Glossary
Product-related terms
| Terminology | Explanation |
|---|---|
| SHIELD Gate | Web security solution based on Remote Browser Isolation (RBI) technology. Protects users' web browsing sessions by hosting them on a server to safeguard against online threats. |
| SHIELD Viewer | A dedicated viewer that provides a secure preview when downloading files. Supports read-only document viewing functionality. |
| SHIELD Drive | The file storage function of SHIELD Gate. A storage system that safely stores files downloaded in an isolated environment. |
| Edge server | Server supporting the establishment of local storage for internal protection. Key elements of a file storage-based architecture. |
Security Technology Terms
| Terminology | Explanation |
|---|---|
| RBI (Remote Browser Isolation) | Remote browser isolation. A security technology that executes web browsing sessions on a remote server to isolate the local system from threats. |
| CDR (Content Disarm and Reconstruction) | Document sanitization technology. Removing malware or threats from files and reconstructing them into a safe form for delivery. |
| Isolated Browser | Remote browser running on the server. Provides an isolated environment to prevent web content from being directly stored on the user's local PC. |
| Screen Marking | A feature that displays user identification information on the screen in the form of a watermark to ensure traceability in case of information leakage. |
| Input Prompt Firewall | Input security feature that inspects text and attachments that users input into external services such as generative AI before transmission, blocking and masking sensitive information, and safely delivering only to services allowed by policy. The inspection is performed at the gate control point, not on the user's PC, making it impossible to bypass (Formerly known as: Custom Overlay) |
| Input Sensitive Information Check | Input prompt firewall inspection items. The administrator detects and controls sensitive information such as resident registration numbers and account numbers from the text entered by the user using registered regular expressions and keywords. |
Access and Authentication Terms
| Terminology | Explanation |
|---|---|
| SSO (Single Sign-On) | Single Sign-On. An authentication method that allows access to multiple systems with a single login. Used in conjunction with internal accounts. |
| AD (Active Directory) | Microsoft's directory service. Used for managing user accounts and permissions, and can be integrated with SHIELD Gate. |
| OTP (One-Time Password) | One-time password. A time-based or event-based password used for additional security authentication. |
| RBAC (Role-Based Access Control) | Role-based access control. A method of granting system access permissions based on the user's role. |
| WOL (Wake On LAN) | Technology to power on a turned-off PC remotely via the network. Used for desktop remote access. |
Policy-related terms
| Terminology | Explanation |
|---|---|
| Conditional Policy | Access control policies that are applied differently based on specific conditions such as user location, time, device, and group. |
| Priority | The value that determines the order of policy application. The lower the number, the earlier it is applied, and in case of a conflict, the more restrictive policy is applied last. |
| Web Category | Groups classified by the nature of the URL (e.g., shopping, social media, finance, etc.). Access allow/block policies can be set by category. |
| wildcard | Special character (*) used for URL pattern matching. Used before the domain to match all URLs including subdomains. |
| Regular Expression (Regex) | Expression for finding strings of a specific pattern. Used for detecting sensitive information (resident registration number, account number, etc.) |
| Expiration Date | Start and end dates of the policy. It can be set to activate the policy only during the specified period. |
Network Terms
| Terminology | Explanation |
|---|---|
| PAC (Proxy Auto-Config) | Proxy auto-configuration file. A script that automatically determines which proxy to use when the browser accesses a specific URL. |
| DNS (Domain Name System) | A system that converts domain names to IP addresses. In the RBI environment, DNS queries are performed on an isolated server. |
| Protocol | Network communication protocols. HTTP and HTTPS are separately distinguished for policy application. |
| VDI (Virtual Desktop Infrastructure) | Virtual Desktop Infrastructure. A technology that provides virtual desktops from a server. |
File-related terms
| Terminology | Explanation |
|---|---|
| extension | The suffix after the filename that indicates the file format (e.g., .pdf, .xlsx, .docx). Upload/download control is possible by extension. |
