FIELD: information security.
SUBSTANCE: invention relates to the field of information security. The effect is achieved by setting the gateway state to secure, indicating for the recipient agent to allow access to trusted memory, as well as to deny access to the second network and to prohibit access to untrusted memory, in the secure state of the gateway, configure the recipient agent based on the parameters the recipient agent stored in trusted memory, while the recipient agent is designed to transfer data received from the source agent to the second network, and the source agent is designed to receive the mentioned data from devices from the first network, change the gateway state to working, indicating for the recipient agent to deny access to trusted memory and to allow access to the second network and to untrusted memory, as well as to allow data transfer from the source agent to the recipient agent and to prohibit data transfer from the recipient agent to the source agent, in working condition gateways transfer data from the first network to the second network through the source agent to the recipient agent under the control of the security monitor, taking into account the results of the configuration of the recipient agent, while the recipient agent uses untrusted memory to carry out the said data transfer.
EFFECT: increasing the level of protection of the trusted memory of the network gateway from computer network attacks.
24 cl, 8 dwg
Title | Year | Author | Number |
---|---|---|---|
DATA ACCESS CONTROL SYSTEM AND METHOD | 2021 |
|
RU2790338C1 |
SYSTEM AND METHODS FOR VERIFYING THE INTEGRITY OF SOFTWARE INSTALL IMAGE | 2021 |
|
RU2775157C1 |
SYSTEM AND METHOD OF CONTROLLING ACCESS TO APPLICATION DATA FOR ISOLATING DATA OF ONE APPLICATION FROM DATA OF ANOTHER APPLICATION | 2023 |
|
RU2816864C1 |
SYSTEM AND METHOD FOR FORMING A SECURITY MONITOR | 2021 |
|
RU2773108C1 |
SYSTEM AND METHOD FOR CONTROLLING THE DELIVERY OF MESSAGES TRANSMITTED BETWEEN PROCESSES FROM DIFFERENT OPERATING SYSTEMS | 2021 |
|
RU2777302C1 |
SYSTEM AND METHOD OF OPENING FILES CREATED BY VULNERABLE APPLICATIONS | 2015 |
|
RU2606883C2 |
SYSTEM AND METHOD OF GATEWAY CONFIGURATION FOR AUTOMATED SYSTEMS PROTECTION | 2019 |
|
RU2746105C2 |
SYSTEM AND METHOD OF PROTECTING AUTOMATED SYSTEMS USING GATEWAY | 2019 |
|
RU2724796C1 |
POLICY-CONTROLLED DELEGATION OF ACCOUNT DATA FOR SINGLE REGISTRATION IN NETWORK AND SECURED ACCESS TO NETWORK RESOURCES | 2007 |
|
RU2439692C2 |
METHOD FOR CONFIGURATION OF IoT APPARATUSES DEPENDING ON THE TYPE OF NETWORK | 2021 |
|
RU2760625C1 |
Authors
Dates
2022-04-18—Published
2021-10-14—Filed