// THREAT DETECTION AND DATA PRIVACY TERM

Air Gap

An air gap is a security measure that physically isolates a computer or network from any other network, such as the public internet. This lack of a physical or wireless connection is intended to protect the most critical systems from remote cyberattacks.

Air Gap — illustration from Wikipedia
Image via Wikipedia

TECHNICAL DEFINITION

An air gap is a network security control that implements complete physical isolation to separate a secure computer system or network from insecure networks, including the public internet and local area networks (LANs). This defense-in-depth strategy protects critical infrastructure, SCADA/ICS environments, and classified systems by preventing remote access, malware propagation, and data exfiltration vectors that require network connectivity.

BACKGROUND

Pine Gap is a joint Australian–United States satellite communications and signals intelligence surveillance base and Australian Earth station approximately 18 km (11 mi) south-west of the town of Alice Springs. It is jointly operated by Australia and the United States, and since 1988 it has been officially called the Joint Defence Facility Pine Gap (JDFPG); previously, it was known as Joint Defence Space Research Facility. It plays a crucial role in supporting the intelligence activities and military operations of the US around the world.

READ MORE ON WIKIPEDIA

SYNONYMS & ALIASES

  • physical separation
  • network isolation
  • air wall
  • secure gap
  • air-gapped system
  • isolated network

USAGE NOTE

While highly effective, air-gapped systems can still be compromised via removable media like USB drives, insider threats, or sophisticated covert channel attacks.

DEVELOPERS

Organizations developing technology related to Air Gap.

  • Owl Cyber Defense

    A company specializing in data diode and cross-domain solutions designed to create hardware-enforced, one-way data transfer segments between networks, effectively creating and bridging air gaps for critical infrastructure and government agencies.

  • Waterfall Security Solutions

    A leading provider of unidirectional security gateways, a type of data diode, which physically prevent the propagation of attacks from external networks into protected, air-gapped operational technology (OT) and industrial control system (ICS) networks.

  • Forcepoint

    Develops a suite of Cross Domain Solutions (CDS) used extensively by government, intelligence, and defense organizations to securely access and transfer information between networks of different security classifications, effectively managing the air gap.

  • OPSWAT

    Provides solutions like MetaDefender Kiosk and Vault to secure the transfer of data across an air gap. Their technology focuses on sanitizing and controlling data brought in or out of secure environments via removable media (USB, CDs, etc.).

  • General Dynamics Mission Systems

    A major defense contractor that develops trusted Cross-Domain Solutions like TACDS and Trusted Guard, which enable secure and filtered information sharing between air-gapped networks of varying security levels for military and intelligence communities.

  • BAE Systems

    A global defense and aerospace company that produces Cross-Domain Solutions (CDS), including the STOP™ series of data diodes and guards, to ensure secure, one-way information sharing across different security domains, protecting air-gapped networks.

  • L3Harris Technologies

    An aerospace and defense technology company offering robust Cross-Domain Solutions and secure data transfer systems that facilitate filtered data exchange across security boundaries for military and government applications, including air-gapped environments.

  • RTX (Raytheon)

    A multinational defense contractor that engineers and implements multi-level security and cross-domain solutions to protect mission-critical systems and enable secure data exchange between classified and unclassified networks, often involving air gap architectures.

RELATED TERMS IN DEFENSE & ARCHITECTURE