Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

64 results about "Bastion host" patented technology

A bastion host is a special-purpose computer on a network specifically designed and configured to withstand attacks. The computer generally hosts a single application, for example a proxy server, and all other services are removed or limited to reduce the threat to the computer. It is hardened in this manner primarily due to its location and purpose, which is either on the outside of a firewall or in a demilitarized zone (DMZ) and usually involves access from untrusted networks or computers.

Multi-protocol integration method and device, equipment, storage medium and program product

The invention relates to a multi-protocol integration method and device, equipment, a storage medium and a program product, which are applied to a bastion host, and the bastion host comprises a communication port. The method comprises the following steps: firstly, receiving a first access request generated based on a first protocol and sent by each client through a communication port, then, determining target equipment needing to be accessed by each client according to the first access request, then, determining a second protocol supported by each target equipment based on preset configuration of each target equipment, and finally, sending the second protocol to the client through the communication port. And converting each first access request based on the first protocol and the second protocol, determining a second access request of each client, and accessing the corresponding target device through the second access request. By adopting the method, the number of communication ports can be reduced, so that the network attack surface is reduced, potential security holes and threats are reduced, and the access security of the target equipment is improved.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Power grid dispatching cloud platform access authentication method, device and equipment based on bastion host, storage medium and program product

The invention relates to a power grid dispatching cloud platform access authentication method, device and equipment based on a bastion host, a storage medium and a program product, and relates to the technical field of information security. According to the method, the security risk existing when the power grid dispatching cloud platform is remotely accessed can be reduced, and the operation information is efficiently stored. The method comprises the following steps: sending an access request of a current user to a configured OTP server, so that the OTP server generates a password and a detection token according to the access request; the method comprises the following steps: acquiring a user name of a current user, receiving a password and a detection token returned by an OTP server, packaging and sending the user name, the password and the detection token to a bastion host, verifying the detection token by the bastion host according to the user name, and sending the password to the OTP server by the bastion host under the condition that the verification of the detection token is passed, the OTP server verifies the password password; and logging in the bastion host under the condition that the password verification is passed, and accessing the power grid dispatching cloud platform through the bastion host.
Owner:CHINA SOUTHERN POWER GRID COMPANY

RAG-based bastion host intelligent operation guidance method and system

The invention discloses a bastion host intelligent operation guidance method and system based on RAG, and the method comprises the following steps: carrying out the partitioning processing of a bastion host operation document, constructing an operation document knowledge base and a vector database, and improving the semantic consistency of the document content; creating a chat window, and proposing an original natural language operation query; according to the method, the original natural language operation query is optimized and reconstructed to obtain a semantic optimization result of frame structuring, and the original natural language operation query is converted into an operation query vector, so that oral language content and semantic ambiguity of the operation query are effectively reduced, and standardized query content is provided for generation of operation guidance; therefore, the accuracy of operation guidance generation can be improved. Similarity retrieval is carried out, through a two-step retrieval method, the retrieval difficulty is reduced, the retrieval effect is improved, and context information with high semantic correlation is provided for generation of operation guidance; and inputting the retrieval content and the operation query into a dialogue model, and generating an operation instruction and a command instruction.
Owner:BEIJING LONGERSEC TECH CO LTD +1

Public data fusion development platform

The invention discloses a public data fusion development platform which comprises a platform portal website, a business center, a capability support plate and an infrastructure layer. The platform web portal serves as a user layer to provide an external service window; the business center serves as a business layer and comprises an operation management system, a second-level development system and a competition management system which serve a first-level development subject, a second-level development subject and the public respectively. The capability supporting plate serves as a middle table layer and comprises a data management system, a resource management system, a privacy computing system and an operation and maintenance management system which are used for providing data management, resource scheduling, security computing and full-life-cycle operation and maintenance support for the service center; the infrastructure layer provides one or more infrastructures including a cloud resource pool, a privacy computing environment, a computing engine, containerization, a scheduling engine, intrusion protection, threat detection, a firewall, and a bastion host for the capability support section.
Owner:XIAMEN BIG DATA CO LTD

Data processing method and device, storage medium and electronic equipment

The invention discloses a data processing method and device, a storage medium and electronic equipment. Relates to the field of financial science and technology, and the method comprises the following steps: obtaining device information of a plurality of devices in a device management platform through a bastion host, the device information at least comprising device parameter information and first user identity information corresponding to the devices; comparing second user identity information in the bastion host with the first user identity information to obtain a target user list; and performing data change processing on the identity information corresponding to the target user list through the bastion host to obtain a processing result. Through the method and the device, the problem of relatively low processing efficiency of the user data caused by management of the user data of the equipment based on a manual mode in related technologies is solved.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

