Containerized cross-domain solutions
The software-based containerized CDS addresses the limitations of hardware-based systems by providing scalable and cost-effective data transfer between security domains with reduced computational costs and efficient rule updates, ensuring secure communication across multiple domains.
Patent Information
- Application Number
- JP2023577677
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-06-21
- Filing Date
- 2022-05-25
- Publication Date
- 2025-05-20
- Estimated Expiration
- 2042-05-25
AI Technical Summary
Existing containerized cross-domain solutions (CDS) are costly, hardware-constrained, and require extensive recertification due to hardware-based implementations, limiting scalability and efficiency in managing multiple security domains.
A software-based containerized CDS using a cross-domain interface (CDI) server with network interface and data filter containers, enabling scalable and efficient data transfer between security domains by employing containerized processes and external rule updates without recertification.
The solution reduces computational and power costs, supports multiple security domains, and allows for seamless updates to security rules without reauthentication, enhancing scalability and cost-effectiveness compared to hardware-based systems.
Smart Images

Figure 0007680575000001 
Figure 0007680575000002 
Figure 0007680575000003
Abstract
Description
[Technical field]
[0001] The present disclosure relates to a containerized cross-domain solution (CDS). [Background technology]
[0002] A CDS is an integrated information assurance system that provides the ability to access, restrict, or transfer information between two or more security domains. A CDS may be one-way only (low to high domain or high to low domain) or it may be bidirectional. CDS are intended to prevent unauthorized cross-contamination of classified data between domains, prevent the transmission of malicious content, and prevent covert channels. Thus, CDS are designed to enforce domain separation and typically include some form of content filtering used to specify information that is not authorized for transfer between security domains or classification levels, such as between different military branches, intelligence agencies, or other operations critically dependent on the timely sharing of potentially classified information.
[0003] The goal of a CDS is to allow trusted network domains to exchange information unidirectionally or bidirectionally with other domains without introducing the potential for security threats normally associated with network connectivity. Although the goal is 100% assurance, this is not possible in practice, and therefore the development, evaluation, and deployment of a CDS is based on comprehensive risk management. Due to the sensitive nature of their use, all aspects of a certified CDS must be rigorously evaluated under security standards such as Lab-Based Security Assessment (LBSA) to reduce potential vulnerabilities and risks to the system itself and to those on which it is deployed. Evaluation and certification of CDS in the United States is primarily under the purview of the National Cross-Domain Strategic Management Office (NCDSMO) within the National Security Agency (NSA). Summary of the Invention
[0004] The present disclosure relates to containerized CDS. In one example, the computer-implemented method can include receiving, in a first network interface application, a data packet generated in a first security domain. The first network interface container can be executed to operate the network interface application, and the data packet can include data generated by a first process executing in the first security domain. The computer-implemented method can include evaluating, in a data filter, a data content of the data to determine whether the data is compromised. The filter container can be executed to operate the data filter. The computer-implemented method can include providing, in the data filter, the data packet to a second network interface application in response to determining that the data is not compromised. The second network interface container can be executed to operate the second network interface application. The computer-implemented method can include providing, in the second network interface application, the data packet to the second security domain for a second process executing in the second security domain.
[0005] In yet another example, the system may include a memory storing data that may include machine-readable instructions representing a cross-domain router for communicating data packets between a first security domain and a second security domain, and a content data rule database that may include a set of data rules for determining whether data of one or more data packets is compromised. The system may include one or more processors that access the memory and execute the machine-readable instructions to execute a first network interface container to operate a first network interface application, a second network interface container to operate a second network interface application, and a filter container to operate a data filter. The first network interface application may be programmed to receive a data packet generated in the first security domain. The data packet may include data generated by a first process running in the first security domain. The data filter may be programmed to query the content data rule database to obtain a set of data rules, and provide the data packet to a second network interface application in response to determining that the data content of the data does not violate the set of data rules. The second network interface application may be programmed to provide the data packet to a second security domain for a second process running in the second security domain.
[0006] In a further example, the computer-implemented method can include executing a first network interface container on a cross-domain interface (CDI) server to operate a first network interface application. The first network interface application can be programmed to receive a data packet from a first network, the data packet being generated in the first security domain. The data packet can include data generated by a first process running in the first security domain. The computer-implemented method can include executing a filter container on the CDI server to operate a data filter. The data filter can be programmed to query a content data rule database located outside the filter container on the CDI server to obtain a set of data rules and determine whether data content of the data of the data packet is compromised based on the set of data rules. The computer-implemented method can include executing a second network interface container on the CDI server to operate a second network interface application. The second network interface application can be programmed to provide the data packet to the second security domain over the second network for a second process running in the second security domain. [Brief description of the drawings]
[0007] [Figure 1] Figure 1 shows an example of a CDS system. [Diagram 2] Figure 2 shows an example of a cross-domain router. [Diagram 3] FIG. 3 is an example of a method for communicating data between a first security domain and a second security domain. [Figure 4] FIG. 4 is another example of a method for communicating data between a first security domain and a second security domain. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0008] The present disclosure relates to a containerized CDS. Existing CDSs rely on hardware-based implementations, which are not only very costly but also prevent scaling to larger environments. Thus, as more networks become involved in the CDS, the resources required become larger, and the hardware-based CDS often becomes a bottleneck for the entire data or enterprise system. Furthermore, the hardware-based CDS may grow exponentially as additional networks are incorporated, and recertification may be difficult because the hardware-based CDS cannot keep up with evolving technical requirements fast enough due to the redundant and time-consuming process of CDS certification. For example, in order for the hardware-based CDS to comply with security standards (e.g., those set by government agencies), the hardware-based CDS must go through a formal validation or certification process, which requires a great deal of time and effort. Thus, if the hardware-based CDS is modified (e.g., updated), the hardware-based CDS must be recertified according to the security standard to ensure that the modified hardware-based CDS is secure.
[0009] Disclosed herein are systems and methods that provide a containerized CDS that allows for scaling of security domains and efficient authentication of cross-domain resources. By implementing a software-based CDS in a container, the hardware constraints presented by existing CDSs are removed. Furthermore, the systems and methods disclosed herein allow the CDS to be reauthenticated more effectively since authenticated containers no longer need to be reauthenticated. The systems and methods disclosed herein provide a cost-effective and portable CDS that can be scaled to meet the needs of a user or entity and thus is no longer limited or constrained to a specific set of hardware as existing CDSs are. Furthermore, the systems and methods disclosed herein eliminate the need for dedicated personnel for installing and updating the CDS and thus reauthenticating. Because the systems and methods disclosed herein separate containerized processes into microservices, constant reauthentication of the CDS is no longer required since the container image remains unchanged and has access to external rules that can be modified (e.g., updated, changed, etc.) via an external program or user.
