Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

21 results about "Jump server" patented technology

A jump server, jump host or jump box is a computer on a network used to access and manage devices in a separate security zone. The most common example is managing a host in a DMZ from trusted networks or computers.

Windows domain penetration test system and method based on deep reinforcement learning

The invention discloses a Windows domain penetration test system and method based on deep reinforcement learning. The system comprises an information collection module, a vulnerability detection module, an agent generation module and an agent training module. A host in an intranet domain is used as a springboard machine, an information collection module is deployed, and all network nodes in the domain are subjected to comprehensive information collection; generating a configuration file for constructing an intelligent agent according to the information in the domain, and constructing the deep reinforcement learning intelligent agent through the configuration file; and the intelligent agent automatically verifies all possible potential safety hazards in the domain environment by using a vulnerability detection module, learns in detection, and finally generates all possible safety problems in the domain. According to the method, the automatic penetration testing technology is utilized, full-automatic penetration testing and risk assessment of the domain environment are achieved, deep reinforcement learning is combined, various safety problems in the Windows domain are found more accurately, resources are allocated efficiently, high-risk path areas are defended in a centralized mode, and therefore the overall network safety is enhanced.
Owner:NANJING UNIV OF POSTS & TELECOMM

Container Application Script Execution Method, Device, System, Electronic Device and Medium

Embodiments of the present disclosure disclose a method, apparatus, system, electronic device, and medium for executing a container application script. A specific implementation of the method includes: in response to receiving a container application script execution request, obtaining a container private key, a jump server identifier, and a jump server private key corresponding to the jump server identifier from a key management system; connecting to the jump server corresponding to the jump server identifier through the jump server private key; sending the container private key and a container application script execution command corresponding to the container application script execution request to the jump server, so that the jump server sends the container application script execution command to the container after connecting to the container through the container private key; and in response to receiving a container application script execution result corresponding to the container application script execution command sent by the jump server, sending the container application script execution result to a request side corresponding to the container application script execution request. This implementation is related to information security and container technology, improves the security of the container, and avoids process blocking of the container.
Owner:JD DIGITS HAIYI INFORMATION TECHNOLOGY CO LTD

Checking performance related to distributed units (DU) and radio units (RU) in a 5th generation (5G) network

A jump server receives a command to check performance of one or more Distributed Units (DUs) or one or more Radio Units (RUs) at one or more cell sites. In response, the jump server executes a wrapper script that logs into a performance server, copies at least one input file that identifies the one or more DUs or the one or more RUs and a performance script to a user-specific directory at the performance server and initiates execution of the performance script at the performance server. The execution of the performance script causes the performance server to run a set of performance checking procedures on the one or more DUs or the one or more RUs identified in the input file, generate an output log file that comprises results of running the set of performance procedures, and store the output log file in the user specific directory.
Owner:DISH WIRELESS LLC

Non-containerized service operation and maintenance method based on different network environments of a jump machine

ActiveCN119211050BTransmissionOperating systemJump server
The application provides a non-containerized service operation and maintenance method based on a different network environment of a jump machine, the method comprising: creating a login account of a code hosting tool, setting corresponding permissions therefor, and pushing the code of a business system to the login account as needed; the non-containerized service operation and maintenance method based on the different network environment of the jump machine provides a visual interface for the pushed code in environment 1, and compiles and packages the code after selection according to actual needs; and the application provides a method for realizing non-containerized front-end and back-end engineering service operation and maintenance by taking the jump machine as a transfer station and integrating deployment and operation and maintenance work in two different network environments while indirectly connecting the two different network environments.
Owner:CHANGHE AIRCRAFT INDUSTRIES CORPORATION

Cloud resource service assessment data credibility assessment method and application

The invention discloses a cloud resource service assessment data credibility assessment method. The method comprises the following steps: 1) deploying a monitoring agent on a cloud resource for data acquisition; (2) the monitoring agent synchronously collects operation data of a cloud service availability data set Dprobe and an availability data set Dvendor of a corresponding service reported by a cloud service provider cloud management platform at a preset time interval; (3) reporting the operation data acquired in the step (1) to a fat Agent in a springboard machine; the cloud resource service assessment data credibility assessment method comprises the steps of (1) collecting data of each monitoring agent, (2) processing and converging the data of each monitoring agent by the fat agent and then reporting the data, and (5) performing credibility assessment based on the set F in the step (2) and the set M in the step (4) and calculating a credibility assessment factor C. The cloud resource service assessment data credibility assessment method can eliminate human subjective factors and improve objectivity and operability of credibility assessment.
Owner:DIGITAL HUNAN CO LTD

