GB/T 25068.4-2022Information technology - Security techniques - Network security - Part 4: Securing communications between networks using security gateways (English PDF)
Also coversGBT25068.4-2022
Open the GB/T 25068.4-2022 preview as PDF
This is a limited preview
Buy now to download the full PDF
Issued by
State Administration for Market Regulation, China National Standardization Administration
Level / Type
National · Recommended
Issue date
October 14, 2022
Implementation date
May 1, 2023
Scope
GB/T 25068.4-2022 (Information technology - Security techniques - Network security - Part 4: Securing communications between networks using security gateways) is available as an English-translated PDF.
GB/T 25068.4-2022 — This document provides guidelines for the security protection of communication between networks using security gateways (firewalls, application firewalls, intrusion prevention systems, etc.). South, these security gateways communicate in accordance with documented information security policies, guidelines including. a) identify and analyze cybersecurity threats associated with the security gateway; b) Define the network security requirements of the security gateway based on the threat analysis; c) use techniques designed and implemented to address threats and controls associated with typical cyber scenarios; d) Identify issues related to implementing, operating, monitoring, and reviewing cybersecurity gateway controls.
Document preview — GB/T 25068.4-2022
National Standard of the People's Republic of China
- ICS
- 35.030
- Classification
- L 80
- Replacing
- GB/T 25068.3-2010
Issued by: State Administration for Market Regulation, China National Standardization Administration
Contents
- foreword
- Introduction
- 1 Scope
- 2 Normative references
- 3 Terms and Definitions
foreword
This document is in accordance with the provisions of GB/T 1.1-2020 "Guidelines for Standardization Work Part 1.Structure and Drafting Rules of Standardization Documents"
drafted.
This document is part 4 of GB/T 25068 "Information Technology Security Technology Network Security". GB/T 25068 has been published with
the next part.
--- Part 1.Overview and concepts;
--- Part 2.Guidelines for network security design and implementation;
--- Part 3.Threats, design techniques and controls for network access scenarios;
--- Part 4.Security protection of inter-network communication using security gateways;
--- Part 5.Cross-network communication security protection using virtual private network.
This document replaces GB/T 25068.3-2010 "Information Technology Security Technology IT Network Security Part 3.Using Security Gateways"
Internet Communication Security Protection. Compared with GB/T 25068.3-2010, except for structural adjustment and editorial changes, the main technical changes
as follows.
a) Changed the recommended terms and expressions used when stating "scope" (see Chapter 1, Chapter 1 of the.2010 edition);
b) Changed the content of "Terms and Definitions" (see Chapter 3, Chapter 3 of the.2010 edition);
c) Deleted abbreviations such as "IT", "IDP", "V.35", and added abbreviations such as "ACL", "ASIC", "CPU", "DDoS" and "URL"
(See Chapter 4, Chapter 4 of the.2010 edition);
d) Added three chapters "Document Structure", "Overview" and "Security Threats" (see Chapters 5 to 7);
e) Changed "Security Requirements" to "Security Requirements", added "Table 1", and incorporated the relevant contents of the.2010 edition after changes (see Section 1.1).
Chapter 8, Chapter 5 of the.2010 edition);
f) Changed "Security Gateway Technology" to "Security Control" (see Chapter 9, Chapter 6 of the.2010 edition), and added the element "General" (see Chapter 6 of the.2010 edition)
9.1), "Intrusion Prevention System and Intrusion Detection System" (see 9.6), "Security Management API" (see 9.7), deleted the element "Network location".
Address Translation (NAT)" (see 6.4 of the.2010 edition);
g) Deleted the comparison of the advantages and disadvantages of "Stateful Packet Inspection Firewall" and "Application Proxy Firewall", and changed the relevant content of the.2010 edition to
Incorporated after modification (see 9.3, 6.2 of the.2010 edition);
h) Changed "Application Proxy" to "Application Firewall", and incorporated the relevant content of the.2010 version after the modification (see 9.4,.2010 version
6.3);
i) Changed "Content Analysis and Filtering" to "Content Filtering", added "Content Analysis" column item "Protocol Analysis", and changed the.2010 version
The relevant content is changed and incorporated (see 9.5, 6.5 of the.2010 edition);
j) The chapters "Security Gateway Components" and "Security Gateway Architecture" were merged into the "Design Techniques" chapter, and the dangling segment guidance was deleted
Words, redrawn the schematic diagram (see Figure 3 to Figure 6, Figure 1 to Figure 4 of the.2010 edition), and changed the relevant content of the.2010 edition
later included (see Chapter 10, Chapters 7 and 8 of the.2010 edition);
k) Added the usage rule of "There may be a load balancing switch" (see 10.1.1, 7.1 of the.2010 edition);
l) Changed "application-level gateway" to "application-level gateway", added the usage rules of "SIP gateway", and changed the relevant rules of the.2010 edition
Incorporated after content changes (see 10.1.3, 7.3 of the.2010 edition);
m) Added the usage rules of "monitoring function" (see 10.1.5);
n) Changed "Security Gateway Architecture" to "Deploying Security Gateway Controls", removed the overhang section (see 10.2,.2010 edition of
8.1);
o) Deleted the element "Hierarchical approach" (see 8.2 of the.2010 edition);
p) deleted the paragraph describing the advantages and disadvantages of "shielded host architecture" (see 8.1.3 of the.2010 edition);
q) Added the usage rules of "Packet Filtering Firewall" (see 10.2.1);
r) Added the element "General" (see 11.1);
s) Changed "Security Features and Settings" to "Security Features Settings", added "Support for packaged enterprise or other business applications"
Proxy Services" and "Support for identifying applications running in protocol streams (such as office productivity applications, embedded video, instant messaging, etc.)"
