Valid

GB/T 25068.4-2022Information technology - Security techniques - Network security - Part 4: Securing communications between networks using security gateways (English PDF)

Also coversGBT25068.4-2022

Open the GB/T 25068.4-2022 preview as PDF

Preview — first pages of GB/T 25068.4-2022

This is a limited preview

Buy now to download the full PDF

Issued by

State Administration for Market Regulation, China National Standardization Administration

Level / Type

National · Recommended

Issue date

October 14, 2022

Implementation date

May 1, 2023

Scope

GB/T 25068.4-2022 (Information technology - Security techniques - Network security - Part 4: Securing communications between networks using security gateways) is available as an English-translated PDF.

GB/T 25068.4-2022 — This document provides guidelines for the security protection of communication between networks using security gateways (firewalls, application firewalls, intrusion prevention systems, etc.). South, these security gateways communicate in accordance with documented information security policies, guidelines including. a) identify and analyze cybersecurity threats associated with the security gateway; b) Define the network security requirements of the security gateway based on the threat analysis; c) use techniques designed and implemented to address threats and controls associated with typical cyber scenarios; d) Identify issues related to implementing, operating, monitoring, and reviewing cybersecurity gateway controls.

Document preview — GB/T 25068.4-2022

National Standard of the People's Republic of China

ICS
35.030
Classification
L 80
Replacing
GB/T 25068.3-2010

Issued by: State Administration for Market Regulation, China National Standardization Administration

Contents

  • foreword
  • Introduction
  • 1 Scope
  • 2 Normative references
  • 3 Terms and Definitions

foreword

This document is in accordance with the provisions of GB/T 1.1-2020 "Guidelines for Standardization Work Part 1.Structure and Drafting Rules of Standardization Documents"

drafted.

This document is part 4 of GB/T 25068 "Information Technology Security Technology Network Security". GB/T 25068 has been published with

the next part.

--- Part 1.Overview and concepts;

--- Part 2.Guidelines for network security design and implementation;

--- Part 3.Threats, design techniques and controls for network access scenarios;

--- Part 4.Security protection of inter-network communication using security gateways;

--- Part 5.Cross-network communication security protection using virtual private network.

This document replaces GB/T 25068.3-2010 "Information Technology Security Technology IT Network Security Part 3.Using Security Gateways"

Internet Communication Security Protection. Compared with GB/T 25068.3-2010, except for structural adjustment and editorial changes, the main technical changes

as follows.

a) Changed the recommended terms and expressions used when stating "scope" (see Chapter 1, Chapter 1 of the.2010 edition);

b) Changed the content of "Terms and Definitions" (see Chapter 3, Chapter 3 of the.2010 edition);

c) Deleted abbreviations such as "IT", "IDP", "V.35", and added abbreviations such as "ACL", "ASIC", "CPU", "DDoS" and "URL"

(See Chapter 4, Chapter 4 of the.2010 edition);

d) Added three chapters "Document Structure", "Overview" and "Security Threats" (see Chapters 5 to 7);

e) Changed "Security Requirements" to "Security Requirements", added "Table 1", and incorporated the relevant contents of the.2010 edition after changes (see Section 1.1).

Chapter 8, Chapter 5 of the.2010 edition);

f) Changed "Security Gateway Technology" to "Security Control" (see Chapter 9, Chapter 6 of the.2010 edition), and added the element "General" (see Chapter 6 of the.2010 edition)

9.1), "Intrusion Prevention System and Intrusion Detection System" (see 9.6), "Security Management API" (see 9.7), deleted the element "Network location".

Address Translation (NAT)" (see 6.4 of the.2010 edition);

g) Deleted the comparison of the advantages and disadvantages of "Stateful Packet Inspection Firewall" and "Application Proxy Firewall", and changed the relevant content of the.2010 edition to

Incorporated after modification (see 9.3, 6.2 of the.2010 edition);

h) Changed "Application Proxy" to "Application Firewall", and incorporated the relevant content of the.2010 version after the modification (see 9.4,.2010 version

6.3);

i) Changed "Content Analysis and Filtering" to "Content Filtering", added "Content Analysis" column item "Protocol Analysis", and changed the.2010 version

The relevant content is changed and incorporated (see 9.5, 6.5 of the.2010 edition);

j) The chapters "Security Gateway Components" and "Security Gateway Architecture" were merged into the "Design Techniques" chapter, and the dangling segment guidance was deleted

Words, redrawn the schematic diagram (see Figure 3 to Figure 6, Figure 1 to Figure 4 of the.2010 edition), and changed the relevant content of the.2010 edition

later included (see Chapter 10, Chapters 7 and 8 of the.2010 edition);

k) Added the usage rule of "There may be a load balancing switch" (see 10.1.1, 7.1 of the.2010 edition);

l) Changed "application-level gateway" to "application-level gateway", added the usage rules of "SIP gateway", and changed the relevant rules of the.2010 edition

Incorporated after content changes (see 10.1.3, 7.3 of the.2010 edition);

m) Added the usage rules of "monitoring function" (see 10.1.5);

n) Changed "Security Gateway Architecture" to "Deploying Security Gateway Controls", removed the overhang section (see 10.2,.2010 edition of

8.1);

o) Deleted the element "Hierarchical approach" (see 8.2 of the.2010 edition);

p) deleted the paragraph describing the advantages and disadvantages of "shielded host architecture" (see 8.1.3 of the.2010 edition);

q) Added the usage rules of "Packet Filtering Firewall" (see 10.2.1);

r) Added the element "General" (see 11.1);

s) Changed "Security Features and Settings" to "Security Features Settings", added "Support for packaged enterprise or other business applications"

Proxy Services" and "Support for identifying applications running in protocol streams (such as office productivity applications, embedded video, instant messaging, etc.)"

