An alternative to sneakernet
Stanley A. Orrell, S. Ralstin · OSTI OAI (U.S. Department of Energy Office of Scientific and Technical Information) · 1993
Security plans for classified computer systems often specify that only a small percentage of the data processed will be classified. Thus, the bulk of the data on such secure systems is unclassified. This situation requires that some mechanism be provided for moving files to or from the open environment. For many years, this has been accomplished by writing selected files to a magnetic medium, and carrying it to another system where the files are retrieved. These procedures, in many cases, have been developed informally and ad hoc to a specific transfer requirement. This media transport process, referred to as sneakernet, often is manually logged, if at all, and controlled only by administrative procedures. While sneakernets may isolate secure systems from direct attack, other security concerns remain. There has been little guidance available for handling such transfers in a secure manner. Comprehensive criteria for the security evaluation of the procedures used for these transfers have yet to be published. This paper examines the security concerns associated with transfers of unclassified files between security environments and develops a set of criteria which can be used in evaluating the security of any system or procedure for that purpose. Methods for bidirectional unclassified filemore » transfer between secure and open environments could range from completely manual to fully automated. The criteria developed, however, are intended to be generic and to apply to any system for the purpose, existing or proposed.« less