The recommended clauses of the.2010 edition will be incorporated into the revised version (see 11.5, 9.4 of the.2010 edition);
t) Added "fine-grained access rights" (see 11.6, 9.6 of the.2010 edition);
u) deleted the element "documentation" (see 9.7 of the.2010 edition);
v) elements "implementation type" and elements "high availability and operation mode" were added (see 11.10, 11.11).
This document is equivalent to ISO /IEC 27033-4.2014 "Information Technology Security Technology Cybersecurity Part 4.Security of Use"
Internet Communication Security Protection of Gateways.
The following minimal editorial changes have been made to this document.
--- Replaced ISO /IEC 27035 (see 9.1) with GB/T 20985.2-2020 cited for information;
--- Replaced ISO /IEC 27039 (see 9.5) with GB/T 28454-2020 cited for information;
Please note that some content of this document may be patented. The issuing agency of this document assumes no responsibility for identifying patents.
Introduction
The purpose of GB/T 25068 is to provide detailed guidance on the security aspects of the management, operation, use and interconnection of information system networks.
To facilitate the adoption of this document by those responsible for information security, especially cybersecurity, within the organization to meet their specific needs. to consist of six parts
constitute.
--- Part 1.Overview and concepts. The purpose is to define and describe concepts related to cybersecurity and to provide management guidance.
--- Part 2.Network security design and implementation guidelines. The purpose is to help organizations plan, design, and implement high-quality cybersecurity
system to ensure that network security is suitable for the appropriate business environment to provide guidance.
--- Part 3.Threats, design techniques and controls for network access scenarios. The purpose is to enumerate typical network access scenarios
The specific risks, design techniques, and controls related to cybersecurity are applicable to all those involved in the planning, design, and implementation of cybersecurity architecture.
--- Part 4.Security protection of inter-network communication using security gateways. The purpose is to secure Internet-to-network communications using a secure gateway.
It provides information on how to identify and analyze network security threats related to security gateways, and define a network security gateway based on threat analysis.
Network security requirements, introduces network technology security architecture design techniques to address threats and controls associated with typical network scenarios
Guidelines for technical implementation and addressing issues related to the use of secure gateways to implement, operate, monitor, and review network security controls. This article
This software applies to all those involved in the detailed planning, design and implementation of security gateways (e.g. network architects and designers, network
administrators and cybersecurity executives).
--- Part 5.Cross-network communication security protection using virtual private network. The purpose is to define the use of virtual private networks to establish secure connections
The specific risks, design techniques and control elements that are involved.
--- Part 6.Wireless network access security. The purpose is to provide for the selection, implementation and monitoring of the use of wireless networks necessary to provide secure communications
The technical controls of the
Check and select.
GB/T 25068 is based on GB/T 22081 "Information Technology Security Technology Information Security Control Practice Guidelines", and further
Detailed implementation guidance on network security controls is provided. GB/T 25068 only emphasizes the importance of business types and other factors affecting network security
rather than specify.
Where this document involves the use of cryptographic technology to solve the requirements of confidentiality, integrity, authenticity, and non-repudiation, the relevant national standards for cryptography shall be followed.
and industry standards.
information technology security technology cyber security
Part 4.Internetwork using secure gateways
Communication security protection
1 Scope
This document provides guidelines for the security protection of communication between networks using security gateways (firewalls, application firewalls, intrusion prevention systems, etc.).
South, these security gateways communicate in accordance with documented information security policies, guidelines including.
a) identify and analyze cybersecurity threats associated with the security gateway;
b) Define the network security requirements of the security gateway based on the threat analysis;
c) use techniques designed and implemented to address threats and controls associated with typical cyber scenarios;
d) Identify issues related to implementing, operating, monitoring, and reviewing cybersecurity gateway controls.
2 Normative references
The contents of the following documents constitute essential provisions of this document through normative references in the text. Among them, dated citations
documents, only the version corresponding to that date applies to this document; for undated references, the latest edition (including all amendments) applies to
this document.
ISO /IEC 27033-1 Information technology security technology Cybersecurity Part 1.Overview and concepts (Informationtech-
Note. GB/T 25068.1-2020 Information Technology Security Technology Network Security Part 1.Overview and Concepts (ISO /IEC 27033-1.2015,
IDT)
3 Terms and Definitions
ISO /IEC 27033-1 and the following terms and definitions apply to this document.
3.1
bastionhost
Used to intercept packets in and out of the network, specific hosts with hardened operating systems, and any outsiders accessing services within the organization's firewall
When connecting to the host system, the host system should be connected.
3.2
end-pointsoftware-basedfirewal
A software application that protects network traffic to and from a single machine by allowing or denying communications based on end-user-defined security policies.
3.3
A specially configured or designed operating system to minimize the possibility of potentially unwanted content or attacks.
Note. It may be a general-purpose operating system, such as a Linux system specially configured for the environment, or a solution with a higher degree of customization.
3.4
Internet gateway
Port device to access the Internet.
......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — all pages — is available in the English PDF.
Referenced standards
Normative references
IEC 27033 · GB/T 25068.1-2020
How to Buy GB/T 25068.4-2022
- 1Add to cart. Click the "Buy GB/T 25068.4-2022" button on this page. You can add more standards before checkout.
- 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
- 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
- 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.
Related Standards
GB/T 25068.3-2022 — Information technology - Security techniques - Network security - Part 3: Threats, design techniques and control for network access scenarios
GB/T 46830.2-2026 — Plastics - Liquid crystal polymer (LCP) moulding and extrusion materials - Part 2: Preparation of test specimens and determination of properties
GB/T 28593-2026 — Sand and dust weather warning levels
Secure payment via Stripe
Payments accepted
GB/T 25068.4-2022
$305.00