{"product_id":10123,"v_id":10123,"product_name":"Tripwire Enterprise Version 5.2","certification_status":"Not Certified","certification_date":"2009-04-03T00:04:00Z","tech_type":"Sensitive Data Protection","vendor_id":{"name":"Tripwire, Inc.","website":"http://www.tripwire.com"},"vendor_poc":"Harold Metzger, Creative Services Manager","vendor_phone":"503.276.7572","vendor_email":"hmetzger@tripwire.com","assigned_lab":{"cctl_name":"Leidos Common Criteria Testing Laboratory"},"product_description":"<p class=\"Body\" style=\"margin: 0in 0in 6pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times;\">The Tripwire Enterprise <span style=\"letter-spacing: -0.45pt; mso-font-width: 102%;\">i</span><span style=\"mso-font-width: 102%;\">s</span><span style=\"letter-spacing: -0.2pt;\"> </span><span style=\"mso-font-width: 102%;\">a</span><span style=\"letter-spacing: -0.3pt;\"> </span><span style=\"letter-spacing: -0.45pt; mso-font-width: 102%;\">change audit</span><span style=\"letter-spacing: 0.05pt;\"> </span><span style=\"mso-font-width: 102%;\">assessment</span><span style=\"letter-spacing: 0.2pt;\"> </span><span style=\"letter-spacing: -0.15pt; mso-font-width: 102%;\">produc</span><span style=\"letter-spacing: -0.9pt; mso-font-width: 102%;\">t</span><span style=\"letter-spacing: 0.15pt; mso-font-width: 102%;\"> </span><span style=\"letter-spacing: -0.4pt; mso-font-width: 102%;\">th</span><span style=\"mso-font-width: 102%;\">at</span><span style=\"letter-spacing: -0.7pt;\"> </span><span style=\"letter-spacing: -0.2pt; mso-font-width: 102%;\">can</span><span style=\"mso-font-width: 102%;\"> <span style=\"letter-spacing: -0.2pt;\">assure</span> <span style=\"letter-spacing: -0.2pt;\">the</span> <span style=\"letter-spacing: -0.2pt;\">integrity</span> <span style=\"letter-spacing: -0.2pt;\">of critical</span><span style=\"letter-spacing: -0.15pt;\"> </span><span style=\"letter-spacing: -0.2pt;\">data</span><span style=\"letter-spacing: -0.15pt;\"> </span><span style=\"letter-spacing: -0.2pt;\">o</span>n</span><span style=\"letter-spacing: 0.6pt;\"> </span>a wide variety of servers and network devices (e.g., routers, switches, firewalls, and load balancers) called nodes.<span style=\"mso-spacerun: yes;\">&nbsp; </span>It does this<span style=\"letter-spacing: 0.2pt;\"> </span><span style=\"letter-spacing: -0.45pt; mso-font-width: 102%;\">b</span><span style=\"mso-font-width: 102%;\">y</span><span style=\"letter-spacing: -0.2pt;\"> </span><span style=\"letter-spacing: -0.45pt; mso-font-width: 102%;\">gathering</span><span style=\"letter-spacing: -0.35pt;\"> </span>system status, configuration settings, file content, and file metadata<span style=\"letter-spacing: -0.2pt; mso-font-width: 102%;\"> on the nodes and checking gathered node data against previously stored node data to detect </span><span style=\"letter-spacing: -0.25pt; mso-font-width: 102%;\">modifications</span><span style=\"mso-font-width: 102%;\">.<span style=\"mso-spacerun: yes;\">&nbsp; </span></span></span></span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in 6pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times;\">The Tripwire Enterprise consists of a server application component (Tripwire Enterprise Server for Windows 2000, XP Professional, or 2003; Solaris 7, 8, or 9; or, Red Hat Enterprise Linux 3 or 4), a client application component (Tripwire Enterprise Agents for Windows 2000, XP Professional, and 2003; Solaris 8, 9, 10; Red Hat Enterprise Linux 3 and 4; SUSE Enterprise Server 9; HP-UX 11.0, 11i v1, and 11i v2; and, AIX 5.1, 5.2, and 5.3), and a client administrative console application component (Tripwire CLI).<span style=\"mso-spacerun: yes;\">&nbsp; </span>The Tripwire Enterprise Server utilizes the SSL mechanism provided by the JVM in its IT environment to facilitate HTTPS communication with the GUI and the CLI. The product is also bundled with a database application (Firebird Database) to support the product&rsquo;s storage needs.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The Firebird Database is considered part of the IT environment.<span style=\"mso-spacerun: yes;\">&nbsp;&nbsp;&nbsp; </span>While the product supports using the Firebird Database and the Tripwire Enterprise Server (TE Server) on different machines, they must run on the same machine in an evaluated configuration.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The other Tripwire Enterprise components can run on different machines in various combinations.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The Tripwire Enterprise Server is the only product installed and active on the machine in which it is running.</span></span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in 6pt;\"><span style=\"mso-font-width: 102%;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times;\">There are two classes of nodes that the Tripwire Enterprise can monitor, those with built-in external administration interfaces and those without.