An identity authentication method and device based on a commercial cipher algorithm

PendingCN122640127AAlgorithmSession key
The application discloses an identity authentication method and device based on commercial cryptographic algorithms, which is applied to a bastion host operation and maintenance scene, and relies on SM2, SM3 and SM4 commercial cryptographic algorithms, and realizes high-security and high-performance two-way identity authentication. The method strictly follows the core process of GB / T 15843.3-2023 standard, and the standard is optimized and enhanced in multiple dimensions through commercial cryptographic algorithms, including true random number hardware generation, SM2 signature verification enhancement, SM3 session key derivation, SM4 transmission encryption and other steps, to make up for the lack of standard original protection and complete two-way identity authentication. The application strengthens the commercial cryptographic algorithm set of hardware devices, and is deeply integrated with the optimized standard, effectively solves the problems of private key leakage, performance bottleneck and standard protection short board of the existing scheme, meets the compliance requirements of equal protection and secret evaluation, and provides a reliable identity access solution for remote operation and maintenance of the bastion host.
Owner:TOEC ANCHEN INFORMATION TECH

Data transmission method and related apparatus

The embodiment of the application provides a data transmission method and related device, which are applied to the field of communication. The method comprises the following steps: a first device logs in a bastion host through ssh; the first device receives and responds to a first operation for selecting a second device from a plurality of device identifiers, and establishes a communication connection with the second device through the bastion host. The first device receives a shortcut key command and sends the shortcut key command to a session management module of the bastion host. The bastion host converts the shortcut key command into a control command, and interacts with the second device according to the control command to obtain a service address of a server corresponding to the second device. The first device accesses the server according to the service address from the bastion host to download data in the second device or upload data to the second device through the server. In this way, the service address for file transmission is obtained on the bastion host through the shortcut key command, and file transmission is realized through the service address. This method is simple to operate, convenient for file transmission, small in resource occupation, and low in governance cost.
Owner:BEIJING WODONG TIANJUN INFORMATION TECH CO LTD +1

Method and management method for accessing business database

The application discloses a business database access method and management and control method, and belongs to the field of data security. The method comprises the following steps: a client obtains channel configuration information of a target database through a bastion host, wherein the channel configuration information comprises channel address information between the bastion host and the target database; the client sends a first access request to the bastion host based on the channel address information, wherein the first access request carries the channel address information and an access condition; and the client receives an access result meeting the access condition, which is obtained by the bastion host from the target database based on the channel address information.
Owner:CHINA MOBILE GROUP ZHEJIANG +1

Intranet security operation and maintenance method and device based on bastion host, medium and program product

The embodiment of the invention provides an intranet security operation and maintenance method and device based on a bastion host, a medium and a program product, and relates to the technical field of operation and maintenance management. The method comprises the following steps: in response to a connection request actively initiated by a zero-trust proxy client, establishing an end-to-end encrypted application layer tunnel between a zero-trust proxy server and the zero-trust proxy client under the condition that bidirectional authentication is passed; acquiring context information corresponding to the operation and maintenance terminal, and determining a dynamic authorization strategy based on the context information; and performing operation and maintenance management and control on the operation and maintenance operation of the operation and maintenance terminal based on the dynamic authorization strategy, and transmitting operation and maintenance traffic generated between the operation and maintenance terminal and the intranet resource side through the application layer tunnel. According to the embodiment of the invention, the zero-trust system model taking the internal resource side as the active connection end is constructed, and the dynamic authorization strategy is generated by acquiring the related context information in real time, so that the security of internal network operation and maintenance is greatly improved.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Train network security protection method and system and storage medium

The invention provides a train network security protection method, a train network security protection system and a computer readable storage medium. The train network security protection method comprises the following steps: carrying out identity authentication on an external system, and identifying an equipment category and a corresponding port of the external system; in response to the fact that the equipment category of the external system is maintenance equipment, starting a bastion host function; and in response to the fact that the equipment category of the external system is communication equipment, based on the configuration of the corresponding port, starting a security audit and intrusion detection function or a firewall function, the starting of the security audit and intrusion detection function or the firewall function comprising analysis of a message of a train-specific protocol and control data thereof. According to the train network safety protection method, multiple safety protection functions can be achieved at the same time, the number of safety devices and the size of a train communication network are reduced, analysis of a train special protocol is achieved, and therefore more efficient protection is achieved in a rail transit vehicle-mounted network.
Owner:CRRC ZHUZHOU ELECTRIC LOCOMOTIVE RESEARCH INSTITUTE CO LTD

