Skip to main content
Guidance

Technology assurance

The NCSC’s Technology Assurance activities provide a means to gain confidence in the cyber security of the services and technologies on which the UK relies.

Page 25 of 35

3. Protect sensitive data in transit

When sending sensitive data across any network it must be protected against eavesdropping and tampering.

Users and product developers need to be confident that whenever sensitive data is in transit, it is protected against eavesdropping and tampering. This is true regardless of the type of connection: it could be a physical (wired) connection across a network, a wireless or Bluetooth connection between devices, or a broadcast radio frequency transmission. The mechanisms used should protect both communications over public (untrusted) networks and within private (trusted) networks.

An adversary who can intercept a communication may seek to gain an advantage in a number of ways.

  • They may want to extract sensitive data directly
  • They may want to modify the communication in order to masquerade as a legitimate user and send malicious messages
  • They may look to replay previously transmitted data to cause a disruptive effect
  • They may seek to prevent data reaching its intended recipient, causing a denial of service

Protective mechanisms aim to defend against these attacker objectives in two main ways:

  1. Preventing an adversary from intercepting data in the first place
  2. Preventing loss of confidentiality or integrity if it is intercepted

Example defensive measures

  • Strong cryptography should be used to establish trusted connections, ensuring sensitive data only goes where it is intended to. This will also provide confidentiality and integrity protection. Standardised algorithms and transport protocols provide the mechanisms to do this effectively, and to detect a range of attacks.
  • Where content is encrypted, encryption should happen at source, and decrypted only at the final destination, not en route. This ensures that an attacker intercepting data in transit cannot learn its content.
  • Cryptographic mechanisms rely on secret values – keys – that should be unpredictable by an adversary. Strong random number generators should be used to generate keys, and there should be appropriate processes for distributing, managing and storing keys in a secure manner, throughout their lifetime.
  • Data in transit is less likely to be at risk from an adversary if it is hard to identify. Use of standardised, widely used protocols can help with this for electronically transmitted data. Unusual regions or patterns of use of the radio frequency spectrum should be avoided for data transmitted over-the-air.
  • Where availability of communications is a critical requirement, you should consider building in redundancy to the system, so that if one connection is unavailable, data can be transmitted through an alternative route.

Published

Reviewed

Version

1.0