{"product_id":10164,"v_id":10164,"product_name":"TeraText DBS 4.3.13","certification_status":"Not Certified","certification_date":"2008-06-20T00:06:00Z","tech_type":"DBMS","vendor_id":{"name":"Science Applications International Corporation (SAIC)","website":"http://www.saic.com/"},"vendor_poc":"Charles Wagner","vendor_phone":"585.442.2642","vendor_email":"charles.h.wagner@saic.com","assigned_lab":{"cctl_name":"CygnaCom Solutions, Inc"},"product_description":"<p>The TOE is a database server application that is for managing records containing text. The TOE is not a relational database system.</p>\r\n<p><br />\r\nThe TOE manages text documents in a variety of formats and encodings including HTML, SGML, XML, RTF, MARC, spreadsheets, word processor documents, plain text, Unicode, and images. It also supports storing images and other non-text formats. For textual data, the TOE provides full text indexing and searching capabilities such as word, field and phrase based querying, fuzzy matching, word stemming, Boolean operators, word distance (proximity) operators, ranking, results sorting, and term highlighting.<br />\r\n&nbsp;</p>","evaluation_configuration":null,"security_evaluation_summary":"<p>The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) processes and procedures. SAIC TeraText DBS 4.3.13 software was evaluated against the criteria contained in the Common Criteria for Information Technology Security Evaluation, Version 2.2. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 2.2. CygnaCom Solutions has determined that the product meets the security criteria in the Security Target, which specifies an assurance level of EAL2. A Validator, on behalf of the CCEVS Validation Body, monitored the evaluation.&nbsp; The evaluation was completed in&nbsp;June 2008.</p>","environmental_strengths":"<p>The TOE provides the following evaluated security services:</p>\r\n<p>&bull;&nbsp;Security audit<br />\r\nThe TOE generates audit records which contain date and time of the event, type of event, subject identity, and the outcome (success or failure) of the event. Note that auditable events are associated with the identity of the user based on user identifier. <br />\r\nThe auditable events include:<br />\r\n&bull;&nbsp;Start-up and shutdown of the audit function (more specifically, of the TOE);<br />\r\n&bull;&nbsp;Successful requests to perform an operation on an object covered by the SFP;<br />\r\n&bull;&nbsp;Unsuccessful use of the authentication mechanism;<br />\r\n&bull;&nbsp;Unsuccessful use of the user identification mechanism, including the user identity provided;<br />\r\nThe TOE writes audit records to text files stored in the IT environment that comprise the audit trail. The operating system in the IT environment is relied on to protect audit trail files and for the time. The TOE does not provide any interfaces to read from the audit trail. <br />\r\n&bull;&nbsp;User data protection<br />\r\nThe TOE can restrict access to Z39.50 databases, records, and schema elements to users and&nbsp; groups based on permissions.&nbsp;</p>\r\n<p>&bull;&nbsp;Identification and authentication<br />\r\nThe TOE ensures users are identified and authenticated prior to allowing them the ability to access the TOE&rsquo;s security functions.&nbsp; Users are identified with a user name and authenticated with a password.&nbsp;&nbsp; Users attributes include: user name, authentication data (password), and group membership. Note that while the product supports additional authentication mechanisms, only username/password is supported in the evaluated configuration</p>\r\n<p>&bull;&nbsp;Security management<br />\r\nThe TOE provides administrator console interfaces that can be used by authorized administrators to perform all management functions, including: managing database subjects (including authentication data), database objects, and TOE session establishment IP addresses.</p>\r\n<p>&bull;&nbsp;Protection of the TSF<br />\r\nThe TOE can ensure that implicit and explicit policies that it enforces are not bypassed by controlling access to its interfaces, including separating client connections between users and the TOE, and between TOE components. The TOE relies on its platform to operate correctly and to prevent unauthorized access to TOE data and stored executables.</p>\r\n<p>&bull;&nbsp;TOE access<br />\r\nThe TeraText Content Server component of the TOE can restrict user sessions based on the IP address of the originating client connection (where client in this context is defined as TOE components and subcomponents that initiate Z39.50 connections with the TeraText Content Server).</p>\r\n<p>&nbsp;</p>","features":[]}