Skip to main content

Product Introduction

What is SHIELD Gate?

SHIELD Gate isZero Trust-Based Integrated Security GatewayIt is. It fundamentally blocks security threats that occur when accessing external web and SaaS services, preventing data leakage and malware infection.

Core Concepts

Integrated Security Gateway

  • Integrating web isolation, access control, file security, and remote access into a single platform.
  • Each function is not independent but interconnected organically.
  • Forming a Consistent Security System with a Single Policy Engine

Zero Trust Architecture

  • "Never trust absolutely, always verify"
  • Verify all access attempts and grant only the minimum necessary permissions.
  • Dynamic permission control based on user, location, time, and device conditions

agentless solution

  • No separate program installation required
  • Use all features with just a web browser
  • Minimize management and deployment burden

Why is the SHIELD Gate necessary?

Changing Work Environment

Distributed Workforce

  • Work in various locations such as office, home, cafe, and abroad.
  • Increase in access to work systems through personal devices (BYOD)
  • Increase in external access from partner companies and vendors

Scattered Data

  • Data no longer exists only on the company server.
  • Moving to cloud SaaS such as Microsoft 365, Google Workspace
  • Increase in the use of public cloud (AWS, Azure)

New Threats

  • Zero-day attacks, ransomware, and other advanced threats
  • Phishing, targeted attacks through spear phishing
  • Concerns about sensitive information leakage when using generative AI

Limitations of Existing Security Methods

Problems with VPN

1. Network-wide Trust

info

VPN connection → Access to the entire internal network is possible
└─ Issue: Lateral Movement Attack Risk

  • After connecting to the VPN, users are always trusted.
  • Devices infected with malware can access the internal network.
  • If one system is breached, it spreads throughout the entire internal network.

2. Installation and Management Burden

  • Need to install VPN client on all devices
  • Version control, update distribution burden
  • Frequent user configuration errors

3. Performance and Scalability Limitations

  • Speed reduction due to encryption
  • Concurrent User Limit
  • Additional capacity expansion costs incurred

Limitations of Web Filtering/Firewall

1. Block only known threats

info

Blacklist method → Only blocks known malicious sites.
└─ Issue: Zero-Day Attack, Unable to Respond to New Threats

2. Inconvenience Due to False Positives

  • Normal sites are also blocked as false positives.
  • Decreased Work Productivity
  • Increase in exception handling requests

3. Policy Management Complexity

  • Managing a list of tens of thousands of URLs
  • Policy conflicts and omissions occur
  • Continuous updates needed

Limitations of VDI

1. High construction cost

  • Server Infrastructure Setup Cost
  • License Cost
  • Maintenance Costs

2. Performance Constraints

  • Graphic Work Limitations
  • Difficulty in use during network latency
  • Degradation of User Experience

3. Management Complexity

  • Virtual Desktop Image Management
  • Resource Allocation and Optimization
  • Need for specialized personnel

Differentiating Features of SHIELD Gate

1. Complete Web Isolation (RBI)

SHIELD Gate: Use After Isolation

info

Access the site → Run on the isolation server → Transmit only the secure screen
└─ Effect: Block all threats at the source

Operating Principle

  • Run all web content (HTML, JavaScript, images, etc.) on an isolated server.
  • Only the rendered screen stream is transmitted to the user's PC.
  • Malware, scripts do not reach the user's PC

Technical Features

  • Perfect support for the latest web standards using the Chromium engine
  • Same user experience as existing browsers with low latency
  • Supports all advanced web features including JavaScript, WebGL, and Webjet protocols.
  • WebJet™ Protocol: High-quality screen streaming developed by SOFTCAMP using standard HTTPS without a relay server (no separate firewall configuration required)

2. URL Unit Policy Control

SHIELD Gate: URL Unit Control

info

https://company.sharepoint.com→ Allow
https://personal-account.onedrive.com→ Block
└─ Effect: Selective Allowance for Company Tenant Only

Application Example

URL patternPolicyDescription
company.sharepoint.comAllow all featuresCompany SharePoint
*.onedrive.comDownload BlockedBlocking OneDrive Personal Account
web.whatsapp.comComplete IsolationWhatsApp Web Usage Restrictions
chatgpt.comKeyboard Input CheckSafe Use of AI Services

3. Zerotrust-based Conditional Dynamic Access Control

SHIELD Gate: Conditional Dynamic Permissions

info

Office (internal IP) + weekday working hours → full permissions
Remote Work (External IP) + Weekday Working Hours → Restricted Access + MFA
Cafe (Public WiFi) → View only + Download blocked
└─ Effect: Apply Minimum Permissions According to the Situation

Combination of 5 Conditions

conditionexample
User (Who)Employee, Partner, Administrator
WhereIn-house, Remote, Overseas
Time(When)Working hours, night, weekend
Device(What)Company PC, Personal PC, Mobile
Target (Which)General Systems, Sensitive Data

Main Application Areas

VPN Alternative

Target Application: Organizations with many remote workers

  • No separate client installation required
  • After connecting to the VPN, resolve the security issue of unconditionally trusting the user.
  • Fast connection speed

SaaS Security Enhancement

Target Application: Microsoft 365, Google Workspace using organizations

  • Fine Control at the URL Level
  • Blocking Personal Account
  • Automatic Decontamination of File Downloads

Access Management for Partner Companies

Target Application: An organization with a lot of collaboration with external partners

  • Safe Access from Unmanaged PCs
  • Automatic Permission Management Based on Project Duration
  • Tracking All Work History

Safe Use of Generative AI

Target Application: Organizations that need to use AI tools like ChatGPT

  • Allow access to AI services + Apply isolation
  • Automatic Blocking of Sensitive Information Input
  • Work Efficiency and Security Coexistence

Compliance Response

Target Application: Personal Information Protection Act, Organizations Required to Comply with Industry-Specific Regulations

  • Detailed Record of All Access History
  • Sensitive Information Access Tracking
  • Automatic Generation of Audit Materials

Authentication and Reliability

GS Certification

  • Software Quality and Stability Verification Completed
  • Nationally Certified Quality Certification

Security Function Verification Certificate

  • Acquisition of Nationally Certified Security Function Certification
  • Verification of Security Requirements

Copyright Registration

  • Program Copyright Ownership
  • Possession of independent technological capabilities