[0010] In some examples, the CDI server may be configured to employ a cross-domain router. The cross-domain router may be represented as coded instructions executable on the CDI server to facilitate the exchange of data between two or more security domains, and thus the movement of data between the security domains. The cross-domain router may include a first network interface container, a second network interface container, and a filter container. The network interface container may be executed to operate the respective first and second network interface applications. The filter container may be executed to operate the data filter. Each of the first and second network interface applications and the data filter may be configured to cooperate to facilitate the transfer of data between the respective security domains.
[0011] The first network interface application may be configured to include a first set of network rules for evaluation of one or more data packets generated in the first security domain. The one or more data packets may include data generated by a first process (e.g., an application or service) executing on a node of the first security domain. The first network interface application may be configured to provide the one or more data packets to a data filter in response to determining that the one or more data packets do not violate the first set of network rules. The data filter may include a set of data rules for evaluation of data content. The data filter may be configured to retrieve the set of data rules from a content data rule database located external to the cross-domain router. The set of data rules may be applied to data in the one or more data packets to determine whether the data is compromised. Thus, the data filter may be used to inspect data content of the data for malware, unwanted code and / or data.
[0012] In some examples, the data filter may be configured to provide one or more data packets having the data to a second network interface application in response to determining that the data is not compromised based on the set of data rules. The second network interface application may be configured to include a second set of network rules for evaluation of one or more data packets generated in the first security domain. The second network interface application may be configured to provide one or more data packets to the second domain in response to determining that the one or more data packets do not violate the second set of network rules. Thus, the CDI server enables processes (e.g., applications or services) executing on different security domains having different security levels to securely communicate data between each other. Furthermore, because the cross-domain router uses containers for data routing between security domains, the overall power consumption and computational costs at the CDI server may be reduced. Furthermore, implementing a cross-domain router on a CDI server is relatively low cost compared to hardware-based CDS, highly scalable, and can support any number of security domains.
[0013] FIG. 1 is an example of a CDS system 100. The CDS system 100 may be configured to transfer data between two or more security domains, such as a first security domain 102 and a second security domain 104. In some examples, each of the first security domain 102 and the second security domain 104 may be referred to as a security enclave. Each of the first security domain 102 and the second security domain 104 may be implemented on physical hardware, such as a computing resource, as disclosed herein. In some examples, each of the first security domain 102 and the second security domain 104 may be implemented on similar physical hardware. Each of the first security domain 102 and the second security domain 104 may include multiple physical or virtual computers that are networked together and may be referred to as nodes. The nodes may be implemented on respective physical hardware. In some examples, the nodes are virtual nodes that may reside on a hypervisor on similar physical hardware. In further examples, the physical nodes and virtual nodes may be implemented on similar physical hardware or across one or more different hardware systems. Each of the first security domain 102 and the second security domain 104 may be a physically separate security domain or may be a logically separate security domain that exists on the same physical hardware. The first security domain 102 and the second security domain 104 may have different security levels. For example, the first security domain 102 and the second security domain 104 may have different government security levels, such as unrestricted, restricted, classified, secret, unclassified, secret, and top secret.
[0014] Each of the first security domain 102 and the second security domain 104 can communicate with a CDI server 106. In some examples, the CDI server 106 can be referred to as a node. The CDI server 106 can be configured to facilitate the movement of data between the first security domain 102 and the second security domain 104. The CDI server 106 can pass the data through one or more filters that can be configured to evaluate the data against one or more data rules to determine if the data should be routed to the intended security domain, as disclosed herein. By using the CDI server 106 for communication of data between the first security domain 102 and the second security domain 104, cross-domain contamination of sensitive data can be minimized or eliminated, the possibility of malicious content being transmitted can be reduced or eliminated, or covert channels can be prevented.
[0015] The first security domain 102 can be configured to communicate with the CDI server 106 via a first network 108, and the second security domain 104 can be configured to communicate with the CDI server 106 via a second network 110. In some examples, the first security domain 102 can include the first network 108. In additional or alternative examples, the second security domain 104 can include the second network 110. Each network 108 and 110 can be a physical network or a virtual network. For example, if one or more virtual nodes in each of the first security domain 102 and the second security domain 104 are implemented in a respective virtualization environment (e.g., virtual machine), the networks 108 and 110 can be implemented as virtual networks and can be configured to enable the one or more virtual nodes to communicate with the CDI server 106. In further examples, each network 108 and 110 is a physical network such as a wireless network (e.g., a local area network (LAN) wireless network, a cellular network, etc.) and / or a wired network (e.g., a digital subscriber line (DSL), cable line, fiber optic line, etc.). In some examples, each of the first network 108 and the second network 110 includes electrical cables (e.g., coaxial, Ethernet, telephone lines, etc.) and / or optical cables. Each of the first security domain 102 and the second security domain 104 may include a respective network interface (not shown in FIG. 1 ) to enable one or more nodes of each security domain 102 and 104 to communicate with the CDI server 106.
[0016] As an example, one or more nodes in each of the first security domain 102 and the second security domain 104 may provide a software environment for implementing one or more processes, such as services and / or applications. In some examples, a first process running on a first node in the first security domain 102 may be configured to communicate data to a second process running on a second node in the second security domain 104 via the CDI server 106 as disclosed herein. In some examples, the second process may be programmed to communicate data to the first node via the CDI server 106 as disclosed herein. The CDI server 106 may be used to route data between the first security domain 102 and the second security domain 104. The data may include files, applications, service data, scripts, sensor data, image data, or other types of data. In some examples, the data may include user-generated data. In some examples, the data is mission-critical data, and at least one of the first and second processes may be configured to generate a message including the mission-critical data for routing to another process in a different security domain. The first and second processes may be configured to automatically and / or manually send data to the CDI server 106. In some examples, the CDI server 106 may be configured to poll at least one of the first and second processes to obtain data for another process. For example, at least one of the first and second processes may be configured to store data in a node (e.g., in a specific folder) in a respective security domain that the CDI server 106 can access via one of the first network 108 and the second network 110 to communicate with another application that resides in a different security domain.
[0017] The CDI server 106 may include computing resources 112. The computing resources 112 may include a processor 114 and a memory 116. The memory 116 may store machine-readable instructions that may be retrieved and executed by the processor 114 for container virtualization and data processing / routing as disclosed herein. By way of example, the memory 116 may be implemented as a non-transitory computer storage medium, such as a volatile memory (e.g., random access memory), a non-volatile memory (e.g., a hard disk drive, a solid-state drive, a flash memory, etc.), or a combination thereof. The processor 114 may be implemented as, for example, one or more processor cores. In this example, the components of the CDI server 106 are shown as being implemented on a single server, but in other examples, the components may be distributed across different servers (e.g., computers, devices, etc.) and may communicate, for example, via a network (e.g., wireless and / or wired network). In some examples, the CDI server 106 may be implemented in a cloud computing environment. The cloud computing environment may include one or more processing units (e.g., servers). Other components of a cloud computing environment include storage devices, networking devices (eg, switches), and the like.
