{"product_id":10083,"v_id":10083,"product_name":"Radware APSolute OS Version 1.0, Models WSD v8.21.04, DP v1.32.11","certification_status":"Not Certified","certification_date":"2006-02-03T00:02:00Z","tech_type":"Miscellaneous","vendor_id":{"name":"Radware Ltd.","website":"http://www.radware.com"},"vendor_poc":"Eran Havousha","vendor_phone":null,"vendor_email":"eranh@radware.com","assigned_lab":{"cctl_name":"CygnaCom Solutions, Inc"},"product_description":"<p>Radware provides Intelligent Application Switching (IAS) products that provide high-speed hardware switching with software security services across layers 3-7.&nbsp; SynApps is a software module included in Radware IAS appliances that provides the following security functions:</p>\r\n<ul>\r\n    <li>Auditing of certain network attacks specified by the Administrator through setting of filters, filter groups, and attack definitions </li>\r\n    <li>Enforcement of policies that define specific actions to be taken in the event of a defined network attack </li>\r\n</ul>\r\n<p>The SynApps software module is identical in all Radware products.<br />\r\nThe CLI provides Security Management of security attributes and data. The SynApps software module and the CLI together constitute the TOE. The Policy definition file is the interface of the CLI and the SynApps module, and is also included in the TOE. The Radware appliance and operating system, which is in the IT environment, provides additional functionality that allows administrators to be identified and authenticated, provides tools for configuring the TOE and provides reliable time stamps in support of the TOE.&nbsp; IAS products produced by Radware that were included in the evaluation are as follows:</p>\r\n<ul>\r\n    <li>DefensePro </li>\r\n    <li>Web Server Director </li>\r\n</ul>","evaluation_configuration":"<p>The evaluated configuration includes a management station where the TOE&rsquo;s administrative interface (CLI) is installed. TOE configuration excludes the remote administration authentication functionality, and there is no claim of satisfying a security functional requirement relating to I&amp;A. The only means of Administrator authentication that is compatible with the TOE is through the connected console port. Hence, to authenticate as an administrator, a user must have physical access to the TOE and posses a valid user identifier and authenticator.</p>\r\n<p>The evaluated configuration also includes a web server station and an audit station. For the purposes the Common Criteria evaluation, Web Server Director Application Switch II (version WSD v8.21.04) and DefensePro Application Switch III (version DP v1.32.11) were tested.</p>\r\n<p>The tested configuration did not include any enabled hardware accelerators or high bandwidth fiber connections.</p>","security_evaluation_summary":"The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) processes and procedures. The TOE,&nbsp; Radware APSolute OS Version 1.0 (SynApps module version 3.402151), was evaluated against the criteria contained in the Common Criteria for Information Technology Security Evaluation, Version 2.2. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 2.2. CygnaCom Solutions has determined that the product meets the security criteria in the Security Target, which specifies an assurance level of EAL3. A validator, on behalf of the CCEVS Validation Body, monitored the evaluation.&nbsp; The evaluation was completed in February 2006.","environmental_strengths":"<p>The Radware APSolute OS Version 1.0 TOE consists of the SynApps module and the Command Line Interface (CLI). The SynApps module consists of a single subsystem, which performs audit and policy enforcement.&nbsp; Audit functions include generating alarms, generating audit records for specific events defined by the Administrator, and potential violation analysis.&nbsp; Policy enforcement functions include information flow control and security management.&nbsp; The policy enforcement functions require support from the Radware Appliance Software Application for policy configuration by the administrator. The CLI supports the Administrator in setting filters, filter groups, and policies. </p>\r\n<p>&nbsp;</p>","features":[]}