Skip to main content
Guidance

Security principles for cross domain solutions

Thirteen things that need to be good to make a secure Cross Domain Solution (CDS).

Page 4 of 15

Content based attack protection

A CDS should provide a strong level of protection against attacks which use malicious content contained, even concealed, in data files, or other data constructs. Such attacks could adversely affect data processing on the receiving network, or the correct operation of the CDS itself.

In designing a CDS capable of defending against content based attacks, you should take into consideration the susceptibilities of the target system to content based attack. For instance, the complexity of the data formats being used.

Your design should take into account the capabilities and likelihood of any attacker performing such an attack. You should employ appropriate mitigations.

The potential for content based attacks on the CDS itself should also be kept in mind. For instance, the parsers that the CDS itself uses to process content should be robustly designed and implemented.


Additional information

For more information on defending against content based attacks, please see the NCSC guidance on Safely Importing Data.

Published

Reviewed

Version

1.0