[0018] In some examples, the computing resource 112 includes one or more network interfaces 118. For clarity and brevity, other elements of the computing resource 112 are omitted. The one or more network interfaces 118 may include communication devices, such as a transmitter, a receiver, a transceiver, a modem, and / or a network interface card, to facilitate the movement of data between the first security domain 102 and the second security domain 104. For example, a first network interface of the one or more network interfaces 118 may be coupled to the network 108, and a second network interface of the one or more network interfaces 118 may be coupled to the second network 110. The first network interface may be configured to facilitate the movement of data between the CDI server 106 and the first security domain 102. The second network interface may be configured to facilitate the movement of data between the CDI server 106 and the second security domain 104.
[0019] The memory 116 may include an operating system 120. The operating system 120 may be stored in the memory 116 as coded instructions (e.g., computer and / or machine readable instructions) and executed by the processor 114. The operating system 120 may be programmed to support a container system 122. By way of example, the operating system 120 may be Linux, Microsoft Windows, Apple OS X, or any operating system that supports virtual containerization. The container system 122 in the example of FIG. 1 is implemented on the CDI server 106, but in other examples, the container system 122 may be implemented using, for example, a personal computer, a mobile phone (e.g., a cell phone, a smartphone, etc.), a tablet computer, or any other type of computing device. The container system 122 may be programmed to allocate resources of the CDI server 106 for containers, such as the network interface containers 124 and 126 and the filter container 128, which may be collectively configured to cooperate to define or form a cross-domain router 130, as shown in FIG. 1. The cross-domain router 130 may be programmed to control the flow of information between the first security domain 102 and the second security domain 104. The network interface containers 124 and 126, as well as the filter container 128, may be stored in the memory 116 as coded instructions (e.g., computer and / or machine readable instructions) and executed by the processor 114 to control the flow of information between the first security domain 102 and the second security domain 104.
[0020] In some examples, the container system 122 can employ pods, where the pods can include the network interface containers 124 and 126 and the filter container 128. For example, the network interface containers 124 and 126 and the filter container 128 can be combined to constitute a pod. By way of example, the pod can be a Kubernetes pod or another type of pod. The pod can be configured to host an instance of each process (e.g., application or service) included with each container 124, 126, and 128. Because the containers 124, 126, and 128 are located within the same pod, the containers 124, 126, and 128 can be co-scheduled in a shared context on the CDI server 106.
[0021] Network interface containers 124 and 126, and filter container 128 execute respective containerized processes as disclosed herein. In a computing environment, a container is a virtual construct used to run isolated instances of an application or service in a host environment, such as CDI server 106. Containers provide virtualization at the operating system level by abstracting (e.g., isolating) the application or service from an operating system, such as operating system 120. For example, an application or service running in a container may be isolated from applications or services running on CDI server 106 or in other containers.
[0022] In some examples, the operating system 120 may be programmed (e.g., using a customized kernel) to provide isolation and resource management for processes (e.g., applications or services running on a host operating system) executing within the CDI server 106. Isolation of processes is known as containers. Thus, the network interface containers 124 and 126 and the filter container 128 in the example of FIG. 1 share the operating system 120. Thus, processes running within each container are isolated from other processes running within each container on the operating system 120. Exemplary operating system virtualization environments can include Linux Containers LXC and LXD, Docker™, OpenVZ™, and the like. The network interface containers 124 and 126 and the filter container 128 may be programmed to run directly from the operating system in the container without a hypervisor layer or dedicated memory, disk space, or processor. Thus, the CDS containerization approach disclosed herein does not require a virtual machine to be implemented in the CDI server 106. Thus, coded instructions (e.g., computer and / or machine readable instructions) representing the container system 122 can interface to resources of the CDI server 106 without a hypervisor, and the coded instructions can interface to resources of the CDI server 106 without depending on any particular operating system configuration.
[0023] As an example, during operation (e.g., runtime), the network interface containers 124 and 126 may execute to operate the respective first and second network interface applications 132 and 134. The filter container 128 may execute to operate the data filter 136. Each of the first and second network interface applications 132 and 134 may be programmed to facilitate communication of data between the respective security domains 102 and 104. For example, the first network interface application 132 may be programmed to receive data generated by a first process executing in the first security domain 102. The data generated by the first process may be received at a first network interface of the one or more network interfaces 118. The first network interface container 124 may include a first set of network rules for whitelisting traffic between services and / or applications. The first network interface application 132 may be programmed to process the data based on the first set of network rules. In some examples, data generated by the second process may be received at a second network interface of the one or more network interfaces 118. The second network interface container 126 may include a second set of network rules for whitelisting traffic between the services and / or applications. The second network interface application 134 may be programmed to process the data based on the second set of network rules.Each of the first network interface application 132 and the second network interface application 134 may be programmed to enforce respective network rules to prevent a rogue service operating in the respective security domain from issuing messages to other applications or services operating on a different security domain.
[0024] In some examples, the first network interface application 132 and the second network interface application 134 may be implemented as a layer 3 proxy container and configured to support a layer 3 protocol. As an example, data generated by the first process may be packetized in the first security domain 102 and transmitted to the CDI server 106 via the first network 108. The first network interface of the network interface 118 may be configured to receive the packetized data. The packetized data may include header information, Internet Protocol (IP) information, data, and other information. Each segment of the packetized data may have an assigned source and destination IP address. The first network interface application 132 may be programmed to evaluate the packetized data against a first set of network rules to determine whether the packetized data violates any of the first set of network rules. In some examples, the packetized data includes a data label, and the first set of network rules includes one or more label rules. The first network interface application 132 may be programmed to evaluate the data label against the one or more label rules to determine whether the data label matches the data label of the one or more label rules. The first network interface application 132 may be programmed to provide the data to the data filter 136 in response to determining that the data labels of the data match the data labels of the one or more label rules. In some examples, the first network interface application 132 may be programmed to refuse to pass the data to the data filter 136 in response to determining that the data labels of the data do not match the data labels of the one or more label rules.
[0025] The data filter 136 may be programmed to apply the packetized data to the set of data rules to determine whether the data of the packetized data violates one or more rules of the set of data rules. In some examples, the set of data rules is located outside the filter container 128 of a volume that the data filter 136 may be programmed to access for processing of the data. In some examples, the set of data rules is stored in a content data rule database. The data filter 136 may be programmed to provide the packetized data to the second network interface application 134 in response to determining that the data does not violate the set of data rules. In other examples, the data filter 136 may be programmed to refuse to pass the packetized data to the second network interface application 134 in response to determining that the data violates at least one data rule of the set of data rules.