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Examples of the kind of node with built-in administration interfaces are firewalls, routers, switches, load balancers, etc..<span style=\"mso-spacerun: yes;\">&nbsp; </span>Some of these external interfaces use web servers and allow administration via a remote web browser, and others provide command line interfaces or other custom protocols.<span style=\"mso-spacerun: yes;\">&nbsp;&nbsp; </span>These nodes are referred to as agentless nodes.<span style=\"mso-spacerun: yes;\">&nbsp;&nbsp; </span>Examples of nodes without built-in administration interfaces are Microsoft Windows systems and UNIX systems (Solaris, AIX, HP-UX, etc.)<span style=\"mso-spacerun: yes;\">&nbsp;&nbsp; </span>These nodes are referred to as agent nodes, and host an installation of Tripwire Enterprise Agent.</span></span></span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in 6pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times;\">The Tripwire Enterprise Agent provides an interface for Tripwire Enterprise Server where none otherwise exists or to provide a more fully featured interface than an existing one.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Tripwire Enterprise Agents are installed on nodes that run server-type operating system.<span style=\"mso-spacerun: yes;\">&nbsp; </span></span></span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in 6pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times;\">The Tripwire Enterprise may be used to administer the configuration of the nodes it monitors.<span style=\"mso-spacerun: yes;\">&nbsp; </span>It may also be used to monitor the configuration of its nodes, thereby identifying changes made by users or other applications, such as software-provisioning and patch-management tools that run independently of Tripwire Enterprise. </span></span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in 6pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times;\">The TOE also uses RMI (Remote Method Invocation) over mutually authenticated SSL network connections to protect intra-TOE communication between Tripwire Enterprise Server and the Tripwire Enterprise Agents over an untrusted network.</span></span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in 6pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times;\">The Evaluated Configuration of the Tripwire Enterprise does not include the AAA Monitoring Tool and authentication using external servers.</span></span></p>","evaluation_configuration":null,"security_evaluation_summary":"<p class=\"Body\" style=\"margin: 0in 0in 6pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times;\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The criteria against which the Tripwire Enterprise was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 2.3 and International Interpretations effective on 30, September 2005.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 2.3.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Science Applications International Corporation (SAIC) determined that the evaluation assurance level (EAL) for the product is the EAL 3 (methodically tested and checked)package of assurance requirements augmented with ALC_FLR.2 (flaw reporting procedures).<span style=\"mso-spacerun: yes;\">&nbsp; </span>The product, when configured as specified in the installation guides and user guides, satisfies all of the security functional requirements stated in the Tripwire, Inc. Tripwire Enterprise Security Target.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Validators on behalf of the CCEVS Validation Body monitored the evaluation carried out by SAIC.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The evaluation was completed in February 2009.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report for Tripwire Enterprise v5.2 prepared by CCEVS.</span></span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in 6pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times;\">For this evaluation, it was appropriate for the Security Target to claim compliance with the external standards for MD5 and SHA-1 for the definition of the encryption algorithm. There are many ways of determining compliance with a standard. Tripwire has chosen to make a developer claim of compliance. This means that there has been no independent verification (by either the evaluators or a third party standards body, such as a FIPS laboratory) that the implementation of the cryptographic algorithms actually meets the claimed standards. Potential users of this product should confirm that the cryptographic capabilities are suitable to meet the user's requirements.</span></span></p>","environmental_strengths":"<p class=\"Body\" style=\"margin: 0in 0in 6pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times;\">The Tripwire Enterprise is a commercial IT change audit assessment product that provides change audit assessment, audit, user data protection, security management, authentication and identification, and protection of the security functions features.