Validated Product - SecureSphere 6Certificate Date: 20 February 2009 Validation Report Number: CCEVS-VR-VID10238-2009 Product Type: IDS/IPS Conformance Claim: EAL2 Augmented with ALC_FLR.1 PP Identifier: Intrusion Detection System System Protection Profile, Version 1.6, dated April 4, 2006 (Archived) CC Testing Lab: SAIC Common Criteria Testing Laboratory
PRODUCT DESCRIPTION
Imperva SecureSphere 6 is an IDS/IPS that monitors network traffic between clients and servers in real-time, analyses that traffic for suspected intrusions, and provides a reaction capability. Reaction options include recording and monitoring suspected traffic and ID events, blocking traffic, and generating alarms containing event notifications. Database auditing allows you to record selected user database queries for audit purposes. Web queries and responses can also be selectively recorded. In addition, monitored databases can be actively scanned to identify potential vulnerabilities. Imperva SecureSphere 6 includes the following gateway and Management Server appliances running the SecureSphere 6 software image: G4, G8, G16, MX, G4 FTL, G8 FTL and MX FTL. SECURITY EVALUATION SUMMARY
The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The criteria against which the Imperva SecureSphere 6 TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 2.3. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 2.3. SAIC determined that the evaluation assurance level (EAL) for the product is the EAL 2 family of assurance requirements augmented with ALC_FLR.1. The product, when configured as specified in the installation guides and user guides, satisfies all of the security functional requirements stated in the Imperva SecureSphere 6 Security Target. A validator on behalf of the CCEVS Validation Body monitored the evaluation carried out by SAIC. The evaluation was completed in February 2009. Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report for Imperva SecureSphere 6 prepared by CCEVS. ENVIRONMENTAL STRENGTHSImperva SecureSphere 6 is a commercial IDS/IPS product that provides: Data Collection, ID Analysis, Actions, Audit, Security Management, and TSF Protection security functions. Vendor Information
IMPERVA, Inc. Amichai Shulman, Nir Naaman 972-3-6840103 972-3-6840200 (Fax) shulman@imperva.com nir.naaman@metasec.com |