[0026] In some examples, the second network interface application 134 may be programmed to receive the packetized data from the data filter 136. The second network interface application 134 may be programmed to transmit the packetized data over the second network 110 to the second security domain 104 via a second network interface of the network interface 118. In some examples, the second network interface application 134 may be programmed to evaluate the packetized data against a second set of network rules to determine whether the packetized data violates any of the second set of network rules. In response to determining that the packetized data does not violate any of the second set of network rules, the second network interface application 134 may be programmed to transmit the packetized data to the second security domain 104. The second security domain 104 may be configured to extract data from one or more packets and provide the extracted data to a second process for use therewith.
[0027] In some examples, the content data rules database may be programmed to receive an updated set of data rules based on user input data. The data filter 136 may be programmed to query the content data rules database to obtain the updated set of data rules to determine that data having the packetized data (or subsequent packetized data) is compromised. The data filter 222 may be programmed to evaluate data content of the data of the packetized data to determine whether the data is compromised. In some examples, the data filter 222 may be programmed to provide the packetized data to the second network interface application 134 in response to determining that the data of the packetized data is not compromised. The second network interface application 134 may be programmed to provide the packetized data to the second security domain 104 for a second process operating therein.
[0028] Thus, the CDI server 106 allows processes (e.g., applications or services) running on different security domains with different security levels to securely communicate data between each other. Furthermore, because the cross-domain router 130 uses containers for data routing between security domains, the overall power consumption and computational costs in the CDI server 106 can be reduced. Furthermore, implementing the cross-domain router 130 on the CDI server 106 is relatively low-cost compared to hardware-based CDS, highly scalable, and can support any number of security domains. Although the example of FIG. 1 shows the CDI server 106 managing communication between two security domains, in other examples, the CDI server 106 may be configured to manage communication of data between three or more security domains.
[0029] FIG. 2 is an example of a cross-domain router 200. In some examples, the cross-domain router 200 is the cross-domain router 130 as shown in FIG. 1. Thus, the following description of FIG. 2 also refers to FIG. 1. The cross-domain router 200 may represent coded instructions that may be stored in the memory 116 of the CDI server 106. The processor 114 may be configured to access the memory 116 and execute the coded instructions to regulate (e.g., enable and / or restrict) the transfer of data between two or more security domains, such as a first security domain 202 and a second security domain 204 as shown in FIG. 2. In some examples, the first security domain 202 is the security domain 102 and the second security domain 204 is the second security domain 104 as shown in FIG. 1. Each of the first security domain 202 and the second security domain 204 may have a different security level and may include one or more nodes that may represent computing devices (e.g., computers, tablets, mobile phones, mission deployment systems, etc.). In some examples, one or more nodes may represent a virtual computer, such as a virtual machine.
[0030] In some examples, a first process (e.g., an application or service) may be running on a first node in the first security domain 202. The process may be programmed to generate data that is consumed (e.g., processed) by a second process running on a second node in the second security domain 204. As an example, the data generated by the respective node may be a message. Thus, in some examples, the first process may be a messenger application or service. The message may include sensor status information, system status information, mission status information, or other types of status information. The data may be encapsulated in a data packet and transmitted from the first security domain 202 to the CDI server 106 over the first network 206. As disclosed herein, the cross-domain router 200 may be programmed to evaluate the data packet against a set of network and data rules to determine whether the data packet is allowed to be provided to the second security domain 204. The CDI server 106 may be configured to provide the data packet to the second security domain 204 via the second network 208 for a second process in response to the cross-domain router 200 based on an evaluation of the data packet against a set of network and data rules as disclosed herein.
[0031] The cross-domain router 200 may include a first network interface container 210 and a second network interface container 212. The first network interface container 210 may be the first network interface container 124, and the second network interface container 212 may be the second network interface container 126, as shown in FIG. 1. By way of example, during operation (e.g., runtime), the first network interface container 210 and the second network interface container 212 may execute to operate respective first network interface applications 214 and second network interface applications 216. The first network interface application 214 may be the first network interface application 132, and the second network interface application 216 may be the second network interface application 134, as shown in FIG. 1. The first network interface application 214 may be programmed to evaluate data packets against a first set of network rules 218. The first set of network rules 218 may include data routing rules for the first network 206. The term "set" as used herein with respect to network rules and data rules may include a single rule or multiple rules. Thus, for example, the first set of network rules 218 may include a single network rule or two or more different network rules. As shown in FIG. 2, the network interface container 210 includes a first set of network rules 218 that may be accessed by the first network interface application 214.
[0032] The cross-domain router 200 may further include a filter container 220. By way of example, during operation (e.g., runtime), the filter container 220 may be executed to operate a data filter 222. The filter container 220 may be a filter container 128 as shown in FIG. 1. Thus, in some examples, the data filter 222 is a data filter 136 as shown in FIG. 1. The first network interface application 214 may be programmed to evaluate the data packet against the first set of network rules 218 to determine whether the data packet violates at least one network rule of the first set of network rules 218. The first network interface application 214 may be programmed to provide the data packet to the data filter 222 based on the evaluation of the data packet against the first set of network rules 218.
[0033] In some examples, the data packet includes a data label, and the first set of network rules 218 includes one or more label rules. The first network interface application 214 may be programmed to evaluate the data label against the one or more label rules to determine whether the data label matches a data label of the one or more label rules. The first network interface application 214 may be programmed to provide the data packet to the data filter 222 in response to determining that the data label of the data matches a data label of the one or more label rules. As disclosed herein, the data filter 222 may be programmed to evaluate a data content of the data of the data packet to determine whether the data is compromised. By way of example, in response to determining that the data of the data packet includes malware, or unwanted code and / or data, the data may be referred to as compromised data.
[0034] In some examples, the network interface container 210 may execute to operate the crypto module 224. Although the example of FIG. 2 shows the crypto module 224 separate from the first network interface application 214, in some examples, the first network interface application 214 may include the crypto module 224. In examples where the data packets are encrypted, the crypto module 224 may be programmed to decrypt the data packets for evaluation against the first set of network rules 218. The crypto module 224 may be programmed to encrypt and decrypt the data packets based on a two-way authentication scheme between the crypto module 224 and each crypto module operating on each node of the first security domain 202. Thus, in some examples, the first node may be configured to encrypt the data packets and provide the encrypted data packets to the CDI server 106 over the first network 206, where the encrypted data packets can be decrypted by the crypto module 224. In some examples, the two-way authentication is mutual transport layer authentication (mTLS). In some examples, an mTLS certificate may be derived by the crypto module 224 (and each node of the first security domain 202) from a root certificate authority located on the first network 206 to enable the CDI server 106, and thus the first network interface application 214, to securely communicate with one or more nodes of the first security domain 202, such as the first node. In some examples, the first security domain 202 may include the first network 206. In additional or alternative examples, the second security domain 204 may include the second network 208.
