A CDS should maintain separation between sessions, so that an attack on one session cannot influence or access another session, running within the system. Where appropriate, such as in higher threat environments, isolation between input and output flows of data within the components should also be implemented.
Defensive techniques
Software components which interpret complex data types should be logically or physically separate. In this context, “separate“ means that a component which processes one complex type should not process another complex type, and should not use shared resources (e.g. memory), or process more than one data object concurrently. The degree of separation will depend on the threats the component has to be resilient against.
Software components (common or shared) and memory space, which are used in the processing of complex data, should be reset to a known good state prior to processing new complex data (for example, the component which processes an Office document should be reset after each document).
Separate paths for different types of data should be considered, including the use of physical separation.