Network transitions.
The infodas approach to secure data exchange in isolated systems and network segmentation is based on the zero-trust model.
Network segmentation is an important element of information security concepts. Organizational networks are divided into areas according to security requirements. Their security requirements depend, among other things, on the data stored or transported and the criticality of the systems. Individual network segments carrying particularly sensitive data subject to confidentiality requirements can be completely disconnected (with an “air gap”) or only made available to a limited extent, with communication patterns or data flows being forced.
The model similarly distrusts all endpoints, applications and users. All internal and external communications traffic must be checked and all users and services must authenticate themselves. Many IT security concepts ignore this and focus on minimizing external threats. This is a major weakness that is exploited in cyberattacks.
Accordingly, a distinction is made between
- Transitions between internal networks
- Transitions between internal networks and DMZ
- Transitions between internal networks and the Internet
- Transitions between DMZ under own/third party control and the Internet
It is particularly the complete isolation of network segments that poses an increasing challenge for public and private organizations. For various reasons, authorities, the military and companies (e.g. banks, power plants, oil platforms) increasingly have to exchange, merge or evaluate data in order to be able to fulfill their tasks and orders in real time. In many cases, only computer systems need to communicate with each other. However, manual data exchange (“swivel chair interfaces” or “sneaker networks”) between an isolated system and other systems is an obstacle to this, as it is labor-intensive and time-consuming.
This is where cross-domain solutions come into play. These are trustworthy, government-approved network security components (security gateways, data diodes) that control and, if necessary, block the flow of data between two security domains at all layers.
By combining these with the OPSWAT MetaDefender Kiosk and MetaDefender Vault, you can also ensure that no malware can infiltrate via external data or portable media.
Our offer to you.
Cross-domain Solutions.
Cybersecurity Consulting.
- Analysis of risks and security requirements
- IT security concepts
- Ethical hacking / pentesting
What are domain transitions?
Test now
Request a quote
Discuss use case