</span></span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in 6pt 0.5in; text-indent: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in;\"><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: x-small;\">&middot;</span><span style=\"font: 7pt &quot;Times New Roman&quot;;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"font-size: x-small;\"><span style=\"font-family: Times;\"><strong style=\"mso-bidi-font-weight: normal;\">Change Audit Assessment</strong>:<span style=\"mso-spacerun: yes;\">&nbsp; </span>Tripwire Enterprise can monitor files, directories, and registry keys and values by collecting object attribute information of servers and monitor files, command output, and availability of network devices by collecting object attribute information from the devices and compare the information against stored object attribute baselines.<span style=\"mso-spacerun: yes;\">&nbsp; </span></span></span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in 6pt 0.5in; text-indent: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in;\"><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: x-small;\">&middot;</span><span style=\"font: 7pt &quot;Times New Roman&quot;;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"font-size: x-small;\"><span style=\"font-family: Times;\"><strong style=\"mso-bidi-font-weight: normal;\">Security Audit:</strong><span style=\"mso-spacerun: yes;\">&nbsp; </span>Tripwire Enterprise generates audit records containing results of the integrity check of the servers and network devices and management actions that occur on the Tripwire Enterprise. </span></span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in 6pt 0.5in; text-indent: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in;\"><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: x-small;\">&middot;</span><span style=\"font: 7pt &quot;Times New Roman&quot;;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"font-size: x-small;\"><span style=\"font-family: Times;\"><strong style=\"mso-bidi-font-weight: normal;\">User Data Protection</strong>:<span style=\"mso-spacerun: yes;\">&nbsp; </span>Tripwire Enterprise implements a discretionary access control policy for three security objects: user sessions, nodes, and node groups.<span style=\"mso-spacerun: yes;\">&nbsp; </span></span></span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in 6pt 0.5in; text-indent: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in;\"><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: x-small;\">&middot;</span><span style=\"font: 7pt &quot;Times New Roman&quot;;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"font-size: x-small;\"><span style=\"font-family: Times;\"><strong style=\"mso-bidi-font-weight: normal;\">Identification and Authentication:</strong><span style=\"mso-spacerun: yes;\">&nbsp; </span>Tripwire Enterprise requires that all users are identified and authenticated before any access to the Tripwire Enterprise and the Tripwire Enterprise security-relevant data is allowed.</span></span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in 6pt 0.5in; text-indent: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in;\"><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: x-small;\">&middot;</span><span style=\"font: 7pt &quot;Times New Roman&quot;;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"font-size: x-small;\"><span style=\"font-family: Times;\"><strong style=\"mso-bidi-font-weight: normal;\">Security Management:</strong><span style=\"mso-spacerun: yes;\">&nbsp; </span>Tripwire Enterprise provides web-based GUIs used by authorized administrators to manage the Tripwire Enterprise, its functions, and its security-relevant data.</span></span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in 6pt 0.5in; text-indent: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in;\"><span style=\"font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: x-small;\">&middot;</span><span style=\"font: 7pt &quot;Times New Roman&quot;;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"font-size: x-small;\"><span style=\"font-family: Times;\"><strong style=\"mso-bidi-font-weight: normal;\">TSF protection</strong>:<span style=\"mso-spacerun: yes;\">&nbsp; </span>Users of the Tripwire Enterprise can access commands only through one of the two administration interfaces provided.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE enforces Commands issued by a user are processed within the TE Server such that the TOE&rsquo;s enforcement of access control cannot be bypassed.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE invokes the SSL used to protect the communication between the agent and the server.</span></span></p>","features":[]}