[0035] As a further example, the data filter 222 may be programmed to provide the data packet to the second network interface application 216 in response to determining that the data is not compromised as disclosed herein. The second network interface application 216 may be programmed to evaluate the data packet against a second set of network rules 226. As shown in FIG. 2, the network interface container 212 includes a second set of network rules 226 that may be accessed by the second network interface application 216. The second set of network rules 226 may include data routing rules for the second network 208. The second set of network rules 226 may be different from the first set of network rules 218 and may be based on the security level of the respective security domains. For example, the first security domain 202 may be designated as a top secret security domain and the second security domain 204 may be designated as a secret security domain. The top secret security domain may have one set of network rules and the secret security domain may have another set of network rules that may be based on the security level of the respective security domain. Thus, in some examples, the first security domain 202 and the second security domain 204 may have different network rules. Each of the first network rules 218 and the second network rules 226 may vary based on the type of data and the type of data that may be provided to the respective security domain. In some examples, at least one of the first set 218 and the second set 216 of network rules may include a message type rule (e.g., health, status, etc.) that may be provided to the respective security domain.Each network interface application may be programmed to pass messages having data of a particular message type and block all other message types based on a respective set of network rules.
[0036] In some examples, as disclosed herein, the data packet may include a data label. The second set of network rules 226 may include one or more label rules. The second network interface application 216 may be programmed to evaluate the data label against the one or more label rules to determine whether the data label matches a data label of the one or more label rules. The second network interface application 216 may be programmed to provide the data packet to the second security domain 204 via the second network 208 in response to determining that the data label of the data matches a data label of the one or more label rules.
[0037] In some examples, the network interface container 212 may execute to operate a crypto module 228. Although the example of FIG. 2 shows the crypto module 228 separate from the second network interface application 216, in some examples, the second network interface application 216 may include the crypto module 228. The crypto module 228 may be programmed to encrypt and decrypt data packets based on a two-way authentication scheme between the crypto module 228 and each crypto module operating on each node of the second security domain 204. For example, the crypto module 228 may be programmed to encrypt the data packet in response to the second network interface application 216 determining that the data packet does not violate the second set of network rules 226. In some examples, the two-way authentication is mTLS. In some examples, an mTLS certificate may be derived by the crypto module 228 (and each node of the second security domain 204) from a root certificate authority located on the second network 208 to enable the CDI server 106, and thus the second network interface application 216, to communicate securely with one or more nodes of the second security domain 204, such as the second node.
[0038] In some examples, a data packet originating from the first security domain 202 may be referred to herein as a first data packet. As an example, a second data packet may be generated by a second process (e.g., an application or service) running on a second node of the second security domain 204. The process may be programmed to generate data that is consumed (e.g., processed) by the first process running on the first node of the first security domain 202. As an example, the data generated by the respective node may be a message as disclosed herein. The data may be encapsulated in the second security domain 204 to form a second data packet and transmitted to the CDI server 106 via the second network 208.
[0039] The second network interface application 216 may be programmed to evaluate the second data packet against the second set of network rules 226 to determine whether the second data packet violates at least one of the second set of network rules 226 in a manner the same or similar to that disclosed herein with respect to the first data packet. The second network interface application 216 may be programmed to provide the second data packet to the data filter 222 in response to determining that the second data packet does not violate the second set of network rules 226. In examples in which the second data packet is encrypted, the crypto module 228 may be programmed to decrypt the second data packet for evaluation against the second set of network rules 226 in a manner the same or similar to that disclosed with respect to the first data packet.
[0040] In some examples, the data filter 222 may be programmed to provide the second data packet to the first network interface application 214 in response to determining that the data of the second data packet is not compromised in the same or similar manner as disclosed herein with respect to the first data packet. The first network interface application 214 may be programmed to provide the second data packet to the first security domain 202 via the first network 206 for the first process based on an evaluation of the second data packet against the first set of network rules 218 in the same or similar manner as disclosed herein with respect to the first data packet.
[0041] In some examples, the filter container 220 can include a first input filter container 230, a first output validator container 232, a second input filter container 234, and a second output validator container 236. In some examples, the first input filter container 230, the first output validator container 232, the second input filter container 234, and the second output validator container 236 may be executed on the CDI server 106. In some examples, the first input filter container 230, the first output validator container 232, the second input filter container 234, and the second output validator container 236 can be collectively referred to as the filter container 220. Thus, in some examples, first input filter container 230 may be executed to operate first input filter 238, first output validator container 232 may be executed to operate first output validator 240, second input filter container 234 may be executed to operate second input filter 242, and second output validator container 236 may be executed to operate second output validator 244. In some examples, first input filter 238, first output validator 240, second input filter 242, and second output validator 244 may be collectively referred to as data filter 222.
[0042] As shown in FIG. 2, a first data path 246 (e.g., a data pipe) may be established to provide a unidirectional data path between the first input filter 238 and the first output validator 240, and a second data path 248 (e.g., a data pipe) may be established to provide a unidirectional data path between the second input filter 242 and the second output validator 244. The first input filter 238 may be programmed to receive a first data packet from the first network interface application 214. The first input filter 238 may be programmed to communicate with a content data rules database 250. As shown in FIG. 2, the content data rules database 250 is located outside the cross-domain router 200 and thus the filter container 220. For example, the first input filter 238 may be programmed to query the content data rules database 250 for a first set of data rules 252. In some examples, the content data rules database 250 is stored in the memory 116 of the CDI server 106. In other examples, the content data rules database 250 may be located external to the CDI server 106 and queried as disclosed herein to obtain the data rules.
[0043] The first set of data rules 252 may include one or more data content rules that identify the type of content, and therefore the data, that may be provided from the first security domain 202 to the second security domain 204. In some examples, the first set of data rules 252 may include malware signatures or rules for detecting different types of malware that may be embedded within the data of one or more data packets originating from the first security domain 202. The first input filter 238 may be programmed to evaluate the data content of the data of the first data packet against the first set of data rules 252 to determine whether the data is compromised. In some examples, the first input filter 238 may be programmed to evaluate the data content of the data of the first data packet against the first set of data rules 252 to determine whether the type of data in the data packet may be provided to the second security domain 204.
[0044] The first input filter 238 may be programmed to communicate the first data packet to the first output validator 240 via the first data path 246 in response to determining that the data content of the data of the first data packet does not violate the first set of data rules 252. In some examples, the first output validator 240 may be programmed to communicate with a content data rules database 250. The first output validator 240 may be programmed to query the content data rules database 250 for the first set of data rules 252. The first output validator 240 may be programmed to evaluate the data content of the data of the first data packet against the first set of data rules 252 in the same or similar manner as the first input filter 238. Thus, both the first input filter 238 and the first output validator 240 may be programmed to evaluate the first data packet based on a similar set of data rules. In some examples, the first input filter 238 may have a different code base than the first output validator 240. In some examples, a malware attack may cause one of the first input filter 238 and the first output validator 240 to be taken offline. Because the first input filter 238 and the first output validator 240 can have different code bases (e.g., coded by different developers), the remaining filter or validator can remain functional and online, thus protecting against data leakage from each security domain to another, or malware infiltrating a given security domain.
