{"product_id":10132,"v_id":10132,"product_name":"NitroSecurity Intrusion Prevention System v7.1.3","certification_status":"Not Certified","certification_date":"2007-06-11T00:06:00Z","tech_type":"Wireless Monitoring","vendor_id":{"name":"NitroSecurity, Inc.","website":"http://www.nitrosecurity.com"},"vendor_poc":"John Cummings","vendor_phone":"703.505.0075","vendor_email":"jcummings@nitrosecurity.com","assigned_lab":{"cctl_name":"Leidos Common Criteria Testing Laboratory"},"product_description":"<p>The NitroSecurity Intrusion Prevention System <span style=\"font-family: \" times=\"\" new=\"\">TOE is an intrusion detection and prevention system that can detect network intrusion attempts and react by actively recording and/or blocking such attempts. </span><span style=\"mso-bidi-font-size: 9.0pt\">The TOE can pass, drop, and log packets as they arrive, based on administrator-configurable rules. </span><span style=\"font-family: \" times=\"\" new=\"\">When the TOE is performing intrusion detection, it is said to be operating in an &ldquo;IDS mode&rdquo;. When the TOE is performing intrusion prevention, it is said to be operating in an &ldquo;IPS&rdquo; mode. </span><span style=\"mso-bidi-font-size: 9.0pt\"><o:p></o:p></span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in 6pt; text-align: left\" align=\"left\">The TOE is composed of two hardware appliance components, the NitroSecurity IPS (also known as &ldquo;NitroSecurity Intrusion Protection System&rdquo;, or &ldquo;IPS&rdquo;) and the NitroSecurity ESM (also known as &ldquo;NitroView ESM&rdquo;, &ldquo;ESM&rdquo;, or &ldquo;Enterprise Security Manager&rdquo;). <o:p></o:p></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in 6pt; text-align: left\" align=\"left\">The NitroSecurity IPS provides network intrusion detection and prevention services for an enterprise type network.<span style=\"mso-spacerun: yes\">&nbsp; </span>The ESM provides web-based administrator console interfaces that can be used to manage NitroSecurity IPS services and collected data that are accessible using a web browser in the IT Environment.<span style=\"mso-spacerun: yes\">&nbsp; </span>HTTPS is used to protect the connection between the web browser in the IT Environment and the ESM appliance. The ESM offers HTTP v1.0 and v1.1 using SSL v2.0 and v3.0 or TLS v1.0 to web browsers. It is up to the web browser to request a particular combination of HTTP and SSL/TLS versions.<o:p></o:p></p>","evaluation_configuration":null,"security_evaluation_summary":"<p>The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The criteria against which the NitroSecurity TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 2.3 and International Interpretations effective on 12 October, 2005.<span style=\"mso-spacerun: yes\">&nbsp; </span>The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 2.3 Science Applications International Corporation (SAIC) determined that the evaluation assurance level (EAL) for the product is EAL 3 family of assurance requirements.<span style=\"mso-spacerun: yes\">&nbsp; </span>The product, when configured as specified in the installation guides and user guides, satisfies all of the security functional requirements stated in the Nitro Security Intrusion Prevention System Version 7.1.3 Security Target.<span style=\"mso-spacerun: yes\">&nbsp; </span>The evaluation was completed in April 2007.<span style=\"mso-spacerun: yes\">&nbsp; </span>Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report for Nitro Security Intrusion Prevention System Version 7.1.3 prepared by CCEVS.<o:p></o:p></p>","environmental_strengths":"<p>The NitroSecurity Intrusion Prevention System TOE is a commercial intrusion and anomaly detection product that provides intrusion and anomaly detection identification and authentication, audit, protection of security functions and security management.<o:p></o:p></p>","features":[]}