Usage Scenarios
Introducing how to utilize SHIELD Gate in various work environments.
1. VPN Alternative
situation
Remote Access Environment of Large Organizations
The problem many organizations face:
- Burden of installing and managing VPN clients on all employee PCs
- Version updates, certificate renewals, and other ongoing management are necessary.
- Access to the entire internal network after VPN connection (security risk)
- Connection delay during peak times due to simultaneous user limit
- Slow speed due to encryption overhead
Utilizing SHIELD Gate
Composition Plan
1. Internal Work System Registration
- ERP, Groupware, HR System, etc.
- Register access URLs for each system
2. Conditional Policy Settings
- Internal IP: Allow all functions
- Remote IP: Restricted functions + OTP
- Overseas IP: Block or require approval
3. Authentication Integration
- Active Directory SSO
- Microsoft 365 account integration
- Google Workspace integration
4. Gradual Transition
- Step 1: Operate in parallel with VPN
- Step 2: Transition some departments to SHIELD Gate
- Step 3: Expand company-wide
Expected Effects
- Simplification of Management: No client installation or management required
- Strengthening Security: Application-level access control instead of network-level
- Performance Improvement: Faster connection speed compared to VPN
- scalability: Unlimited simultaneous connections supported
- Cost Reduction: Reducing VPN Equipment and License Costs
2. Vendor Access Management
situation
Collaboration with multiple external partners
Challenges in Managing Partner Companies:
- Separate account issuance and management for each partner company
- Account Recovery Omission After Project Completion
- Accessing from unmanaged PC (risk of malware infection)
- Difficulty in tracking work details
- Risk of Information Leakage Due to Excessive Authorization
Utilizing SHIELD Gate
Composition Plan
1. Project-specific access rights
Project A member → Access only to Project A folder
Project B member → Access only to Project B folder
2. Complete isolation mode applied
- All access through isolated browser
- Complete blocking of downloads
- Blocking of copy and paste
- Blocking of screenshots
3. Work history tracking
- Access time history
- File view and edit history
4. Automatic permission management
- Project start date → Automatic permission granting
- Project end date → Automatic permission revocation
3. Strengthening SaaS Security
situation
Utilizing cloud SaaS such as Microsoft 365, Google Workspace
Security Challenges of Using SaaS:
- Difficulty distinguishing between personal accounts and company accounts
- Send to personal email after downloading the file
- Irresponsible creation of external sharing links
- Save company files to personal OneDrive
Utilizing SHIELD Gate
Composition Plan
1. URL Level Detailed Policy
company.sharepoint.com
→ Company SharePoint: All features allowed
personal-account.onedrive.com
→ Personal OneDrive: Access blocked
web.whatsapp.com
→ WhatsApp Web: Upload blocked
2. Tenant Control
- Only company tenant (@company.com) access allowed
- Access from other tenants blocked
3. File Download Control
- SharePoint file download → CDR applied
- Teams attachments → Automatic sanitization
- External sharing link creation → Blocked
4. Safe Use of Generative AI
situation
Need to utilize AI tools such as ChatGPT, Copilot, etc.
The Dilemma of Using Generative AI:
- Need for AI tools for work efficiency
- Concerns about entering sensitive information (source code, customer data, etc.)
- Unconditional blocking leads to employee dissatisfaction and decreased productivity
- Bypass using a personal account
Utilizing SHIELD Gate
Composition Plan
1. Allow access to AI services + isolation
chatgpt.com → Open in isolation browser
copilot.microsoft.com → Isolation mode
2. Keyboard input pattern inspection
- When entering resident registration number pattern → Block
- When entering account number pattern → Block
- IP address pattern → Block
3. Copy and paste control
- Internal → AI: Block
- AI → Internal: Allow
(Code copying is possible, but source upload is blocked)
5. Remote Work Environment
situation
Corporate Remote Work or Hybrid Work
Security Challenges of Remote Work:
- Employee home PC security status uncertain (no antivirus installed, patches not applied)
- Cafes, using public WiFi in public places
Utilizing SHIELD Gate
Composition Plan
1. All Access Isolation
- Access through an isolated browser on any device
- Even infected devices are safe
2. Screen Watermark
- Display username and ID
- Display access time
- Traceable when taking screenshots
3. Policy by Network
- When accessing from external IP
→ Additional OTP authentication
→ Block downloads
4. Storage Location Control
- Block local downloads
- Allow saving only to SHIELD Drive
- Save files encrypted
6. Personal Desktop Remote Access
situation
High-spec PC required tasks (design, development, video editing)
Challenges of Utilizing High-Spec PCs:
- Unable to perform high-spec tasks while working from home
- VDI Construction Cost Burden (Server, License)
- Need access to office PC for external workers (freelancers)
Utilizing SHIELD Gate
Composition Plan
1. Personal PC Registration
- Register on the office desktop SHIELD Gate
- Set access permissions (only for yourself or team members)
2. Wake on LAN
- You can turn off the PC when leaving work
- Power on remotely
3. Conditional Access Control
- Weekday working hours: Free access
- Night/weekend: Access not allowed
- Overseas business trip: Access not allowed
4. Session Monitoring
- Access history logging
- Automatic logout after task completion
7. Server Management Console
situation
Operating multiple Linux/Unix servers
Security Challenges of Server Management:
- Security Risks of Direct SSH Access
- Difficulty in tracking administrator work history
Utilizing SHIELD Gate
Composition Plan
1. Web-based SSH Terminal
- Direct SSH access from the browser
- No separate terminal program needed
2. Work History Record
- Who, when, where, on which server
8. Response to Phishing Attacks
situation
Increase in Email Phishing Attacks
The Reality of Phishing Attacks:
- Accessing malicious sites by clicking email links
- Limitations of Security Training (People Make Mistakes)
- Sophisticated phishing sites are difficult to distinguish.
- Risk of transmission infection even with just one click
Utilizing SHIELD Gate
Composition Plan
1. Isolation of all external links
- All links in emails → Isolated browser
- Messenger links → Isolated browser
- Links within documents → Isolated browser
2. Automatic isolation of unclassified sites
- Sites not in the category DB → Complete isolation
- New sites → Block keyboard input
- Suspicious domains → Block downloads
3. Input control
- Phishing suspected sites → Block keyboard input
- Login forms detected → Warning popup
- Requests for personal information → Block
4. File download sanitization
- All attachments → Automatic CDR application
- Executable files → Block
- Compressed files → Internal re-inspection
9. Compliance Response
situation
Compliance with regulations required (Personal Information Protection Act, Medical Act, Financial Act, etc.)
Compliance Requirements:
- Obligation to Record Personal Information Access History
- Principle of Least Privilege
- Prevention of Sensitive Information Leakage
- Submission of Evidence of Gratitude
- Insider Threat Management
Utilizing SHIELD Gate
Composition Plan
1. Perfect Access History Record
Who: User ID, Name
When: Access Start/End Time
Where: IP Address, Location
What: Accessed System, File
How: View, Edit, Download
2. Sensitive Information Access Control
- When accessing patient information → Watermark automatically displayed
- Customer data download → Reason input required
- Confidential document printing → Administrator approval needed
3. Principle of Least Privilege
- Access only the information necessary for work
- Differential privileges based on position and department
- Automatic privilege revocation upon expiration
4. Log Integrity Assurance
- Log tampering prevention technology
- Blockchain-based hash verification
- Automatic backup to external storage