Product / 產品評估
單一 1U 雙節點的硬體單向邊界
Falcon-1000 將 Blue Node 與 Red Node 收納於同一設備,讓技術評估從安全域、實體方向與目的端資料可用性開始。
- Product
- Falcon-1000
- Form
- 單一 1U appliance
- Nodes
- Blue Node + Red Node
- Direction
- Blue → Red only
Product composition / 一個產品
一個產品,兩個獨立節點
Falcon-10001U dual-node appliance
Source-facing compute node
Blue Node
連接 Blue SideOne-way fiber
Destination-facing compute node
Red Node
連接 Red SideArchitecture / 產品拓撲
安全域在外,兩個節點在同一設備內
Blue Side / Protected
來源安全域
- OT、控制與受保護網路
- 設備狀態、事件與檔案
- 位於 appliance 外部
Source endpoint
Blue Node
採集與送出Blue-to-Red 單向光纖資料傳輸
Destination endpoint
Red Node
接收與重建Red Side / Destination
目的安全域
- IT、DMZ、SOC
- MES、SIEM、分析環境
- 位於 appliance 外部
Boundary evidence / 分開檢查
三項邊界證據
Physical direction
沒有 Red-to-Blue 反向物理通道跨域光纖只提供 Blue-to-Red 的資料方向。Network reachability
沒有跨域 routed return pathRed Side 不具備跨過硬體邊界回連 Blue Side 的路由。Destination utility
Red Side 仍可使用重建後的資料介面Red Node 接收資料,並建立目的系統可使用的表示。
Data path / Evaluation sequence
來源採集、單向傳輸與目的端重建
- 01 / Collect
Blue Node source collection
Blue Node 從 Blue Side 採集已定義的來源資料,並將資料映射為可跨越單向邊界的表示。
- 02 / Transfer
單向光纖資料傳輸
硬體路徑只允許 Blue-to-Red,不提供 Red-to-Blue 的反向物理資料通道。
- 03 / Reconstruct
Red Node destination reconstruction
Red Node 接收資料,並建立目的系統可使用的資料介面或資料表示。
Integration boundaryRed Side 使用的是重建後的目的端資料介面,不是原始雙向 session 的延伸。
Control boundary / Comparison
硬體單向邊界與防火牆規則的控制差異
| 評估面向 | 硬體單向邊界 | 防火牆規則 |
|---|---|---|
| 方向控制 | 跨域資料方向由實體單向路徑約束。 | 依網路策略定義允許的流量。 |
| 反向資料路徑 | 硬體邊界不提供 Red-to-Blue 反向物理資料通道。 | 可達性與允許方向由部署的網路與規則共同決定。 |
| 控制角色 | 限定跨域資料的物理方向。 | 在各安全域及網路邊界執行流量與存取政策。 |
本表只比較控制邊界差異,不評斷控制強弱,也不以硬體單向邊界取代分層防禦。防火牆與其他安全控制仍有各自的防護角色。
Documentation state / Preparing
產品資料表狀態
STATUS / PREPARING
產品資料表準備中;如需目前可公開的產品規格,請預約技術簡報。
技術簡報將依來源資料、所需資料介面、目的系統與部署條件整理可公開資訊。