Identity authentication method, device and equipment, and computer storage medium

The application discloses an identity authentication method, device and equipment and a computer storage medium. The method is applied to a bastion host and comprises the following steps: obtaining a user account; sending a biological identification request to a server, so that the server randomly generates a user credential code, sends the user credential code to a terminal device, the terminal device collects first target biological information, compares the first target biological information with prestored biological information, obtains a first target biological identification result, marks a target mark corresponding to the first target biological identification result in the user credential code, obtains a target user credential code, encrypts the target user credential code, obtains an encrypted user credential code, sends the encrypted user credential code to the server, the server decrypts the encrypted user credential code, and obtains the target user credential code; and in the case that the target mark in the target user credential code is a first mark, receiving identity authentication passing information sent by the server. The security of server resources is improved.
Owner:CHINA MOBILE GROUP ANHUI +1

Security access method, device and equipment based on bastion host and storage medium

The invention provides a security access method and device based on a bastion host, equipment and a storage medium, and is applied to the technical field of information security, and the method applied to first equipment which cannot directly perform identity verification with the bastion host comprises the following steps: sending a login request to the bastion host through second equipment according to an access operation of a user, the second equipment is user equipment which is authenticated by the bastion host identity of the same user; if the forwarded login failure signal is received, generating a first verification request according to the user credential and a validity verification factor corresponding to the second equipment, and sending the first verification request to the second equipment; and receiving verification result information fed back by the identity verification server and forwarded by the second equipment, logging in the bastion host under the condition that the verification is passed, and establishing access connection with the target access server. According to the method and the device, the user password does not need to be input in the bastion host, so that the login of the user equipment which cannot directly log in the bastion host is ensured, the user experience is improved, and the information security is improved.
Owner:CHINA MOBILE GROUP JIANGSU +1

Data desensitization method based on bastion host operation and maintenance and computer program product

The invention provides a data desensitization method based on bastion host operation and maintenance, a computer program product, electronic equipment and a storage medium, and the method comprises the steps: obtaining communication traffic of bastion host operation and maintenance; analyzing the communication flow to obtain standardized format data; inputting the standardized format data into a pre-constructed large model for sensitive data identification to obtain sensitive data and a corresponding sensitive degree; querying a pre-constructed permission desensitization strategy mapping table according to the sensitive data and the corresponding sensitive degree to obtain a desensitization strategy; and desensitizing the sensitive data according to the desensitization strategy. By implementing the application, accurate classification and identification of sensitive data can be realized, different desensitization strategies can be carried out according to different protocol types, various fine-grained desensitization can be realized, desensitization can be carried out according to operation and maintenance rights, and the desensitization process is more flexible and controllable.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

High-risk command identification method and device of bastion host, computer equipment and storage medium

The invention relates to a high-risk command recognition method and device of a bastion host, computer equipment and a storage medium, and the method comprises the steps: loading a user-defined rule corresponding to target equipment to an output state processor of a character module based on a configuration file after a session is started; echoed data corresponding to a last command input by a user client is transmitted to an output state processor; in the output state processor, matching is carried out according to the echo data, the user-defined rule and a preset built-in rule, and session state conversion is carried out according to a matching result so as to enter a corresponding session state; and when entering the corresponding session state and determining that the current command input by the user client is submitted, carrying out high-risk command identification on the current command. Through the method and the device, the problem of low accuracy of high-risk command identification in related technologies is solved, and accurate session state switching is realized, so that the accuracy of high-risk command identification is maintained, and the command control capability of the bastion host is improved.
Owner:ZHEJIANG QIZHI TECH CO LTD