[0045] In some examples, the second input filter 242 may be programmed to receive a second data packet from the second network interface application 216. The second input filter 242 may be programmed to communicate with the content data rule database 250. For example, the second input filter 242 may be programmed to query the content data rule database 250 for a second set of data rules 254. The second set of data rules 254 may include one or more data content rules that identify the types of content, and therefore data, that may be provided from the second security domain 204 to the first security domain 202. In some examples, the second set of data rules 254 may include malware signatures or rules for detecting different types of malware that may be embedded within the data of one or more data packets originating from the second security domain 204. The second input filter 242 may be programmed to evaluate the data content of the data of the second data packet against the second set of data rules 254 to determine whether the data is compromised. In some examples, the second input filter 242 may be programmed to evaluate the data content of the data of the second data packet against the second set of data rules 254 to determine whether the type of data in the second data packet can be provided to the first security domain 202.
[0046] The second input filter 242 may be programmed to communicate the second data packet to the second output validator 244 via the second data path 248 in response to determining that the data content of the data of the second data packet does not violate the second set of data rules 254. In some examples, the second output validator 244 may be programmed to communicate with a content data rules database 250. The second output validator 244 may be programmed to query the content data rules database 250 for the second set of data rules 254. The second output validator 244 may be programmed to evaluate the data content of the data of the second data packet against the second set of data rules 254 in the same or similar manner as the second input filter 242. Thus, both the second input filter 242 and the second output validator 244 may be programmed to evaluate the second data packet based on a similar set of data rules.
[0047] In some examples, the second input filter 242 can have a different code base than the second output validator 244. In some examples, a malware attack may cause one of the second input filter 242 and the second output validator 244 to be taken offline. Because the second input filter 242 and the second output validator 244 can have different code bases (e.g., coded by different developers), the remaining filter or validator can remain functional and online, thus protecting against data leakage from the respective security domain to another security domain, or malware infiltrating a given security domain. As an example, at least one of the first set of data rules 252 and the second set of data rules can include field validation rules, field removal rules, and other types of rules.
[0048] Thus, the cross-domain router 200 allows processes (e.g., applications or services) running on different security domains with different security levels to securely communicate data between each other. Furthermore, because the cross-domain router 200 uses containers for data routing between security domains, it can reduce the overall power consumption and computational costs at the CDI server 106. Furthermore, implementing the cross-domain router 200 on the CDI server 106 is relatively low cost compared to hardware-based CDS, highly scalable, and can support any number of security domains. Although the example of FIG. 2 shows the cross-domain router 200 managing communication between two security domains, in other examples, the cross-domain router 200 may be configured to manage communication of data between three or more security domains.
[0049] Furthermore, because the content data rules database 250 is located outside the filter container 128 and thus outside each of the containers 230, 232, 234, and 236, there is no need to revalidate each of the containers 230, 232, 234, and 236 following updates or changes to the data rules to ensure that each of the containers 230, 232, 234, and 236 complies with security standards (e.g., as defined by an entity or organization such as a government agency). Thus, each of the containers 230, 232, 234, and 236 does not need to go through a formal validation or authentication process after initially being authenticated in response to a change to the data rules. This is because each of the containers 230, 232, 234, and 236 is programmed to enable communication with the content data rules database 250 that stores data rules located outside the cross-domain router 200 and thus outside each of the containers 230, 232, 234, and 236. Thus, the data rules in the content data rules database 250 may be updated based on user input data 256, which may be provided based on user input at a user input device 258 (e.g., a keyboard, etc.). Thus, a user may modify and update data rules without having to re-authenticate each container 230, 232, 234, and 236. Furthermore, although the example of FIG. 2 illustrates the cross-domain router 200 managing data flow between two security domains, in other examples, the cross-domain router 200 may be configured to manage data flow between three or more security domains.
[0050] With the structural and functional features discussed above in mind, the exemplary method will be better understood with reference to Figures 3-4. For ease of explanation, the exemplary method of Figures 3-4 is shown and described as being performed sequentially, however, it should be understood and appreciated that the exemplary method is not limited by the order shown, as in other examples some actions may occur multiple times, and / or simultaneously, in a different order than as shown and described herein.
[0051] FIG. 3 is an example of a method 300 for communicating data between a first security domain and a second security domain, such as the first security domain 102 and the second security domain 104 as shown in FIG. 1. The method 300 may be implemented by the cross-domain router 130 as shown in FIG. 1 or the cross-domain router 200 as shown in FIG. 2. Thus, the following description of FIG. 3 also refers to FIG. 1-FIG. 2. The method 300 may begin at 302 by receiving a data packet generated in a first security domain (e.g., the first security domain 102 as shown in FIG. 1) at a first network interface application (e.g., the first network interface application 132 as shown in FIG. 1). A first network interface container (e.g., the first network interface container 124 as shown in FIG. 1) may be executed on a CDI server (e.g., the CDI server 106 as shown in FIG. 1) to operate the first network interface application. At 304, a data filter (e.g., data filter 136 as shown in FIG. 1 ) evaluates the data content of the data to determine whether the data is compromised. A filter container (e.g., filter container 128 as shown in FIG. 1 ) may be executed on the CDI server to operate the data filter. At 306, in response to determining that the data is not compromised, the data filter provides the data packet to a second network interface application. A second network interface container (e.g., second network interface container 128 as shown in FIG. 1 ) may be executed on the CDI server to operate the first network interface application. At 308, the second network interface application provides the data packet to a second security domain (e.g., second security domain 104 as shown in FIG. 1 ) for a second process running in the second security domain.
[0052] FIG. 4 is an example of a method 400 for communicating data between a first security domain and a second security domain, such as the first security domain 102 and the second security domain 104 as shown in FIG. 1. The method 400 may be implemented by a cross-domain router 130 as shown in FIG. 1, or a cross-domain router 200 as shown in FIG. 2. Thus, the following description of FIG. 4 also refers to FIGS. 1-2. The method 400 may begin at 402 by executing a first network interface container (e.g., the first network interface container 124 as shown in FIG. 1) on a CDI server (e.g., the CDI server 106 as shown in FIG. 1) to run a first network interface application (e.g., the first network interface application 132 as shown in FIG. 1). The first network interface application may be programmed to receive a data packet generated in a first security domain (e.g., first security domain 102 as shown in FIG. 1) from a first network (e.g., first network 108 as shown in FIG. 1). The data packet may include data generated by a first process executing in the first security domain.
