{"product_id":10090,"v_id":10090,"product_name":"HP Network Node Manager Advanced Edition Software v7.51 with patch PHSS_35278","certification_status":"Not Certified","certification_date":"2007-01-26T00:01:00Z","tech_type":"Network Management","vendor_id":{"name":"Hewlett-Packard Company","website":"www.hp.com"},"vendor_poc":"Harry Lynch, HP NNM R&D Architect","vendor_phone":"970.898.2126","vendor_email":"harry.lynch@hp.com","assigned_lab":{"cctl_name":"CygnaCom Solutions, Inc"},"product_description":"<p>HP Network Node Manager Advanced Edition Software v7.51 with patch PHSS_35278. &nbsp;Network Node Manager (NNM) is a network management system.&nbsp; NNM collects system data from across the targeted network, stores it in a database, and management capabilities. In addition, NNM includes an auto-baseline capability to automatically set alarm thresholds for collected data based on deviations from historical data. If these thresholds are exceeded, then NNM will generate an alarm. NNM is designed to help system administrators detect, solve, and prevent problems occurring in their targeted networks.</p>","evaluation_configuration":null,"security_evaluation_summary":"<p>Hewlett-Packard Network Node Manager Advanced Edition Software v7.51 with patch PHSS_35278 was evaluated against the <em>Common Criteria for Information Technology Security Evaluation</em>, Version 2.2, by the CygnaCom Solutions Common Criteria Testing Laboratory (CCTL). The evaluation methodology used was the <em>Common Methodology for Information Technology Security Evaluation, </em>Version 2.2. The CCTL concluded that the TOE was <em>Common Criteria</em> Part 2 extended and Part 3 conformant, and recommended that an EAL2 certificate be issued. The validation was conducted by NIAP&lsquo;s Common Criteria Evaluation and Validation Scheme (CCEVS). The evaluation was completed in January, 2007.</p>","environmental_strengths":"<p>The TOE does provide the following security features:</p>\r\n<ul>\r\n    <li><strong>Security Audit</strong> &mdash; HP NNM provides its own auditing capabilities separate from those of the Operating System. NNM supplies a command line interface (CLI) view the audit trail.<br />\r\n    <br />\r\n    </li>\r\n    <li><strong>Access Control </strong>- HP NNM provides its own access control (authorization) separate from the Operating System for the user login attempts into the Dynamic Views GUI. This is covered by the HP NNM Access Control SFP. Access control is based on username, password, role, and session initiation (local or remote of NNM server).<br />\r\n    <br />\r\n    </li>\r\n    <li><strong>User Identification and Authentication</strong> &mdash; HP NNM provides user identification and authentication for the use of Dynamic Views GUI through the use of user accounts and the enforcement of its password policy.\r\n    <p>As an additional strength to the password policy, HP NNM implements an authentication failure handling mechanism which disables the specific user account after having 5 successive authentication failure attempts. This feature combined with the password policy has met an SOF metric of resistance of greater than 1 month to password guessing attacks applies for this authentication mechanism.</p>\r\n    </li>\r\n    <li><strong>Security Management</strong> &mdash; HP NNM provides security management through the use of the Dynamic Views GUI and CLIs. The NNM administrator must also have <em>root </em>privilege to the OS. HP NNM relies on the underling OS to enforce the operating system&lsquo;s access control policy to control execution of the OVO CLIs to the Unix user <em>root</em>. CLIs are the main capability of administration.\r\n    <p>Through the enforcement of the HP NNM Access Control SFP, the ability to manage the extended topology configuration is restricted to the NNM Administrator who has initiated the Dynamic Views session from the physical server (local). All users have the ability to change their own password via Dynamic Views GUI. </p>\r\n    </li>\r\n    <li><strong>Data Collection, Analysis, and Alarm Notification</strong> &mdash; The NNM Server collects, analyzes, and reacts with an alarm, on data collected from targeted network devices. NNM polls for the status of targeted network devices, network topology changes, and configuration changes. Several protocols are used to maintain communication channels with each managed device on the targeted network (SNMPv1, SNMPv2, TCP/IP, HTTP/HTTPS, UDP, ICMP, &amp; ARP/RARP were used during testing).\r\n    <p>NNM actively sends notification (alarms) when an important event occurs such as threshold limits reached or exceeded or an operational pattern change of a node or network are discovered through the analysis process. The alarms are then displayed in the Dynamic Views GUI Alarm Browser.</p>\r\n    </li>\r\n    <li><strong>Partial Protection of the TSF</strong> &mdash; Working in concert with its platform, the TOE provides protection of its security functions through non-bypassability and domain separation. All user operations are conducted in the context of an associated session. The TOE manages these sessions to prevent one session from compromising another session. The TOE provides only well-defined interfaces to these sessions, and the sessions allocated only after successful authentication, or when a session is requested from the physically protected local console which is under procedural control. The TOE relies on its platform to operate correctly and to prevent unauthorized access to TOE data, stored executables, and management activities.<br />\r\n    <br />\r\n    </li>\r\n    <li><strong>Partial Protected Data Transmission</strong> &mdash; The TSF permits the local users and remote users to initiate communication via the trusted path for initial user authentication and all communication between Dynamic Views GUI and the NNM Server. The TSF relies on the IT environment to provide protection of the trusted path from modification or disclosure using SSL*.\r\n    <p>*Note: There has been no independent verification by the evaluators that the implementation of the cryptographic algorithm SSL actually meets claimed standards. What testing verified was the services provided by SSL correctly worked with the TOE.</p>\r\n    </li>\r\n</ul>\r\n<!-- InstanceEndEditable -->","features":[]}