Network security maintenance bastion host

The utility model discloses a network security maintenance bastion host, which belongs to the technical field of bastion hosts, and comprises a bastion host main body, a boss is fixedly connected to one side of the outer surface of the bastion host main body, and a plurality of uniformly distributed Ethernet ports are formed in one side, far away from the bastion host main body, of the outer surface of the boss. A power supply socket is formed in a position, far away from the boss, of one side of the outer surface of the bastion host main body. Through the arrangement of the dustproof mechanism, two dustproof covers are driven to rotate away from each other by moving a convex block, then a network cable is inserted into the Ethernet port, and then a sliding plate is driven by a first spring, so that the two dustproof covers rotate close to each other, and meanwhile, the network cable is located in a semicircular groove; according to the bastion host, the two dustproof covers are arranged, so that one end of the network cable and the Ethernet port are sealed in the two dustproof covers, dust is prevented from being accumulated at the position where the network cable is inserted into the Ethernet port, normal use of the bastion host is ensured, and the use effect of the bastion host is improved.
Owner:任晓峰 +3

Security protection method and device for bastion host of sensor application and medium

The invention relates to the technical field of network operation and maintenance, and discloses a bastion host security protection method and device for sensor application, and a medium, and the method comprises the steps: deploying a sensor in a bastion host; user information is input into the perception body, and the perception body obtains the strategy component to perform preliminary authentication on the user information; after the preliminary authentication is passed, the perception body opens up a virtual space of the user; re-authentication is carried out based on user information in the virtual space, and if authentication succeeds, the user successfully logs in the bastion host; the perception body calls the bastion host agent component for the user to perform application access; the perception body obtains a user behavior; and if the user behavior is abnormal, interrupting the user access, and updating the policy component. According to the invention, intelligent configuration and management can be completed, and comprehensive safety protection and threat perception of enterprise operation and maintenance data are realized.
Owner:WUHAN ZIRUI DONGCHUANG TECHNOLOGY CO LTD

Anti-misoperation method for bastion fortress and computer program product

The invention provides an anti-misoperation method for a bastion fortress, a computer program product, electronic equipment and a storage medium, and the method comprises the steps: obtaining an input command; intercepting the input command according to a fortress session agent; performing risk level evaluation on the intercepted input command to obtain a risk level corresponding to the input command; performing safe second-reading buffer processing on the input command according to the risk level, and creating a countdown task; and executing the countdown task, and completing the issuing process of the input command. By implementing the application, the operation can be buffered through safe second reading, misoperation is effectively prevented, the real-time control capability of the execution process is improved, an isolation layer is established between command identification and execution, interruptible and delayed release of high-risk operation is ensured, and the flexible control of the operation is improved.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Permission hierarchical control method and operation and maintenance bastion system based on dynamic desensitization and real-time monitoring

An embodiment of the present invention discloses a permission hierarchical control method and an operation and maintenance bastion host system based on dynamic desensitization and real-time monitoring. The embodiment of the present invention significantly improves data security and operational compliance in operation and maintenance scenarios by integrating a database firewall and a dual-mode desensitization engine, combining permission hierarchical control and real-time semantic analysis. Dynamic desensitization rewrites query statements in real time according to user roles to limit the exposure of original data; static desensitization pre-generates isolated copies to reduce direct access to production libraries; based on semantic analysis and rule engines, the response time is shortened to within 1 second; the static desensitization library supports direct use in development and testing, reducing the permission application process; and the rule library is dynamically updated through the Attention-GRU-Adaboost model to improve adaptability to new attack patterns.
Owner:CENTURY LONGMAI TECH

Remote operation and maintenance method, system and device, storage medium and program product

The invention provides a remote operation and maintenance method, system and device, a storage medium and a program product, and the remote operation and maintenance method applied to a bastion host comprises the steps: building encrypted session channels between the bastion host and an operation and maintenance end and between the bastion host and a target terminal; receiving an operation and maintenance instruction data frame sent by an operation and maintenance end through the encrypted session channel; forwarding the operation and maintenance instruction data frame to a target terminal; and receiving an execution result data frame returned by the target terminal, and sending the execution result data frame to the operation and maintenance terminal. According to the method, unified operation and maintenance control of a single set of protocols on a heterogeneous system is realized by constructing a three-section communication architecture of a unified protocol layer, a system adaptation layer and a protocol agent layer in a cooperative manner, and the problem of protocol and system deep coupling caused by independently developing an adaptation plug-in for each operating system in a traditional scheme is solved.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

A method, apparatus, and electronic device for command approval in a bastion host.

