Validated Product - Sanctuary Application Control Custom Edition 2.8Certificate Date: 11 September 2006 Validation Report Number: CCEVS-VR-06-0036 Product Type: IDS/IPS Conformance Claim: EAL2 PP Identifiers: None CC Testing Lab: SAIC Common Criteria Testing Laboratory
PRODUCT DESCRIPTIONThe TOE, SecureWave Sanctuary Application Control Custom Edition version 2.8, is a three-tiered client/server application that provides the capability to centrally control the programs and applications users are able to execute on their client computers. The TOE controls authorization of applications and executable files by maintaining a database of hashes of approved executables and associating the hashes with users or user groups. When a user logs on to a client that is protected by the TOE, the TOE client driver contacts the server and downloads the list of authorized hashes for the user. Whenever the user attempts to execute a file on the client, the TOE client driver intercepts the operating system request, calculates the hash value of the file and searches for a match in the list of authorized hashes. If a match is found, execution of the file proceeds; otherwise, execution is blocked. The three tiers of a Sanctuary Application Control Custom Edition (SACCE) deployment comprise:
An administrative toolkit, comprising a GUI-based application (the Sanctuary Custom Edition Management Console, or SMC) and various command-line tools, also operates in the client tier, and is supported on Windows 2000 Server or Professional, Windows XP Professional, or Windows Server 2003. SECURITY EVALUATION SUMMARYThe evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The criteria against which the SecureWave Sanctuary Application Control Custom Edition version 2.8 TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 2.1 and International Interpretations effective on 22 August 2003. The evaluation methodology used by the Evaluation Team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 1.0. Science Applications International Corporation (SAIC) determined that the evaluation assurance level (EAL) for the product is the EAL2 family of assurance requirements. The product, when configured as specified in “Sanctuary Application Control Custom Edition Setup Guide”, satisfies all of the security functional requirements stated in the SecureWave Sanctuary Application Control Custom Edition Security Target. One validator on behalf of the CCEVS Validation Body monitored the evaluation carried out by SAIC. The evaluation was completed in May 2006. Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report, (report number CCEVS-VR-06-0036) prepared by CCEVS. For this evaluation, it was appropriate for the Security Target to claim compliance with the external standard for RSA and SHA for the definition of the encryption algorithm. There are many ways of determining compliance with a standard. SecureWave Sanctuary Application Control Custom Edition has chosen to make a developer claim of compliance. This means that there has been no independent verification (by either the evaluators or a third party standards body, such as a FIPS laboratory) that the implementation of the cryptographic algorithms actually meets the claimed standards. Potential users of this product should confirm that the cryptographic capabilities are suitable to meet the user's requirements. ENVIRONMENTAL STRENGTHSSecureWave Sanctuary Application Control Custom Edition version 2.8 provides a low to moderate level of independently assured security in a conventional TOE and is suitable for both commercial and government IT environments that require control over the applications and executable files utilized by the users on the computer systems. The primary security functionality of the TOE is to provide a centrally-managed capability for controlling the applications and executable files users in a networked environment are authorized to run. This capability is provided through the combination of the following security functions:
The fundamental rule used within the TOE is to allow only the use and/or execution of known and authorized executables and deny all else. In other words, the TOE does not use a “black list” of what is to be prevented. It only uses a “white list” of what is authorized; everything else is denied by default. The product also authenticates, at every attempt to initiate, that the “authorized” executable is valid. The TOE provides two methods for granting access to authorized executable files. One is based on matching the SXD-generated file hash to the centrally authorized hash assigned to an executable file. The files are associated with file groups and users are assigned to file groups. In addition, the administrator can grant specific users the privilege to locally authorize executable files on their client computer. The second method is the use of Path Rules that grant access to executable files and/or file directories on the client computer based on their location within the directory hierarchy.
Vendor Information
Lumension Security (formerly SecureWave) Dee Liebenstein +1 (703) 713-3960 Dee.Liebenstein@lumension.com |