Writing TeleWall® Security Policy Rules for STU Lines

Article #ETM229B

Synopsis

A Secure Transmission Unit (STU-III) is a secure telecommunications device designed to operate as both an ordinary telephone and a secure instrument over the telephone network. A STU unit is used to protect the transmission of sensitive or classified information.

Because the unit can be used as an ordinary telephone, it is possible for a call to not go into secure mode. You can define TeleWall® Policy Rules to detect whether a call has gone secure and terminate the call if it is not in secure mode.

Versions Affected

Applies to all versions of the ETM® System.

More Information

The table below is an example of STU Rules.

Note: “STU Lines” in the Source and Destination columns is a user-defined Phone Number Group containing telephone numbers that connect to STU-III Units.

STU Policy
No.Call
Direction
SourceDestinationCall
Type
TimeCall
Duration
ActionTrackComments
1AnyAnyAnySTUAny01:00AllowEmailLogNotify of long STU calls
2InboundAnySTU LinesSTUAny00:01TerminateEmailLogTerminate calls that do not go secure
3OutboundSTU LinesAny! STUAny00:01TerminateEmailLogTerminate calls that do not go secure
4AnyAnyAnySTUAnyAnyAllowLogLog all STU calls

The Rules in the example are processed against calls as follows:

Rule 1

The Policy is looking for any calls with call type of STU-III and call duration of 1 hour. Processing pauses at Rule 1 until call type is determined.

  • If the call type is identified as STU-III, processing continues with the next Rule while it waits for the 1-hour duration to be reached. Rule 1 is reprocessed every 15 seconds until the 1-hour duration is reached or the call ends. If the call lasts 1 hour, an email notification is sent, and the call is logged in the TeleWall Policy Log.
  • If the call is not STU-III, or if a STU-III call does not last 1 hour, Rule 1 does not fire. 

Rule 2

The purpose of Rule 2 is to terminate any inbound calls to STU Lines that do not go secure within the first minute (i.e., the call type is identified as anything except STU). Rule 2 is looking for inbound calls from any source with a call type of anything other than STU-III and a call duration of 1 minute.

  • If the call is an inbound call to STU Lines and does not have a call type of STU-III, Rule 2 is skipped while it waits for the 1-minute duration to be reached. After all of the subsequent Rules are processed, Rule 2 is reprocessed every 15 seconds until the 1-minute call duration is reached or the call ends.
  • If the call type is STU-III, this Rule does not fire.

Rule 3

The purpose of Rule 3 is to terminate any outbound calls from STU Lines that do not go secure within the first minute (i.e., the call type is identified as anything except STU). Rule 3 is looking for outbound calls from STU Lines to any destination with a call type of anything other than STU-III and a call duration of 1 minute. (Note that if SMDR is providing outbound source, these calls will not be terminated, because SMDR is not available until after the call ends.)

  • If the call is an outbound call from STU Lines and does not have a call type of STU-III, Rule 3 is skipped while it waits for the 1-minute duration to be reached. After subsequent Rules are processed, Rule 3 is reprocessed every 15 seconds until the 1-minute call duration is reached or the call ends.
  • If the call type is STU-III, this Rule does not fire.

Rule 4

The purpose of Rule 4 is to ensure that STU calls that go secure are allowed to complete.  If the call has a call type of STU and did not trigger any of the previous Rules, the call is allowed and is logged in the TeleWall Policy Log.

For example, when processing inbound STU-III call to STU Lines:

  • Rule 1 specifies call duration of 1 hour. Processing moves to Rule 2.
  • Rule 2 specifies that any inbound call to STU Lines that does not go secure within 1 minute should be terminated. The call is identified as STU; the Rule does not fire.
  • Rule 3 applies to outbound calls; the Rule does not fire.
  • Rule 4 specifies that any STU call that did not trigger previous Rules should be logged and allowed. The Rule fires and the call is logged.
  • Rule 1 is reprocessed every 15 seconds (even if Rules 2, 3, or 4 fire) until the call duration reaches 1 hour or the call ends. If the call reaches a 1-hour duration, Rule 1 fires, triggering an email notification of a long STU call, and the call is logged in the TeleWall Policy Log.

Last Update: 2/26/02

SecureLogix Corporation

13750 San Pedro, Suite 230 • San Antonio, Texas 78232 • (210) 402-9669 • www.securelogix.com

ETM, SecureLogix, SecureLogix Corporation, TeleWatch Secure, TWSA, the ETM Emblem, the SecureLogix Diamond Emblem, and the ETM Application Suite Emblems are trademarks or registered trademarks of SecureLogix Corporation in the U.S.A. and other countries. All other trademarks mentioned herein are believed to be trademarks of their respective owners.

© Copyright 2002 SecureLogix Corporation. All Rights Reserved.
U.S. Patents No. US 6,249,575 B1 and US 6,320,948 B1.
U.S. and Foreign Patents Pending.

This product includes:
Data Encryption Standard Software developed by Eric Young (eay@mincom.oz.au)
© Copyright 1995 Eric Young. All Rights Reserved.
Style Report software owned and licensed exclusively by InetSoft Technology Corp.
© Copyright 1996-2000 InetSoft Technology Corp. All Rights Reserved.

Published on December 3, 2002  |  Updated on August 9, 2021

Related Articles

Need Support?
Can't find the answer you're looking for? Don't worry we're here to help!
CONTACT SUPPORT