Method for accessing intranet service and management system

The invention provides a method for accessing an intranet service and a management system. The method comprises the following steps: receiving an access request from a user side through public network equipment of a public network; the method comprises the following steps: receiving state information of a springboard machine and an intranet device sent by a jump node through a public network device, and distributing login information of a first springboard machine and a first intranet device to a user side according to experience requests of different users and device information of the springboard machine and the intranet device, therefore, the user can access the target service on the first intranet equipment through the first springboard machine according to the login information of the first springboard machine and the first intranet equipment. According to the method, the user side of the public network, the springboard machine of the intranet and the equipment side of the intranet are managed at the same time, the access process of the user is simplified under the condition that the safety is guaranteed, the user experience is improved, and resource allocation of the intranet laboratory is more reasonable.
Owner:XFUSION DIGITAL TECH CO LTD

An automated testing apparatus for GPU rendering output

The application provides an automatic testing device for GPU rendering output, comprising a host computer, a product library platform and a testing environment platform, wherein the testing environment platform comprises a testing machine and a jump machine; video stream information of GPU rendering output on the testing machine is output to another jump machine responsible for streaming through a video capture card; an open source video recording component is deployed on the jump machine to obtain the video stream information, thereby avoiding the problem of low image frame quality caused by the way of obtaining the video stream through a camera and reducing the running overhead of the testing machine in video streaming; the video stream information obtained on the jump machine is subjected to image feature extraction through an image processing method, and then compared and analyzed with standard sample image feature information in a database of the host computer, so that the test result is efficiently and accurately obtained.
Owner:WUHAN LINGJIU MICROELECTRONICS CO LTD

Asset detection methods and devices for attack purposes

This invention provides a method and apparatus for asset detection at the attack end. The method includes: acquiring the attack end's preference rules for the jump servers based on intelligence data of known jump servers; determining the content management system (CMS) used by the known jump servers; searching for addresses that use the same CMS as the known jump servers and forming an address set; actively probing each address in the address set, and identifying the assets corresponding to addresses that satisfy the preference rules as assets of the attack end. This solution can proactively discover more assets used by the attack end during the attack phase, which is beneficial for the production of threat intelligence by the attack end.
Owner:HARBIN ANTIY TECH

Radio unit (RU) upgrade procedure in a fifth-generation (5G) network

ActiveUS12413988B2Wireless communicationFile replicationCell site
A jump server receives a command to restart a set of distributed units (DUs) at one or more cell sites. In response, the jump server executes a wrapper script that logs in to a backend server, copies an input file that identifies the set of DUs to a user-specific directory at the backend server. The jump server also copies a bulk DU restart script to the user-specific directory at the backend server. The jump server initiates the execution of the bulk DU restart script at the backend server. The execution of the bulk DU restart script causes the backend server to restart the set of DUS, generate an output log file that comprises the results of the DU restart process, and store the output log file in the user-specific directory.
Owner:DISH WIRELESS LLC

High-performance cluster user isolation and task scheduling method and system based on shared account

The invention provides a high-performance cluster user isolation and task scheduling method and system based on a shared account, and the method comprises the steps: configuring a springboard machine with a management authority, and connecting the springboard machine with a high-performance cluster; creating a corresponding independent account number for each user on the springboard machine, and associating the independent account number with a shared account number of the high-performance cluster through a secret key; setting access permissions of the independent accounts, and performing task scheduling and job submission with each independent account through the shared account; and controlling the job submission amount of each independent account according to the resource occupation amount. Under the condition that a shared account mechanism is adopted in a high-performance computing environment, user isolation and job control can be realized without system permission, directory-level data access isolation and job identity tag injection are realized for a plurality of users sharing accounts, a scheduler is supported to identify user ownership, and the operation efficiency is improved. User-level job quota control and resource use limitation are supported, and the security, controllability and resource utilization efficiency in a multi-user cluster scene are improved.
Owner:QINGHAI UNIVERSITY +1

Optimization method and device for memory overflow of springboard machine, equipment and medium

