Skip to main content

Usage Scenarios

Introducing how to utilize SHIELD Gate in various work environments.


1. VPN Alternative

situation

Remote Access Environment of Large Organizations

The problem many organizations face:

  • Burden of installing and managing VPN clients on all employee PCs
  • Version updates, certificate renewals, and other ongoing management are necessary.
  • Access to the entire internal network after VPN connection (security risk)
  • Connection delay during peak times due to simultaneous user limit
  • Slow speed due to encryption overhead

Utilizing SHIELD Gate

Composition Plan

1. Internal Work System Registration
- ERP, Groupware, HR System, etc.
- Register access URLs for each system

2. Conditional Policy Settings
- Internal IP: Allow all functions
- Remote IP: Restricted functions + OTP
- Overseas IP: Block or require approval

3. Authentication Integration
- Active Directory SSO
- Microsoft 365 account integration
- Google Workspace integration

4. Gradual Transition
- Step 1: Operate in parallel with VPN
- Step 2: Transition some departments to SHIELD Gate
- Step 3: Expand company-wide

Expected Effects

  • Simplification of Management: No client installation or management required
  • Strengthening Security: Application-level access control instead of network-level
  • Performance Improvement: Faster connection speed compared to VPN
  • scalability: Unlimited simultaneous connections supported
  • Cost Reduction: Reducing VPN Equipment and License Costs

2. Vendor Access Management

situation

Collaboration with multiple external partners

Challenges in Managing Partner Companies:

  • Separate account issuance and management for each partner company
  • Account Recovery Omission After Project Completion
  • Accessing from unmanaged PC (risk of malware infection)
  • Difficulty in tracking work details
  • Risk of Information Leakage Due to Excessive Authorization

Utilizing SHIELD Gate

Composition Plan

1. Project-specific access rights  
Project A member → Access only to Project A folder
Project B member → Access only to Project B folder

2. Complete isolation mode applied
- All access through isolated browser
- Complete blocking of downloads
- Blocking of copy and paste
- Blocking of screenshots

3. Work history tracking
- Access time history
- File view and edit history

4. Automatic permission management
- Project start date → Automatic permission granting
- Project end date → Automatic permission revocation

3. Strengthening SaaS Security

situation

Utilizing cloud SaaS such as Microsoft 365, Google Workspace

Security Challenges of Using SaaS:

  • Difficulty distinguishing between personal accounts and company accounts
  • Send to personal email after downloading the file
  • Irresponsible creation of external sharing links
  • Save company files to personal OneDrive

Utilizing SHIELD Gate

Composition Plan

1. URL Level Detailed Policy
company.sharepoint.com
→ Company SharePoint: All features allowed

personal-account.onedrive.com
→ Personal OneDrive: Access blocked

web.whatsapp.com
→ WhatsApp Web: Upload blocked

2. Tenant Control
- Only company tenant (@company.com) access allowed
- Access from other tenants blocked

3. File Download Control
- SharePoint file download → CDR applied
- Teams attachments → Automatic sanitization
- External sharing link creation → Blocked

4. Safe Use of Generative AI

situation

Need to utilize AI tools such as ChatGPT, Copilot, etc.

The Dilemma of Using Generative AI:

  • Need for AI tools for work efficiency
  • Concerns about entering sensitive information (source code, customer data, etc.)
  • Unconditional blocking leads to employee dissatisfaction and decreased productivity
  • Bypass using a personal account

Utilizing SHIELD Gate

Composition Plan

1. Allow access to AI services + isolation  
chatgpt.com → Open in isolation browser
copilot.microsoft.com → Isolation mode

2. Keyboard input pattern inspection
- When entering resident registration number pattern → Block
- When entering account number pattern → Block
- IP address pattern → Block

3. Copy and paste control
- Internal → AI: Block
- AI → Internal: Allow
(Code copying is possible, but source upload is blocked)

5. Remote Work Environment

situation

Corporate Remote Work or Hybrid Work

Security Challenges of Remote Work:

  • Employee home PC security status uncertain (no antivirus installed, patches not applied)
  • Cafes, using public WiFi in public places

Utilizing SHIELD Gate

Composition Plan

1. All Access Isolation
- Access through an isolated browser on any device
- Even infected devices are safe

2. Screen Watermark
- Display username and ID
- Display access time
- Traceable when taking screenshots

3. Policy by Network
- When accessing from external IP
→ Additional OTP authentication
→ Block downloads

4. Storage Location Control
- Block local downloads
- Allow saving only to SHIELD Drive
- Save files encrypted

6. Personal Desktop Remote Access

situation

High-spec PC required tasks (design, development, video editing)

Challenges of Utilizing High-Spec PCs:

  • Unable to perform high-spec tasks while working from home
  • VDI Construction Cost Burden (Server, License)
  • Need access to office PC for external workers (freelancers)

Utilizing SHIELD Gate

Composition Plan

1. Personal PC Registration
- Register on the office desktop SHIELD Gate
- Set access permissions (only for yourself or team members)

2. Wake on LAN
- You can turn off the PC when leaving work
- Power on remotely

3. Conditional Access Control
- Weekday working hours: Free access
- Night/weekend: Access not allowed
- Overseas business trip: Access not allowed

4. Session Monitoring
- Access history logging
- Automatic logout after task completion

7. Server Management Console

situation

Operating multiple Linux/Unix servers

Security Challenges of Server Management:

  • Security Risks of Direct SSH Access
  • Difficulty in tracking administrator work history

Utilizing SHIELD Gate

Composition Plan

1. Web-based SSH Terminal
- Direct SSH access from the browser
- No separate terminal program needed

2. Work History Record
- Who, when, where, on which server

8. Response to Phishing Attacks

situation

Increase in Email Phishing Attacks

The Reality of Phishing Attacks:

  • Accessing malicious sites by clicking email links
  • Limitations of Security Training (People Make Mistakes)
  • Sophisticated phishing sites are difficult to distinguish.
  • Risk of transmission infection even with just one click

Utilizing SHIELD Gate

Composition Plan

1. Isolation of all external links
- All links in emails → Isolated browser
- Messenger links → Isolated browser
- Links within documents → Isolated browser

2. Automatic isolation of unclassified sites
- Sites not in the category DB → Complete isolation
- New sites → Block keyboard input
- Suspicious domains → Block downloads

3. Input control
- Phishing suspected sites → Block keyboard input
- Login forms detected → Warning popup
- Requests for personal information → Block

4. File download sanitization
- All attachments → Automatic CDR application
- Executable files → Block
- Compressed files → Internal re-inspection

9. Compliance Response

situation

Compliance with regulations required (Personal Information Protection Act, Medical Act, Financial Act, etc.)

Compliance Requirements:

  • Obligation to Record Personal Information Access History
  • Principle of Least Privilege
  • Prevention of Sensitive Information Leakage
  • Submission of Evidence of Gratitude
  • Insider Threat Management

Utilizing SHIELD Gate

Composition Plan

1. Perfect Access History Record  
Who: User ID, Name
When: Access Start/End Time
Where: IP Address, Location
What: Accessed System, File
How: View, Edit, Download

2. Sensitive Information Access Control
- When accessing patient information → Watermark automatically displayed
- Customer data download → Reason input required
- Confidential document printing → Administrator approval needed

3. Principle of Least Privilege
- Access only the information necessary for work
- Differential privileges based on position and department
- Automatic privilege revocation upon expiration

4. Log Integrity Assurance
- Log tampering prevention technology
- Blockchain-based hash verification
- Automatic backup to external storage