[0053] At 404, a filter container (e.g., filter container 128 as shown in FIG. 2) is executed on the CDI server to operate a data filter (e.g., data filter 136 as shown in FIG. 1). The data filter may be programmed to query a content data rule database (e.g., content data rule database 250 as shown in FIG. 2) located outside the filter container to obtain a set of data rules and determine whether data content of the data of the data packet is compromised based on the set of data rules. At 406, a second network interface container (e.g., second network interface container 126 as shown in FIG. 1) is executed on the CDI server to operate a second network interface application (e.g., second network interface application 134 as shown in FIG. 1). The second network interface application may be programmed to provide data packets to a second security domain (e.g., second security domain 104 as shown in FIG. 1) via a second network (e.g., second network 110 as shown in FIG. 1) for a second process running in the second security domain.
[0054] The above description is an example. Of course, it is not possible to describe every conceivable combination of components or methods, but one of ordinary skill in the art will recognize that many more combinations and permutations are possible. Accordingly, the present disclosure is intended to embrace all such changes, modifications, and variations that fall within the scope of this application, including the appended claims. As used herein, the term "includes" means including, but not limited to, the term "based on" means based at least in part on. Furthermore, when a disclosure or claim recites "a," "a first," "another" element, or the equivalent thereof, it should be construed as including one or more such elements, and does not require or exclude two or more such elements. The technical ideas contained in this disclosure are described below as appendices. (Appendix 1) 1. A computer-implemented method comprising: Receiving a data packet generated in a first security domain at a first network interface application. a first network interface container is executed to operate the network interface application, and the data packet includes data generated by a first process executing in the first security domain, the method comprising: Evaluating, in a data filter, a data content of the data to determine whether the data has been compromised. a filter container is executed to operate the data filter, the method comprising: providing, at the data filter, the data packet to a second network interface application in response to determining that the data has not been compromised. a second network interface container is executed to operate the second network interface application, the method further comprising: providing the data packet to a second security domain for a second process executing in the second security domain in the second network interface application; A computer-implemented method comprising: (Appendix 2) evaluating, in the first network interface application, the data packet against a set of network rules for a network to determine whether the data packet violates at least one network rule of the set of network rules; in response to determining that the data packet does not violate the set of network rules, providing, at the first network interface application, the data packet to the data filter. 2. The computer-implemented method of claim 1, further comprising: (Appendix 3) the set of network rules is a first set of network rules, the network is a first network, and the method comprises: evaluating, in the second network interface application, the data packet against a second set of network rules for a second network to determine whether the data packet violates at least one network rule in the second set of network rules; in response to determining that the data packet does not violate the second set of network rules, providing, at the second network interface application, the data packet to the second security domain for the second process executing in the second security domain. 3. The computer-implemented method of claim 2, further comprising: (Appendix 4) 4. The computer-implemented method of claim 3, wherein the data filter is configured to evaluate the data content of the data against a set of data rules to determine whether the data has been compromised. (Appendix 5) Executing coded instructions in a cross-domain interface (CDI) server representing a cross-domain router for communicating data packets between the first security domain and the second security domain. 5. The computer-implemented method of claim 4, further comprising: the cross-domain router including the first and second network interface containers and the filter container. (Appendix 6) 6. The computer-implemented method of claim 5, wherein the first and second network interface containers and the filter container are combined to form a pod. (Appendix 7) 6. The computer-implemented method of claim 5, wherein the CDI server comprises a memory for storing the coded instructions representing the cross-domain router, the method further comprising storing in the memory a content data rule database comprising the set of data rules for determining whether the data of the data packet is compromised, the content data rule database being located outside the filter container. (Appendix 8) 8. The computer-implemented method of claim 7, further comprising: in the data filter, querying the content data rules database to obtain the set of data rules for determining whether the data of the data packet has been compromised. (Appendix 9) The data packet is a first data packet, and the method includes: receiving, in the content data rules database, an updated set of data rules based on user input; querying the content data rules database in the data filter to obtain the updated set of data rules for determining whether data of a second data packet generated in the first security domain has been compromised; evaluating, in the data filter, a data content of the data in the second data packet to determine whether the data in the second data packet has been compromised; in response to determining that the data in the second data packet is not compromised, providing, at the data filter, the second data packet to the second network interface application; providing the second data packet to the second security domain at the second network interface application; 9. The computer-implemented method of claim 8, further comprising: (Appendix 10) 1. A system comprising: a memory storing machine-readable instructions representative of a cross-domain router for communicating data packets between a first security domain and a second security domain, and data including a content data rule database including a set of data rules for determining whether data of one or more data packets has been compromised; one or more processors that access the memory and execute the machine-readable instructions to execute a first network interface container to operate a first network interface application, a second network interface container to operate a second network interface application, and a filter container to operate a data filter; Equipped with the first network interface application is programmed to receive a data packet generated in the first security domain, the data packet including data generated by a first process executing in the first security domain; the data filter is programmed to query the content data rules database to obtain the set of data rules, and in response to determining that data content of the data does not violate the set of data rules, provide the data packet to the second network interface application; The second network interface application is programmed to provide the data packets to the second security domain for a second process executing in the second security domain. (Appendix 11) The first network interface container comprises a set of network rules for a network, and the first network interface application comprises: evaluating the data packet against the set of network rules to determine whether the data packet violates at least one network rule of the set of network rules; in response to determining that the data packet does not violate the set of network rules, providing the data packet to the data filter. 11. The system of claim 10, programmed to: (Appendix 12) 12. The system of claim 11, wherein the set of network rules is a first set of network rules, the network is a first network, the second network interface container includes a second set of network rules for the second network, the second network interface application is programmed to evaluate the data packet against the second set of network rules to determine whether the data packet violates at least one network rule of the second set of network rules, and in response to determining that the data packet does not violate the second set of network rules, the second network interface application is programmed to provide the data packet to the second security domain for a second process running in the second security domain. (Appendix 13) The data packet is a first data packet, and the second network interface application receiving a second data packet generated in the second security domain, the second data packet may include data generated by the second process executing in the second security domain; The second network interface application comprises: evaluating the second data packet against the second set of network rules to determine whether the second data packet violates at least one network rule of the second set of network rules; In response to determining that the second data packet does not violate the second set of network rules, providing the second data packet to the data filter. 13. The system of claim 12, programmed to: (Appendix 14) 14. The system of claim 13, wherein the set of data rules is a first set of data rules, and the content data rules database includes a second set of data rules for determining whether data of the second data packet generated by the second process has been compromised. (Appendix 15) The data filter includes: Querying the content data rules database to obtain the second set of data rules; In response to determining that data content of the data in the second data packet does not violate the second set of data rules, providing the second data packet to the first network interface application. 15. The system of claim 14, programmed to: (Appendix 16) 16. The system of claim 15, wherein the first network interface application is programmed to provide the second data packet to the first security domain for the first process running in the first security domain. (Appendix 17) the filter container comprises an input filter container and an output validator container, the machine-readable instructions being executed by the processor to execute the input filter container to operate an input filter and to execute the output validator container to operate an output validator, the data filter comprising the input filter and the output validator; the input filter is programmed to, in response to determining that the data content of the data in the first data packet does not violate the first set of data rules, provide the first data packet to the output validator; 17. The system of claim 16, wherein the output validator is programmed to provide the first data packet to the second network interface application in response to determining that the data content of the data in the first data packet does not violate the first set of data rules. (Appendix 18) the input filter container is a first input filter container, the output validator container is a first output validator container, the filter container is a first filter container, the output validator container is a first output validator container, the filter container further comprises a second filter container and a second output validator container, the machine-readable instructions are executed by the processor to execute a second input filter container to operate a second input filter, execute the second output validator container to operate a second output validator, the data filter comprises the second input filter and the second output validator; the second input filter is programmed to provide the second data packet to the second output validator in response to determining that the data content of the data in the second data packet does not violate the second set of data rules; 18. The system of claim 17, wherein the output validator is programmed to provide the second data packet to the first network interface application in response to determining that the data content of the data in the second data packet does not violate the second set of data rules. (Appendix 19) 1. A computer-implemented method comprising: Running a first network interface container on a cross-domain interface (CDI) server to run a first network interface application. the first network interface application is programmed to receive from a first network a data packet generated in a first security domain, the data packet including data generated by a first process executing in the first security domain, the method comprising: Execute a filter container on the CDI server to operate the data filter. the data filter is programmed to query a content data rule database located external to the filter container on the CDI server to obtain a set of data rules and determine whether data content of the data of the data packet is compromised based on the set of data rules, the method comprising: Executing a second network interface container on the CDI server to run a second network interface application. wherein the second network interface application is programmed to provide the data packets to the second security domain over a second network for a second process running in the second security domain. (Appendix 20) 20. The computer-implemented method of claim 19, further comprising storing the set of data rules in the content data rules database, the set of data rules being generated based on user input data.
