Assurance Continuity - McAfee Host Intrusion Prevention Version 7.00 McAfee ePolicy Orchestrator Version 3.6.1 Patch 1

Date of Maintenance Completion: 21 July 2008

Product Type: IDS/IPS

Conformance Claim: EAL3

PP Identifier: Intrusion Detection System System Protection Profile, Version 1.6, dated April 4, 2006 (Archived)

Original Evaluated TOE: 17 May 2007 - McAfee HIP 6.0.2 and ePolicy Orchestrator 3.6.1 patch 1

Please note: These are for the Original Evaluated TOE; consequently, they do not refer to this maintained version, although they apply to the maintained version.

Please note: This serves as an addendum to the VR for the Original Evaluated TOE

Readers are reminded that the certification of this product (TOE) is the result of maintenance, rather than an actual re-evaluation of the product. Maintenance only considers the affect of TOE changes on the assurance baseline (i.e. the original evaluated TOE); maintenance is not intended to provide assurance in regard to the resistance of the TOE to new vulnerabilities or attack methods discovered since the date of the initial certificate. Such assurance can only be gained through re-evaluation.

Using a security impact analysis of the changes made to the TOE, which was provided by the developer, the CCEVS has determined that the impact of changes on the TOE are considered minor and that independent evaluator analysis was not necessary. A summary of the results can be found in the Maintenance Report, which is written in relation to the product's original validation report and Security Target. Readers are therefore reminded to read the Security Target, Validation Report, and the Assurance Maintenance Report to fully understand the meaning of what a maintained certificate represents.

PRODUCT DESCRIPTION

HIP 7.0 is a host-based intrusion prevention system designed to protect system resources and applications. It works to intercept system calls prior to their execution and network traffic prior to their processing. If the HIP Agent determines that a call or packet is symptomatic of malicious code, the call or packet can be blocked and/or an audit log created; if it determines that a call or packet is safe, it is allowed.

Vendor Information

logo
McAfee
Howard Moses
503.466.4432
503.466.9671 (Fax)
howard moses@mcafee.com

http://www.mcafee.com