The invention provides an optimization method and device for memory overflow of a springboard machine, equipment and a medium, the springboard machine comprises two TCP connections for parallel data copying, and the optimization method comprises the following steps: establishing an observer monitoring mechanism between the two TCP connections for parallel data copying; the observer monitors a data reading event of two TCP connections; when it is detected that connection of any end completes data transmission, the observer enters a warning state; and in the warning state, if the surviving TCP connection does not read the data within the preset timeout time, the observer actively closes the corresponding two TCP connections, and the idle connection is timely closed through a monitoring mechanism, so that the connection resource accumulation is prevented, the normal operation of the springboard machine on the server is ensured, and the user experience feeling is good.
Owner:FUJIAN ZIXUN INFORMATION TECH CO LTD

Identity authentication method and device, electronic equipment and storage medium

The invention discloses an identity authentication method and device, electronic equipment and a storage medium, and relates to the computer technology, the method comprises the following steps: receiving a login request initiated by a client, the login request comprising a user identifier and a login key hash; performing first-level identity authentication on the login key hash and the corresponding registration key hash by calling an intelligent contract deployed on the block chain to obtain a first-level authentication result; wherein the smart contract is used for accessing the registration key hash in the database on the chain according to the user identifier; and under the condition that the first-level authentication result is that the authentication is passed, allowing the user to log in the springboard machine environment. According to the invention, the registration key hash is stored in the distributed nodes of the block chain, and the calling of the smart contract is cooperatively processed by a plurality of nodes in the block chain network; even if part of the nodes fail, other nodes can still normally respond to the authentication request, and the beneficial effect of improving the availability and fault tolerance of the authentication system is achieved.
Owner:SHANGHAI JIDOU TECH CO LTD

Network conflict processing method and device, program product and medium

The invention provides a network conflict processing method and device, a program product and a medium. When the method is executed, firstly, a machine accessing a web server is designated to serve as a springboard machine, after the springboard machine obtains an address allocation request sent by an internal machine, whether an MAC address of the internal machine is included in an MAC table or not is determined, and if the MAC address of the internal machine is included, a network address corresponding to the MAC address serves as an address to be allocated and is allocated to the internal machine. The internal machine and the springboard machine are located on the same network segment. One network address in the MAC table corresponds to one machine MAC address. Through the MAC table, the machine is bound with the network address, so that the uniqueness of the network address of the machine can be ensured, and the situation that the network address allocated to the internal machine by the springboard machine based on the MAC address is repeated with the network address of the springboard machine is avoided.
Owner:BEIJING COCONUT TREE INFORMATION TECH CO LTD

Network asset processing method, system and device and electronic equipment

The invention discloses a network asset processing method, system and device and electronic equipment. The method comprises the following steps: receiving a login request of a target object through a springboard machine of a virtual private cloud network; performing identity authentication on the target object according to the connection parameter information and the identification information of the target object to obtain an identity authentication result; if the identity authentication result represents that the target object passes the identity authentication, the login request is responded, and an operation and maintenance request of the target object is received, and the operation and maintenance request at least comprises asset information of the target network asset and operation information of the target operation and maintenance operation; the operation and maintenance request is forwarded to a bastion host of the target network, and the bastion host is used for carrying out target operation and maintenance operation on the target network assets according to the asset information and the operation information. According to the method and the device, the technical problem that the operation and maintenance security of the network assets is relatively low due to the fact that the network assets in a single network are operated and maintained through the bastion host and the login entry of the user is not limited in the related technology is solved.
Owner:HANGZHOU ALICLOUD FEITIAN INFORMATION TECH CO LTD

Method and device for accessing public network by iptv private network and related equipment

The application discloses an IPTV private network access public network method, device and related equipment. The method comprises the following steps: a terminal can receive a service request input by a user, generates a query request and sends the query request to a service management server, the service request is used for requesting to access a target service server of a target service application in a public network, the query request is used for querying target service record information of a target jump machine server corresponding to the target service application, and the target service record information comprises a target routing address; the service management server responds to the query request, queries the target service record information and sends the target service record information to the terminal, and the service management server comprises service record information of at least one jump machine server; the terminal parses the target service record information and obtains the target routing address; the terminal sends the service request to the target jump machine server according to the target routing address; and the target jump machine server can send the service request to the target service server, so that the access to the target service in the public network is realized.
Owner:CHINA MOBILEHANGZHOUINFORMATION TECH CO LTD +1

Bulk distributed unit (DU) restart procedure in a fifth-generation (5G) network

A jump server receives a command to restart a set of distributed units (DUs) at one or more cell sites. In response, the jump server executes a wrapper script that logs in to a backend server, copies an input file that identifies the set of DUs to a user-specific directory at the backend server. The jump server also copies a bulk DU restart script to the user-specific directory at the backend server. The jump server initiates the execution of the bulk DU restart script at the backend server. The execution of the bulk DU restart script causes the backend server to restart the set of DUs, generate an output log file that comprises the results of the DU restart process, and store the output log file in the user-specific directory.
Owner:DISH WIRELESS LLC

