Bastion Worker Control of Anomaly Commands Across Multi-Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud service networks face security vulnerabilities due to limited public IPs, exposing internal instance information, and require cumbersome agent installations for anomaly command control, lacking effective command execution and management through bastion hosts.
Innovation Solution
A system and method for controlling and executing anomaly commands in a multi-network environment using a bastion host, enabling registration and management of anomaly command patterns, setting different command levels, and eliminating the need for instance agents, with features like anomaly command verification tokens and user authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a bastion host is installed across all networks to enable secure access to instances, then security is improved and internal instance information is protected, but device complexity increases and ease of operation deteriorates due to the need to directly manage all account information and execute SSH tunneling for each instance
Solution Approach 1:
The system segments the bastion host functionality into distributed bastion workers across multiple networks. Each bastion worker handles specific network segments, eliminating the need for a single complex centralized bastion host while maintaining security. This segmentation reduces the complexity burden on any single device.
Solution Approach 2:
The patent introduces an intermediary anomaly command control system that mediates between users and instances. This intermediary automatically manages account information, handles SSH tunneling, and controls command execution, eliminating the need for users to directly manage complex bastion host operations while maintaining security.
2Reliability
If a bastion host is installed across all networks to enable secure access to instances, then security is improved and internal instance information is protected, but ease of operation deteriorates due to the need to directly manage all account information and execute SSH tunneling for each instance
Solution Approach 1:
The bastion workers and anomaly command control system operate autonomously, automatically managing account information, establishing SSH tunnels, and controlling command execution without requiring user intervention. This self-service mechanism significantly improves ease of operation while maintaining the security benefits of bastion host deployment.
Solution Approach 2:
The intermediary anomaly command control system automatically handles all complex operations including account management, SSH tunneling establishment, and command filtering. Users simply interact with the simplified interface while the intermediary manages all the complex backend operations, dramatically improving ease of operation.
3Reliability
If an agent is installed on each instance to prevent security threats, then security is improved, but device complexity increases and ease of manufacture deteriorates due to the cumbersome installation process
Solution Approach 1:
The patent extracts the security control functionality from individual instances by implementing it in the bastion workers and anomaly command control system. This eliminates the need to install agents on each instance, significantly improving ease of manufacture while maintaining security through centralized command filtering and control.
4Ease of operation
If public IPs are used to connect to instances, then ease of operation is improved, but security deteriorates as internal instance information is exposed to the outside
Solution Approach 1:
The bastion workers and anomaly command control system serve as intermediaries between external users and internal instances. Users connect to the bastion worker through public IPs for ease of operation, while the intermediary maintains security by filtering commands and preventing direct exposure of internal instance information.
Solution Approach 2:
The system segments network access by separating public-facing bastion workers from private instances. This segmentation allows public IP access for ease of operation while maintaining security through the architectural separation that prevents direct exposure of internal instance information.
Data Source
AI summary
A method of controlling and executing an anomaly command in a multi-network environment is includes: extracting a command, which is input by a user to a target instance through an accessed bastion worker; determining whether the extracted command is an anomaly command by comparing the extracted command with anomaly command patterns; based on the extracted command being determined to be the anomaly command, determining whether an execution of the anomaly command is permitted in the target instance; and based on the execution of the anomaly command being not permitted, notifying the user of a procedure for approving the execution of the anomaly command based on a level of the anomaly command being one of levels, which are classified in advance based on the anomaly command patterns; either executing or blocking the command input by the user, wherein the procedure is determined differently depending on the level of the anomaly command.


