent by the bastion host, and determines a target port number of the operation and maintenance request received by the reverse proxy server carried in the operation and maintenance request; determining a target reverse proxy agent corresponding to the target port number according to a corresponding relationship between the stored reverse proxy server port number and a reverse proxy agent identifier; the operation and maintenance request is forwarded to the target reverse agent, intranet assets are hidden in a normal state, authority control is refined, the damage radius of a security event can be effectively restrained in an extreme condition, and therefore the overall security and reliability are improved.
Owner:CHINA TELECOM NETWORK SECURITY TECH CO LTD

Method and device for controlling access of bastion host based on multi-service architecture

ActiveCN121530769Bavoid direct interactionUser identity/authority verificationInternet privacyEngineering
The application relates to a bastion host access management method and device based on a multi-service architecture, wherein the method comprises the following steps: completing authentication with a client according to a request; obtaining session access traffic after the authentication is passed; the session access traffic is integrated with authentication credentials generated after the authentication is passed; judging whether the current session access traffic belongs to an SSH session or an SFTP session; when the current session access traffic belongs to the SSH session, enabling a first service to establish an SSH communication link with character assets accessed by a user through a second service based on the authentication credentials; processing the current session access traffic; when the current session access traffic belongs to the SFTP session, enabling the first service to establish an SFTP communication link with the character assets accessed by the user through a third service based on the authentication credentials; and processing the current session access traffic. The method solves the problem that SSH sessions and SFTP sessions influence each other in the related art, realizes decoupled access of the two sessions, and avoids direct mutual influence between the two sessions.
Owner:ZHEJIANG QIZHI TECH CO LTD

Storage resource management method and device

The invention relates to the technical field of computers, and provides a storage resource management method and device. The method comprises the following steps: acquiring a user login request; redirecting the user login request to a target server operating system through a bastion host; collecting the storage resource use information of each current user account in real time by using the storage resource attribute identifier corresponding to the target server operating system; according to the storage resource use information of each current user account, performing freezing operation on a target user account by using the bastion host; and performing storage resource directional management and control processing based on the freezing operation. Through the embodiment of the invention, the problem of uneven distribution of the storage resources can be improved by automatically managing and controlling the storage resources of the server operating system supporting simultaneous login of multiple users.
Owner:CHINA CITIC BANK CO LTD

Fortress machine distribution method and device, storage medium and electronic equipment

The application discloses a distribution method and device of a bastion host, a storage medium and an electronic device. The method comprises the following steps: obtaining a service access request of a target client, wherein the service access request carries address information of a target server where service data to be accessed is located; in the case that sensitive level indication information matched with the address information of the target server is found, determining a target bastion host type matched with the sensitive level indication information; obtaining state parameters of each bastion host in a bastion host set corresponding to the target bastion host type; determining a target bastion host from the bastion hosts according to the state parameters; and distributing the target bastion host to the target client, so that the target client accesses the target server through the target bastion host. The application solves the technical problem that the manual selection of the bastion host is relatively complex.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

Bastion host creation and request processing method and device, storage medium and program product

The embodiment of the invention provides a bastion host creation method and device, a bastion host request processing method and device, a storage medium and a program product. In the bastion host creation method, when a bastion host used for managing virtual resources is created in a first virtual private cloud network, a network segment corresponding to a second virtual private cloud network where the virtual resources are located can be obtained, and the network segment used for creating the bastion host is selected by avoiding the network segment of the second virtual private cloud network. Furthermore, under the condition that the network segment corresponding to the virtual private cloud network can be self-defined, the risk of network segment conflict between the bastion host and the virtual resource in different virtual private cloud networks is reduced, and the availability of the bastion host during management of the virtual resource is improved.
Owner:ALIBABA CLOUD COMPUTING CO LTD