When is a Cross Domain Gateway not actually a Gateway?

Author: Danny Wootton

15 Dec 2023

Tags:

When is a cross domain gateway not a gateway?

A cross domain gateway is used to protect your business when moving files internally and externally. Whilst they have been a trusted solution for years, they are no longer suitable for every scenario. Let’s have a closer look.

What is a cross domain gateway?

A cross domain gateway (CDG) is a vital component of a comprehensive information assurance strategy, historically implemented to manage and secure the flow of data between networks operating at different security or trust levels. Traditional CDGs operate using a rigid policy model to perform deep content inspection - checking all transit data for security issues like malware and sensitive terms - ensuring that only 'clean' data reaches the intended, often highly sensitive, destination.

What are the benefits of a cross domain gateway?

Cross domain gateways are very good at doing one thing really well - using a policy to define how data from a particular source is checked for malware, sensitive words, and other security issues, so that only 'clean' data gets to the desired destination. Cross Domain Solutions (CDS) have been doing this for many years and have become very good at it.

However, a little while ago at DSEI, I had a couple of conversations with senior cyber security people who expressed a desire to 'do away with gateways'. I appreciate that this statement is a little for effect, but I do understand the sentiment, as current CDS can tend to be one-dimensional.

What are the weaknesses of a cross domain gateway?

The main weakness of a Cross Domain Gateway is that we’re moving away from that world of simply checking for security issues, to one that requires several additional features and use cases:

  • Implement Data Centric Security (DCS) checks before allowing data in or out;

  • Identify a point where we check for trust within a Zero Trust (ZT) architecture, such as a certificate, provenance, or trusted source.

  • Provide the ability to check code created on the low side and deployed on the high side.

Using the current approach, to do the above, you may need to deploy many standalone approaches that don't talk to each other, and where data coming into a particular gateway needs to have DCS, ZT or other attributes so it can be checked.


But what if that 'gateway' was able to oversee multiple security models at the same time, recognising the attributes of each piece of data as it arrives and a dynamic policy applying the right checks based upon the relevant security model on the fly. In effect, a Policy Defined and Software Defined Gateway.

What is a software defined gateway?

A software defined gateway (SDG) represents the next evolution of the Cross Domain Solution, moving away from fixed-function appliances to a flexible, policy-driven security model. By abstracting the security policies from the underlying hardware, an SDG can implement multiple security models concurrently, recognising the attributes of each piece of data as it arrives and dynamically applying the appropriate checks.

This capability allows organisations to seamlessly transition from legacy security approaches to modern frameworks like Zero Trust and Data Centric Security over time, implementing incremental policies and filter modules to ensure the solution remains compliant and agile for both the past and future threat landscapes.

What are the benefits of a software defined gateway?

The biggest benefit of this approach is that it enables the transition from one CDS Security Model to another over a period of time. An example of this would be transitioning from today’s approach of performing deep content inspection on all content, to utilising trusted certificates or Data Centric Security (DCS) labelling as those approaches are adopted. So, rather than acquiring standalone appliances or applications for each Security Model, a Software Defined Gateway would allow your CDS approach to evolve, implementing incremental Security Models, policies, and filter modules to do the relevant checking.

What are the weaknesses of a Software Defined Gateway?

While the Software Defined Gateway (SDG) offers unmatched architectural flexibility and capability to handle complex, evolving security models, its primary 'weakness' lies not in its technology, but in the necessary shift in operational philosophy and effort during the transition phase. Moving from the static-policy model of a traditional appliance to a dynamic, policy-defined architecture demands a greater initial investment in expertise to define, implement, and maintain the complex security rules required by modern frameworks like zero trust and data centric security.

Because the SDG is built to evolve and integrate multiple security models, the operational challenge is ensuring that the organisation's underlying business policies and data classification strategies are mature and precise enough to fully leverage the power and agility of the software-defined environment from day one.

Nexor’s software defined gateway

What I described above is Nexor Protean, our high-assurance Software Defined Gateway. Given that it is available now, you can implement a Cross Domain Solution that complies with NCSC Principles today and evolve it as you start to implement Zero-Trust, Data-Centric Security, and other approaches over time. In effect, a CDS for the past, present, and future. Why not give us a call? We would be happy to develop your plan with you.

Read more posts on

About the author

Danny is an experienced leader of transformation in digital, data and innovation product and projects areas. Using a blend of commercial, product and business management expertise, Danny has a proven track record delivering significant programmes across public and private sectors in both large and small organisations.

Danny Wootton on Linkedin

Read more posts by Danny Wootton

Read more posts on