Available in VPC
Familiarize yourself with these key terms to get the most out of DB & Server Access Control service.
Access Control Target
A unit of resources registered in the console subject to access control and logging. They correspond to relay sessions that establish a 1:1 connection with the target resource within the proxy server, and are divided into server targets and DB targets.
Access Port
The port number used by the proxy server when connecting to access control target resources.
Client
An agent program installed on the user's PC. When logging in with a sub-account, it receives and displays a list of targets granted access permissions from the proxy server and acts as an entry point that forwards the user's connection traffic to the proxy server.
DB Target
A type of target that has registered a Cloud DB or DBMS Server as its access control target.
DBMS Server
A type of DB target for registering a database directly installed on a server or configured from a server image as an access control target.
Masking
A feature that masks personal information before the proxy server transfers results to the Cloud Log Analytics service. It can be applied when the logging scope is set to Request & Response, and provides default patterns for items subject to encryption under the Personal Information Protection Act.
Proxy Server
A gateway server deployed when you subscribe to the DB & Server Access Control service. It relays connections between the user and the target resource, verifies access permissions, and transmits executed commands and queries to the Cloud Log Analytics service.
Server Target
A type of target registered as an access control target for a Linux server accessed via SSH.
Bulk Query
A query that has returned results exceeding the threshold defined in the Dashboard analytics criteria settings. The number of queries exceeding the threshold is aggregated in the Dashboard and utilized for detecting abnormal behavior, such as bulk retrieval of personal information.
Logging Scope
Access history recording scope configured per target. Request records connection time, connected user, connected IP, queries, and commands, while Request & Response additionally records result values.
Non-business Hours
Time periods outside the business hours range defined during proxy server creation or in the Dashboard analytics criteria settings.
Usage Range
The quantity range for creating server targets. You must set a usage range before creating server targets, and charges are applied from the moment of setting based on that range, regardless of the actual number of server targets created. However, for DB targets, there is no usage range—up to 30 can be created.
Sync policies
A feature that updates the target list by retrieving the latest access permission information from the proxy server via the client.
Closed Network Environment
An environment where VPC is connected via IPSec VPN due to the internet being blocked. Unlike an internet environment, sub-account SSO login is not possible, so you must log into the client by entering the sub-account's Access Key, Secret Key, and OTP.
For additional terms, see Glossary on the NAVER Cloud Platform portal.