This invention discloses a method, apparatus, and electronic device for instruction approval in a bastion host, belonging to the field of network security technology. The method includes: receiving an input instruction input through the bastion host; obtaining a first fuzzy hash calculation result of the input instruction, and obtaining a second fuzzy hash calculation result for each restricted instruction in a preset set of restricted instructions; determining that the input instruction has not passed approval if at least one of the second fuzzy hash calculation results and the first fuzzy hash calculation result has a target similarity greater than or equal to a preset threshold. This invention can improve the security control capabilities of the bastion host.
Owner:CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1

Bastion host operation instruction border crossing behavior identification and control method

The invention provides a bastion host operation instruction border crossing behavior identification and control method, which comprises the following steps of: extracting an input value of a current operation instruction and a security boundary value preset by a system through a bastion host operation log, and synchronously acquiring a CPU occupancy rate, a memory usage amount and a running task number of a target host; analyzing the incidence relation among the CPU occupancy rate, the memory usage amount and the number of running tasks according to the host resource state data and the task load data, and identifying whether the host is in a light-load running state or a heavy-load running state currently to obtain a host load level; and according to the operation instruction input value, the security boundary value and the host load level, calculating the deviation degree of the operation instruction input value and the security boundary by adopting a dynamic risk quantification algorithm, and adjusting a risk weight coefficient in combination with the host load level to obtain a boundary crossing risk level.
Owner:CHINA SOUTHERN POWER GRID DIGITAL GRID GROUP (GUANGDONG) CO LTD

Implementation method and device of audit playback of a bastion

The present disclosure provides an implementation method and device for audit playback of a bastion host, wherein the method comprises: obtaining a pseudo login shell script for calling screen recording software; configuring a user login session to be bound to the pseudo login shell script; and automatically creating a directory and recording a monitoring record file through the pseudo login shell script. The present disclosure can highly restore the user operation site, ensure the integrity of each file and record, and improve the flexibility of file organization mode and the positioning efficiency.
Owner:BEIJING TTSF TECH

Security situation assessment method and device, equipment and storage medium

The invention discloses a security situation assessment method and device, equipment and a storage medium, and relates to the technical field of network security. The method comprises the following steps: acquiring host information of a to-be-evaluated host; generating a black box evaluation instruction based on the host information, sending the black box evaluation instruction to an external scanning agent node, and obtaining a black box scanning result fed back by the external scanning agent node; generating a white-box evaluation instruction based on the host information, sending the white-box evaluation instruction to a bastion host agent node, sending an inspection program to the to-be-evaluated host by the bastion host agent node according to the white-box evaluation instruction, and obtaining a white-box scanning result fed back by the to-be-evaluated host; and generating a security situation assessment report based on the black box scanning result and the white box scanning result. The comprehensiveness and efficiency of security situation assessment can be improved.
Owner:SANGFOR TECH INC

User resource management method, system, device and storage medium

This application provides a user resource management method, system, device, and storage medium. In this embodiment, when a bastion host manages user resources across VPC environments, it can request a network channel between the bastion host and an unbound VPC from a management service node deployed in a private network. The management service node can respond to the bastion host's request and establish a network channel between the bastion host and the unbound VPC using private network interface technology. In this way, the bastion host can manage user resources in other VPCs across VPC environments based on this network channel, realizing cross-VPC user resource management by the bastion host. Furthermore, since both the bastion host and the management service node are located in a private network, the devices involved in the aforementioned cross-VPC user resource management by the bastion host do not need to be exposed to the public network, reducing the public network exposure of the process and helping to improve the security of user resources in the VPC environment.
Owner:ALIBABA CLOUD COMPUTING CO LTD

Safety control system and method for business office fortress machine

The invention relates to the technical field of business office safety, and discloses a business office fortress machine safety control system and method, and the system comprises a construction module which is used for constructing a virtual operation environment for the office of external personnel, and accessing a virtual desktop through a physical terminal to carry out the office operation; the first generation module is used for carrying out real-time video recording on the office operation of the virtual desktop through the bastion host, intercepting an operation image frame on the virtual desktop, generating an operation image set and generating an operation state coefficient; the second generation module is used for capturing and analyzing transmission data between the virtual desktop and the server according to the pre-deployed packet capturing equipment, and generating a data state coefficient according to an analysis result; the control module is used for judging whether intervention is carried out or not according to the operation state coefficient and the data state coefficient, if yes, an intervention strategy is generated, an intervention instruction is issued, operation auditing reliability and data transmission behavior monitoring accuracy are improved, and business office safety is improved.
Owner:NINGXIA XINTONG NETWORK TECH CO LTD

Automatic network disconnection equipment for computer network security protection