Multi-layer Network Forensics Method, System, Electronic Device and Medium

The present application provides a multi-layer network forensics method, system, electronic device and medium. The multi-layer network forensics method includes: detecting the network environment and starting the forensics software to obtain the available basic communication protocols and ports between the NAT subnet relay node and the lower-layer devices; establishing communication tunnels layer by layer between the relay node and each jump server, and between each jump server and the target node according to the communication protocols and ports; receiving a forensics task and splitting the sub-tasks and instructions according to the forensics task to achieve the forensics purpose; distributing the forensics sub-tasks to each distributed target node through the multi-layer communication tunnels; receiving the data packets fed back by the target node through the multi-layer communication tunnels and displaying the forensics results. Such a multi-layer network forensics method can penetrate multiple layers of network firewalls and achieve two-way communication and data transmission with multiple target nodes in different NAT subnets simultaneously.
Owner:SHANGHAI HONGLIAN NETWORK CO LTD

Information technology-side network security system suitable for the complex network environment of new energy power plants

This invention provides an information technology-side network security system suitable for the complex network environment of new energy power plants. The network security system is divided into an isolation zone and an information technology zone, and firewalls are set up at the communication boundaries of each zone. The network security structure includes software and hardware devices such as application control, antivirus, patch management, device control, integrity control, system backup and recovery, security events and event management, network monitor, jump server, firewall, and network attached storage. It meets the basic functions of network security protection with minimal software and hardware configuration, effectively avoids network intrusion, hacker theft, data leakage and other problems, and has low construction cost, making it suitable for new energy power plants.
Owner:POWERCHINA HUADONG ENG CORP LTD

Cloud system for protecting specific information

By properly managing the access routes from user terminals to the database, the risk of information leakage can be reduced. [Solution] The cloud system is connected to an administrator terminal 20 operated by an administrator and a user terminal 30 operated by a user. The cloud system includes a database 11 that stores specific data containing specific information and non-specific data that does not contain specific information, an access management unit 13 that assigns a dedicated role to users designated by the administrator for accessing specific data, a specific operational jump server 16 to which the user terminal 30(a) of a user with a dedicated role is connected and which is permitted to access both specific and non-specific data, and a normal operational jump server 17 to which the user terminal 30(b) of a user without a dedicated role is connected and which is permitted to access only non-specific data.
Owner:TEAM LAB

Game server updating method and device, and storage medium

The present disclosure provides a game server updating method and device and a storage medium, and relates to the technical field of computers. A message interaction component generated based on user demand is acquired; a user operation on the message interaction component is received to generate a server updating command; a Jenkins task is created through a task robot according to the server updating command; an updating script is called according to parameter data of the message interaction component; the updating script is executed through the Jenkins task, and an updating file is uploaded to a jump machine, so that the jump machine uploads the updating file to an Erlang game server, and the Erlang game server is updated according to the updating file, wherein a trust relationship is established in advance between the jump machine and the Erlang game server; and the updating progress of the Erlang game server is sent to a webhook address through the updating script, wherein the webhook address is generated by the task robot, and the webhook address is pre-configured in the updating script. The game server is automatically hot-updated, the operation time of updating is saved, the labor cost is reduced, and the updating efficiency is improved.
Owner:XIAMEN WOOBEST INTERACTIVE NETWORK TECH CO LTD

Version information deployment method and device, equipment, storage medium and program product

The invention provides a version information deployment method and device, equipment, a storage medium and a program product, and relates to the technical field of cloud computing. The method comprises the steps of obtaining target version data in response to a construction signal, and determining a corresponding target storage warehouse based on a mapping relationship; sending the target version data to a target storage warehouse, and performing first integrity verification; after the first integrity verification, the target storage warehouse sends the data to a target springboard machine for second verification, and the target springboard machine is used for sending the verified target version data to a target service host, so that the target service host performs third integrity verification on the target version data; and deploying the target version data by adopting a pre-pulled release script. According to the method, the data transmission process is optimized, the influence of network fluctuation on data transmission is reduced, the stability and reliability of cross-border transmission are improved, and the integrity of transmission data is maintained through a multi-layer verification mechanism.
Owner:CUIJI TECHNOLOGY (SHANGHAI) CO LTD