Skip to main content

Comparison Data

This document is about web browser-based security solutions such as RBI (Remote Browser Isolation), VDI (Virtual Desktop Infrastructure),
This is a document that compares the security effects, construction efficiency, and operational complexity of the CBC (Client-Based Control) method from various perspectives.

divisionSHIELDGate (RBI)VDICBC
Basic StructureComplete Remote Isolation of Browser ExecutionRunning the Browser on Central VDIInstall Agent on User Terminal Browser
Threat Approach★★★★★ Do not allow threat sources to enter internally★★★ Access control only at the session level★★ Detection and Blocking within the Device
Zero-Day Attack Response★★★★★ Browser vulnerability exploitation not possible★★★ VDI OS/Browser Vulnerability Impact★★ Undetected terminal infection
Ransomware Response★★★★★ Internal inflow structurally impossible★★★ Possibility of Internal Spread in VDI★★ Internal Spread Upon Device Infection
Network Worm / Virus★★★★★ No internal propagation path★★★ VDI Internal Propagation Possible⚠️ Possible internal network propagation upon device infection
Attack SurfaceMinimum (screen streaming/rendering)Intermediate (VDI OS + Browser)Large (OS + Browser + Agent)
Internal Network Protection Level★★★★★ Completely Logical Separation★★★ Logical Separation★★ Device Dependency
Cost Structure★★★★ Centralized / Simplification★★ VDI Infrastructure High Cost★★★ Low Initial Cost
Construction Efficiency★★★★★ Browser only★★ VDI Construction/Operation Complexity★★★★ Fast deployment available
Operational Complexity★★★★★ No need for patching or OS management⚠️★★ VDI OS·Image Management★★★ Device-specific Agent Management
User Experience★★★★ Web-based, lightweight★★★★ Similar PC Environment★★★★★ Local Browser Same
Impact Scope in Case of Security Incident★★★★★ Session Unit Immediate Disposal★★★ VDI Unit Impact⚠️ Device unit → Internal diffusion possible