Claims
1. 1. A computer-implemented method comprising: Receiving a data packet generated in a first security domain at a first network interface application. a first network interface container is executed to operate the first network interface application, and the data packet includes data generated by a first process executing in the first security domain, the method comprising: evaluating, in the first network interface application, the data packet against a set of network rules for a network to determine whether the data packet violates at least one network rule of the set of network rules; in response to determining that the data packet does not violate the set of network rules, providing the data packet to a data filter at the first network interface application; evaluating, in the data filter, a data content of the data to determine whether the data has been compromised; a filter container is executed to operate the data filter, the method comprising: providing, at the data filter, the data packet to a second network interface application in response to determining that the data has not been compromised. a second network interface container is executed to operate the second network interface application, the method comprising: providing the data packet to a second security domain for a second process executing in the second network interface application. A computer-implemented method comprising:
2. the set of network rules is a first set of network rules, the network is a first network, and the method comprises: evaluating, in the second network interface application, the data packet against a second set of network rules for a second network to determine whether the data packet violates at least one network rule in the second set of network rules; in response to determining that the data packet does not violate the second set of network rules, providing the data packet to the second security domain for the second process executing in the second security domain at the second network interface application. The computer-implemented method of claim 1 , further comprising:
3. 3. The computer-implemented method of claim 2, wherein the data filter is configured to evaluate the data content of the data against a set of data rules to determine whether the data has been compromised.
4. Executing coded instructions at a cross-domain interface (CDI) server representing a cross-domain router for communicating data packets between the first security domain and the second security domain.
4. The computer-implemented method of claim 3, further comprising: wherein the cross-domain router comprises the first and second network interface containers and the filter container.
5. The computer-implemented method of claim 4 , wherein the first and second network interface containers and the filter container combine to comprise a pod.
6. 5. The computer-implemented method of claim 4, wherein the CDI server comprises a memory for storing the coded instructions representing the cross-domain router, the method further comprising storing in the memory a content data rule database comprising the set of data rules for determining whether the data of the data packet is compromised, the content data rule database being located outside the filter container.
7. 7. The computer-implemented method of claim 6, further comprising: in the data filter, querying the content data rules database to obtain the set of data rules for determining whether the data of the data packet has been compromised.
8. The data packet is a first data packet, and the method includes: receiving, in the content data rules database, an updated set of data rules based on user input; querying the content data rules database in the data filter to obtain the updated set of data rules for determining whether data of a second data packet generated in the first security domain has been compromised; evaluating, in the data filter, a data content of the data in the second data packet to determine whether the data in the second data packet has been compromised; in response to determining that the data in the second data packet is not compromised, providing, at the data filter, the second data packet to the second network interface application; providing the second data packet to the second security domain at the second network interface application; The computer-implemented method of claim 7 further comprising:
9. 1. A system comprising: a memory storing machine-readable instructions representing a cross-domain router for communicating data packets between a first security domain and a second security domain, and data including a content data rule database including a set of data rules for determining whether data of one or more data packets has been compromised; one or more processors that access the memory and execute the machine-readable instructions to execute a first network interface container to operate a first network interface application, a second network interface container to operate a second network interface application, and a filter container to operate a data filter; Equipped with the first network interface application is programmed to receive a data packet generated in the first security domain, the data packet including data generated by a first process executing in the first security domain; The first network interface application comprises: evaluating the data packet against a set of network rules for a network to determine whether the data packet violates at least one network rule of the set of network rules; In response to determining that the data packet does not violate the set of network rules, providing the data packet to the data filter. It is programmed to the data filter is programmed to query the content data rules database to obtain the set of data rules, and in response to determining that data content of the data does not violate the set of data rules, provide the data packet to the second network interface application; The second network interface application is programmed to provide the data packets to the second security domain for a second process executing in the second security domain.
10. 10. The system of claim 9, wherein the set of network rules is a first set of network rules, the network is a first network, the second network interface container includes a second set of network rules for a second network, the second network interface application is programmed to evaluate the data packet against the second set of network rules to determine whether the data packet violates at least one network rule of the second set of network rules, and the second network interface application is programmed to provide the data packet to the second security domain for a second process executing in the second security domain in response to determining that the data packet does not violate the second set of network rules.
11. The data packet is a first data packet, and the second network interface application receiving a second data packet generated in the second security domain, the second data packet may include data generated by the second process executing in the second security domain; The second network interface application comprises: evaluating the second data packet against the second set of network rules to determine whether the second data packet violates at least one network rule of the second set of network rules; In response to determining that the second data packet does not violate the second set of network rules, providing the second data packet to the data filter. The system of claim 10, programmed to:
12. 12. The system of claim 11, wherein the set of data rules is a first set of data rules, and the content data rules database includes a second set of data rules for determining whether data of the second data packet generated by the second process is compromised.
13. The data filter includes: Querying the content data rules database to obtain the second set of data rules; providing the second data packet to the first network interface application in response to determining that data content of the data in the second data packet does not violate the second set of data rules. The system of claim 12, programmed to:
Citation Information
Patent Citations
Illegal access monitoring program, device and method
JP2005352673A
Information processor and control method
JP2014021929A
Multiple virtual network interface support for virtual execution elements
US20200073692A1