Guards and Gateways: What's the difference?
Guards and gateways are full application layer proxies that connect to two or more networks. They accept data passed on an inbound network interface, process it, and then pass data to the outbound network interface. The way in which guards and gateways deal with data make them very important for maximising security in any organisation. The difference between guards and gateways is in the process they both take with the data.
What is a guard?
A guard will inspect the application-level data and perform checks on it – typically checks to see if the data conforms to a security policy. This policy might be checking whether the data is schema compliant, known-virus free or authorised for release. Critically, a guard does not change the data, its principal role is security enforcement.
Nexor Guardian and Nexor Sentinel are guards.
What is a gateway?
A gateway may perform the same capability as a guard but, as an addition, might transform the data in some way. This might be to convert to a different network protocol, content protocol or perform data normalisation to a baseline standard. Typically, a gateway has more functionality than a guard, with its principal role to enable interoperability, but it can be used to enforce the security policy. (To add a little confusion, some refer to the entire solution including firewalls, guards, gateways and maybe diodes as the gateway – but the point holds, in this scenario, the gateway is transforming the data in some way.)
Nexor Protean is a Software Defined Gateway built with security at its forefront.
Why is the distinction between guards and gateways so important?
In short: it’s all to do with assurance.
If the business objective of the application layer proxy is to enforce security, then you need to be able to trust it. When it comes to high assurance, this means the product either needs certification from a 3rd party such as Common Criteria or GCHQs Commercial Product Assurance. Failing that, an accreditor will need to approve the product or the overall system containing the product. Typically to gain such certification or accreditation to a high assurance level, you keep the security enforcing component as simple as possible in order to prove the capability. Thus, guards focus on security enforcement without the complication of data transformation clouding the picture.
Guards and gateways at Nexor
In some cases, the overall solution needs data transformation as well. At Nexor, we prefer to separate this into a gateway. Our Secure Information Exchange Architecture provides for both gateway and guard elements – with a gateway preparing the data for interoperability purposes, then passing it to a guard for security enforcement. If the gateway fails to perform a valid transformation, the guard will prevent the data transfer as a violation of policy. This approach simplifies the assurance approach as only the guard element is security enforcing.
Some suppliers will add transformation capabilities to the guards, and often our customers request this too. For some customers, this will be perfectly adequate, and better than they have today, but it is a security compromise. For high assurance customers, we also recommend that a guard validates the new PDF is schema compliant (or better still, not transfer the PDF – instead have the gateway transform the document to a simpler format that can be checked more easily for schema compliance by the guard).
Security is never easy and is a balancing act between usability, affordability and trust. By having a modular Secure Information Exchange Architecture, with separated components (physically, or virtually) for guards, gateways (and flow control), we are able to work with our customers to select a solution that matches their business risk profile.
Can we help you with your secure information exchange needs?
Discover high assurance guards and gateways at Nexor
If you would like to talk to us directly, contact our team to see how we can help. We value your privacy >
Be the first to know about developments in secure information exchange and read our whitepaper on Innovation In Secure Information Exchange.