What is Content Disarm and Reconstruction (CDR)?
Content disarm and reconstruction (CDR) technology is designed to scan documents and remove potentially malicious content. It plays a crucial role within broader cross-domain solutions (CDS), offering advanced security capabilities. Content disarm and reconstruction is commonly used to eliminate file-borne threats from less trusted domains or to ensure sensitive data is removed before transferring content to less secure environments.
By removing or exposing unapproved file components, CDR reduces the risk of malicious code activation and prevents sensitive information from being unintentionally included in documents. This makes it an essential tool for organisations handling classified or regulated data, such as government agencies.
How it works
Step | Description |
File Ingestion & Verification | The CDR system receives the incoming file (e.g., email attachment or web download) and performs an initial check to verify its true file type and structural integrity. |
Decomposition (Disarm) | The file is broken down into its discrete, basic components, separating the benign data (text, simple images) from the active elements (scripts, macros, embedded objects, metadata). |
Threat Removal (Disarm) | This is the core "Disarm" action. Based on a "positive security" model, ALL active, executable, or high-risk content is completely removed and stripped away, assuming it is malicious. |
Reconstruction | A brand-new, clean file is immediately rebuilt (Reconstructed) using only the non-threatening, known-good components. The original file's structure and usability are preserved in the new file. |
Safe Delivery | The newly sanitised, harmless file is delivered to the end-user or destination system. The original, potentially malicious file is typically quarantined for logging and forensic purposes. |
Why use content disarm and reconstruction software?
Content disarm and reconstruction software is particularly important due to increased regulatory and compliance requirements for content security. For instance, the General Data Protection Regulation (GDPR) within the European Economic Area (EEA) enforces strict rules to protect sensitive personal information.
CDR ensures that files retain their original content while removing potential threats. This eliminates the need for manual intervention or the risk of sending contaminated files, saving both time and resources. CDR also enables organisations to proactively work with clean, verified content rather than relying solely on traditional malware databases that may miss unknown threats.
Benefits of CDR for businesses
Protects against unknown threats
One of the standout benefits of content disarm and reconstruction is its ability to protect against zero-day threats – those new and unknown vulnerabilities that traditional antivirus solutions may not recognise. By disarming all incoming files before they enter your network, CDR ensures that only friendly content is allowed through, reducing the risk of malware or ransomware attacks that could otherwise slip past conventional cyber security measures.
Preserves productivity and file integrity
In fast-paced business environments, maintaining operational efficiency is critical. CDR offers a seamless solution by ensuring that sanitised files retain their original functionality and integrity. This means your teams can continue working without interruptions or concerns about hidden threats, allowing you to focus on growing your business without compromising productivity or security.
Strengthens compliance and data security
In highly regulated industries, such as healthcare, finance, and government, data security and compliance are top priorities. Regulatory bodies demand stringent security measures to safeguard sensitive information and avoid costly breaches or penalties. CDR helps businesses meet these requirements by ensuring that all files are sanitised and redacted before they enter or leave the network, preventing unauthorised access to sensitive data, protecting against supply chain attacks and reducing the risk of data leakage.
Builds trust with clients and stakeholders
For any business, trust is a valuable asset. Ensuring that client data, intellectual property, or sensitive information is protected from cyber threats is key to building and maintaining strong relationships with clients, partners, and stakeholders.
With CDR, you can confidently tell your customers and stakeholders that you are safeguarding their information with the most advanced security measures available, reinforcing your commitment to security and trust.
Real-world application of CDR
Consider a national government agency responsible for coordinating between various departments and agencies, handling a high volume of sensitive information daily. This includes classified documents, policy drafts, and interagency memos that, if compromised, could have severe national security implications.
To safeguard its communications, the agency deployed CDR technology across multiple channels. By integrating CDR into their email system, the agency ensures that all attachments are sanitised with sensitive information redacted before being delivered, preventing malware from infiltrating their network and sensitive information exfiltration.
The outcomes: Strengthened national security, enhanced interagency collaboration, and compliance with stringent government regulations on data security and information handling.
Choosing the right CDR product
With numerous CDR solutions available, selecting the right one requires an understanding of your organisation’s specific information exchange risks. At Nexor, we’re experts at identifying these risks and tailoring fine-grained sanitisation policies to mitigate them efficiently. We support multiple CDR solutions to ensure optimal performance in diverse scenarios:
Arcfield’s PuriFile®: Integrated within Nexor GuarDiode for robust data sanitisation.
Glasswall: Used in Nexor Protean for scalable, high-performance workloads.
Arcfield’s PuriFile®: a trusted CDR product
PuriFile® by Arcfield is a proven solution for secure data sharing, offering deep content inspection and sanitisation. It mitigates hundreds of threats, from hidden content within images to falsified file formats. With its patented technology, PuriFile® has earned a reputation for excellence, particularly within the U.S. Intelligence Community.
Seamlessly integrating with Nexor GuarDiode, PuriFile® provides enhanced protection through additional text and malware filtering, combined with secure quarantining for thorough inspections. This long-standing partnership ensures robust and reliable cross-domain solutions.
Glasswall: a scalable CDR Solution
Glasswall delivers flexible, containerised CDR technology as part of Nexor Protean. It's orchestrated containers and adaptive work scheduling optimise compute resources, scaling to meet high-performance demands or scaling back during periods of lower activity. This flexibility makes Glasswall a cost-effective solution for varying information transfer needs.
Tailored CDR solutions with Nexor
Nexor security analysts provide expert advice on threat mitigation strategies tailored to your unique secure information exchange scenarios. Our solutions are designed and integrated to deliver secure, efficient cross-domain capabilities, supported by experienced teams and industry-leading technology partners such as Arcfield and Glasswall.
If you would like more information about how content disarm reconstruction and secure guarding software can benefit your organisation, get in touch with our team today.