A network security system is provided comprising a plurality of network
bubbles wherein each bubble includes bubble members configured to
transmit and receive data. Bubbles have network security policies that
may be enforced by a plurality of network control point devices. The
system further includes a private virtual backbone configured to
interconnect the plurality of network control points connected to known
bubbles. The privacy of the private virtual backbone is maintained by an
inter-bubble device and/or set of two network control points. The
inter-bubble device and set of control points enforce the network
security policies of any connected bubble and relay data packets between
address spaces. The private virtual backbone may operate in private
address space. The system also includes an instance-specific virtual
backbone that interconnects only bubble partitions from the same network
bubble, thus simplifying the enforcement of a network security policy.