| clipboard | Temporary storage area used for copy/paste functionality. Clipboard usage between PC and remote browser can be controlled by policy. |
| Isolated Storage | Isolated storage space where downloaded files are saved. Not stored directly on the local PC, but saved in designated storage. |
| Trash bin | A space where deleted files are temporarily stored. Automatically deleted after a certain period (default 30 days) and can be restored before that. |
| Encryption | The process of converting files using a special algorithm to protect them securely. Automatic encryption processing is possible during upload. |
User Interface Terms
| Terminology | Explanation |
|---|---|
| app | Icon or shortcut to access the business system (ERP, groupware, etc.) registered by the administrator |
| URL input field (address bar) | An input field where users can directly enter a web address to access the site. |
| GNB (Global Navigation Bar) | Global navigation bar. A top menu that displays a list of recently accessed apps/URLs and supports quick access. |
| top bar | Menu and control area at the top of the screen. Supports full-screen view through hide/show functionality. |
| Lock Screen | A guide page displayed when access is blocked by policy. Customizable |
Collaboration and Integration Terms
| Terminology | Explanation |
|---|---|
| M365 (Microsoft 365) | Microsoft's cloud-based productivity platform. Includes Teams, Office365, Word, PowerPoint, etc. |
| Teams | Microsoft's collaboration tool. Supports viewing, uploading, and editing files within the Teams app at SHIELD Gate. |
| Collaborative Editing | A feature that allows multiple users to edit a single document simultaneously. Supported by MS365, Google Docs, etc. |
| Google Docs | Google's cloud-based document editing tool. Provides real-time collaboration features. |
| Hancom Web | Hancom's web-based document editing solution. hwp/hwpx files can be viewed and edited online. |
| NAS (Network Attached Storage) | Network-connected storage device. Can be linked to external storage. |
| OneDrive | Microsoft's cloud storage service |
| Google Drive | Google's Cloud Storage Service |
Remote Access Terms
| Terminology | Explanation |
|---|---|
| SSH (Secure Shell) | Network protocols for secure remote access. Command execution and file transfer support |
| SFTP (SSH File Transfer Protocol) | SSH-based secure file transfer protocol |
| Terminal | A text-based interface that allows you to control the system by entering commands. |
| Remote Console | Console interface that allows remote access and management of web servers, etc. |
Log and Monitoring Terms
| Terminology | Explanation |
|---|---|
| log | Data that records system and user activities. Includes history of login/logout, file downloads, policy modifications, etc. |
| session | The duration of access from the time the user logs in until they log out or are automatically terminated. |
| Timeout | A feature that automatically ends the session when there is no user activity for a certain period of time. |
| Dashboard | A management screen that visually displays key indicators and statistics. Monitor access status, website categories, and more. |
| Archive | A file stored in compressed format for long-term retention of logs |
| Integrity Verification | Process of verifying that log data has not been tampered with |
Technical Terms
| Terminology | Explanation |
|---|---|
| WebGL | JavaScript API for Rendering 3D Graphics in Web Browsers |
| cache | A memory area that temporarily stores frequently used data to improve performance |
| Cookie | A small data file that a website stores in the user's browser. Used for maintaining login status, etc. |
| Session Information | Server-side data to maintain the user's connection status |
| Endpoint Broker | Technology supporting web applications that require internal communication within a PC (such as banking security programs, etc.) |
Management Terms
| Terminology | Explanation |
|---|---|
| License | Product usage permissions. Can be assigned automatically or manually based on the number of users. |
| Inbound Provisioning | Function to automatically synchronize user information from external systems (Microsoft 365, SCI Server, etc.) |
| scheduling | A feature that schedules a specific task to be executed automatically at a designated time. |
| Policy Group | A bundle of users who are subject to the same policy. Create and manage groups according to organizational structure. |
| CSV | Comma-separated values format file. Used for bulk user registration. |
| Activation/Deactivation | Availability status of the user account. Access to the service is not possible when deactivated. |