ActiveCN224191947UImprove security protection efficiencyQuick physical barrierSubstation remote connection/disconnectionSecuring communicationBastion hostServer
The utility model belongs to the technical field of network security protection, and particularly relates to an automatic network disconnection device for computer network security protection, which comprises a software mainboard, a bastion host linkage network disconnection module electrically installed at the top of the software mainboard, an anti-DDoS system module electrically installed on one side of the bastion host linkage network disconnection module, and an anti-DDoS system module electrically installed on the other side of the software mainboard. The bottom of the software mainboard is fixedly provided with a hardware mainboard, the top of the hardware mainboard is electrically provided with a PCI slot, a bastion host is linked with a network disconnection module to terminate a session and isolate a server during abnormal login, and then an anti-DDoS system module is utilized to enable the quantity to exceed a threshold value to automatically switch and clean nodes. According to the method, the server can be isolated when the computer network logs in abnormally, so that the security protection efficiency of the computer network is improved, then the RJ-45 interface is controlled to be switched on and off through the PCI slot, then physical isolation of the internal network and the external network is achieved through the partition card, the computer network can be quickly and physically blocked, and thus the security of computer network protection is improved.
Owner:JIANGSU JISHEN INFORMATION TECH CO LTD

Methods and systems for users to access web applications

A method and system for accessing a web application (1201) accessible through a web interface includes: a user device (136) requesting access to the web application (1201) and granting the user device (136) access to the web application (1201); a bastion host orchestrator (160) creating an HTTPS bastion host (1031) based on a request from an infrastructure system (150); the user device (136) sending a request to an application router (102); the application router (102) routing the request to the HTTPS bastion host; the HTTPS bastion host rewriting the request into a rewritten request and sending the rewritten request to the web application (1201); the HTTPS bastion host (1031) receiving a response from the web application (1201); the HTTPS bastion host rewriting the response into a rewritten response and sending the rewritten response to the application router (102), and the application router (102) routing the rewritten response to the user device (136).
Owner:OVH

Data leakage behavior checking method and device, computer device and storage medium

The embodiment of the application discloses a data leakage behavior check and control method, comprising obtaining user original behavior data from VPN, a bastion host, a database, office OA, a cloud platform and a terminal, wherein the obtained user original data comprises abnormal behavior of the user in acquiring data through operating a document, taking a screenshot and shooting a video, and the abnormal behavior comprises sensitive data access, unauthorized operation and abnormal time login; preprocessing the obtained user original behavior data, comprising cleaning, analyzing, enriching and normalizing storage; performing real-time risk rule matching on the obtained preprocessed data according to a preset risk rule through a machine learning algorithm, obtaining a risk score according to the matching condition, judging whether there is a violation risk according to the risk score, and generating a visual risk portrait according to the violation risk; and outputting alarm information according to an alarm rule. The application realizes accurate prevention and control of data leakage risk.
Owner:SHENZHEN YUEHUA EXPRESS CO LTD

A request processing method, system and electronic device

The application provides a request processing method and system and an electronic device, and relates to the technical field of communication.The method comprises the following steps: receiving an access request sent by a client, identifying access information;generating request information related to the access request and sending the request information to an authentication server;responding to verification information sent by the authentication server, processing the access request according to the verification information.Through providing an additional security layer, the identity of the client is verified, ensuring that only clients with access rights can access the bastion host, reducing the risk of directly exposing the interface of the bastion host to the public network.Through access limitation, the security of the bastion host is improved, the refinement of access control is realized, and the possibility of potential illegal access is reduced.The technical problem of single-point failure risk caused by centralized management in the prior art is solved, and the stability, security and reliability of the system are ensured.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Sensitive information leakage early warning method and device for bastion host and storage medium

The invention discloses a sensitive information leakage early warning method and device for a bastion host and a storage medium, and belongs to the field of data security. The method comprises the steps that multi-modal data monitored by a bastion host are acquired, and the multi-modal data comprise operation and maintenance video data, system log data and network flow data; based on a pre-constructed deep learning model, performing feature layer weighted fusion on the multi-modal data to obtain a fusion feature vector which corresponds to the multi-modal data and is strongly associated with the sensitive information; based on a pre-constructed sensitive information rule base, matching the fusion feature vectors to identify target sensitive information in the multi-modal data; and triggering an early warning mechanism under the condition of detecting that the target sensitive information has a leakage sign. The leakage risk of sensitive information can be reduced.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2