The recommended clauses of the.2010 edition will be incorporated into the revised version (see 11.5, 9.4 of the.2010 edition);

t) Added "fine-grained access rights" (see 11.6, 9.6 of the.2010 edition);

u) deleted the element "documentation" (see 9.7 of the.2010 edition);

v) elements "implementation type" and elements "high availability and operation mode" were added (see 11.10, 11.11).

This document is equivalent to ISO /IEC 27033-4.2014 "Information Technology Security Technology Cybersecurity Part 4.Security of Use"

Internet Communication Security Protection of Gateways.

The following minimal editorial changes have been made to this document.

--- Replaced ISO /IEC 27035 (see 9.1) with GB/T 20985.2-2020 cited for information;

--- Replaced ISO /IEC 27039 (see 9.5) with GB/T 28454-2020 cited for information;

Please note that some content of this document may be patented. The issuing agency of this document assumes no responsibility for identifying patents.

Introduction

The purpose of GB/T 25068 is to provide detailed guidance on the security aspects of the management, operation, use and interconnection of information system networks.

To facilitate the adoption of this document by those responsible for information security, especially cybersecurity, within the organization to meet their specific needs. to consist of six parts

constitute.

--- Part 1.Overview and concepts. The purpose is to define and describe concepts related to cybersecurity and to provide management guidance.

--- Part 2.Network security design and implementation guidelines. The purpose is to help organizations plan, design, and implement high-quality cybersecurity

system to ensure that network security is suitable for the appropriate business environment to provide guidance.

--- Part 3.Threats, design techniques and controls for network access scenarios. The purpose is to enumerate typical network access scenarios

The specific risks, design techniques, and controls related to cybersecurity are applicable to all those involved in the planning, design, and implementation of cybersecurity architecture.

--- Part 4.Security protection of inter-network communication using security gateways. The purpose is to secure Internet-to-network communications using a secure gateway.

It provides information on how to identify and analyze network security threats related to security gateways, and define a network security gateway based on threat analysis.

Network security requirements, introduces network technology security architecture design techniques to address threats and controls associated with typical network scenarios

Guidelines for technical implementation and addressing issues related to the use of secure gateways to implement, operate, monitor, and review network security controls. This article

This software applies to all those involved in the detailed planning, design and implementation of security gateways (e.g. network architects and designers, network

administrators and cybersecurity executives).

--- Part 5.Cross-network communication security protection using virtual private network. The purpose is to define the use of virtual private networks to establish secure connections

The specific risks, design techniques and control elements that are involved.

--- Part 6.Wireless network access security. The purpose is to provide for the selection, implementation and monitoring of the use of wireless networks necessary to provide secure communications

The technical controls of the

Check and select.

GB/T 25068 is based on GB/T 22081 "Information Technology Security Technology Information Security Control Practice Guidelines", and further

Detailed implementation guidance on network security controls is provided. GB/T 25068 only emphasizes the importance of business types and other factors affecting network security

rather than specify.

Where this document involves the use of cryptographic technology to solve the requirements of confidentiality, integrity, authenticity, and non-repudiation, the relevant national standards for cryptography shall be followed.

and industry standards.

information technology security technology cyber security

Part 4.Internetwork using secure gateways

Communication security protection

1 Scope

This document provides guidelines for the security protection of communication between networks using security gateways (firewalls, application firewalls, intrusion prevention systems, etc.).

South, these security gateways communicate in accordance with documented information security policies, guidelines including.

a) identify and analyze cybersecurity threats associated with the security gateway;

b) Define the network security requirements of the security gateway based on the threat analysis;

c) use techniques designed and implemented to address threats and controls associated with typical cyber scenarios;

d) Identify issues related to implementing, operating, monitoring, and reviewing cybersecurity gateway controls.

2 Normative references

The contents of the following documents constitute essential provisions of this document through normative references in the text. Among them, dated citations

documents, only the version corresponding to that date applies to this document; for undated references, the latest edition (including all amendments) applies to

this document.

ISO /IEC 27033-1 Information technology security technology Cybersecurity Part 1.Overview and concepts (Informationtech-

Note. GB/T 25068.1-2020 Information Technology Security Technology Network Security Part 1.Overview and Concepts (ISO /IEC 27033-1.2015,

IDT)

3 Terms and Definitions

ISO /IEC 27033-1 and the following terms and definitions apply to this document.

3.1

bastionhost

Used to intercept packets in and out of the network, specific hosts with hardened operating systems, and any outsiders accessing services within the organization's firewall

When connecting to the host system, the host system should be connected.

3.2

end-pointsoftware-basedfirewal

A software application that protects network traffic to and from a single machine by allowing or denying communications based on end-user-defined security policies.

3.3

A specially configured or designed operating system to minimize the possibility of potentially unwanted content or attacks.

Note. It may be a general-purpose operating system, such as a Linux system specially configured for the environment, or a solution with a higher degree of customization.

3.4

Internet gateway

Port device to access the Internet.

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — all pages — is available in the English PDF.

Referenced standards

Normative references

IEC 27033 · GB/T 25068.1-2020

How to Buy GB/T 25068.4-2022

  1. 1Add to cart. Click the "Buy GB/T 25068.4-2022" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB/T 25068.4-2022

$305.00

$260.00for partners