{"product_id":10302,"v_id":10302,"product_name":"Top Layer Networks IPS 5500 E Version 5.21 on Models IPS 5500-150E, IPS 5500-500E, and IPS 5500-1000E","certification_status":"Not Certified","certification_date":"2009-04-10T00:04:00Z","tech_type":"Wireless Monitoring","vendor_id":{"name":"Corero Network Security (formerly Top Layer Networks, Inc.)","website":"www.corero.com"},"vendor_poc":"Marty Meyer","vendor_phone":"+1 978-212-1559","vendor_email":"marty@corero.com","assigned_lab":{"cctl_name":"CygnaCom Solutions, Inc"},"product_description":"<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-layout-grid-align: none;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\"><span style=\"mso-bidi-font-size: 12.0pt;\">The Top Layer IPS 5500 E is a </span><span style=\"mso-bidi-font-size: 12.0pt; mso-fareast-font-family: 'MS Mincho'; mso-fareast-language: JA;\">single-appliance security gateway </span><span style=\"mso-bidi-font-size: 12.0pt;\">Intrusion Protection System. </span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-layout-grid-align: none;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\"><span style=\"mso-bidi-font-size: 12.0pt;\">The IPS Unit provides </span><span style=\"mso-bidi-font-size: 12.0pt; mso-fareast-font-family: 'MS Mincho'; mso-fareast-language: JA;\">network-level and application-level protection to a network from good, bad and suspicious traffic. </span><span style=\"mso-bidi-font-size: 12.0pt;\">The TOE acts as an inline single-appliance security gateway providing <span style=\"mso-bidi-font-weight: bold;\">three-dimensional </span>protection to stop resource abuse, prohibit access to unauthorized clients and stop malicious content from entering the protected network. Top Layer&rsquo;s ASIC technology and algorithms integrate stateful analysis techniques with deep packet inspection and DoS (Denial of Service) attack protection to provide protection from Internet-based and internal threats. The difference between the TOE and a typical IDS is that the TOE (IPS Unit) is deployed <span style=\"mso-bidi-font-style: italic;\">inline and not in an</span> offline or a passive mode. </span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-layout-grid-align: none;\"><span style=\"color: black; mso-bidi-font-size: 12.0pt;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">&nbsp;</span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-layout-grid-align: none;\"><span style=\"color: black; mso-bidi-font-size: 12.0pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">The TOE may be configured to:</span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt 1in; text-indent: -0.25in; mso-layout-grid-align: none; mso-list: l0 level1 lfo1; tab-stops: list 1.0in;\"><span style=\"color: black; font-family: &quot;Courier New&quot;; mso-bidi-font-size: 12.0pt; mso-fareast-font-family: 'Courier New';\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: x-small;\">&shy;</span><span style=\"font: 7pt &quot;Times New Roman&quot;;\">&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"mso-bidi-font-size: 12.0pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">Handle IP fragments, TCP header and Payload.<span style=\"color: black;\"></span></span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt 1in; text-indent: -0.25in; mso-layout-grid-align: none; mso-list: l0 level1 lfo1; tab-stops: list 1.0in;\"><span style=\"font-family: &quot;Courier New&quot;; mso-bidi-font-size: 12.0pt; mso-fareast-font-family: 'Courier New';\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: x-small;\">&shy;</span><span style=\"font: 7pt &quot;Times New Roman&quot;;\">&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"mso-bidi-font-size: 12.0pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">Implement firewall rules.</span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt 1in; text-indent: -0.25in; mso-layout-grid-align: none; mso-list: l0 level1 lfo1; tab-stops: list 1.0in;\"><span style=\"font-family: &quot;Courier New&quot;; mso-bidi-font-size: 12.0pt; mso-fareast-font-family: 'Courier New';\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: x-small;\">&shy;</span><span style=\"font: 7pt &quot;Times New Roman&quot;;\">&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"mso-bidi-font-size: 12.0pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">Perform protocol analysis.</span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt 1in; text-indent: -0.25in; mso-layout-grid-align: none; mso-list: l0 level1 lfo1; tab-stops: list 1.0in;\"><span style=\"font-family: &quot;Courier New&quot;; mso-bidi-font-size: 12.0pt; mso-fareast-font-family: 'Courier New';\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: x-small;\">&shy;</span><span style=\"font: 7pt &quot;Times New Roman&quot;;\">&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"mso-bidi-font-size: 12.0pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">Perform deep packet inspections.</span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt 1in; text-indent: -0.25in; mso-layout-grid-align: none; mso-list: l0 level1 lfo1; tab-stops: list 1.0in;\"><span style=\"font-family: &quot;Courier New&quot;; mso-bidi-font-size: 12.0pt; mso-fareast-font-family: 'Courier New';\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: x-small;\">&shy;</span><span style=\"font: 7pt &quot;Times New Roman&quot;;\">&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"mso-bidi-font-size: 12.0pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">Handle network and security management.</span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt 1in; text-indent: -0.25in; mso-layout-grid-align: none; mso-list: l0 level1 lfo1; tab-stops: list 1.0in;\"><span style=\"font-family: &quot;Courier New&quot;; mso-bidi-font-size: 12.0pt; mso-fareast-font-family: 'Courier New';\"><span style=\"mso-list: Ignore;\"><span style=\"font-size: x-small;\">&shy;</span><span style=\"font: 7pt &quot;Times New Roman&quot;;\">&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"mso-bidi-font-size: 12.0pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">Process events, logging, and reports.</span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-layout-grid-align: none;\"><span style=\"mso-bidi-font-size: 12.0pt;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">&nbsp;</span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-layout-grid-align: none;\"><span style=\"mso-bidi-font-size: 12.0pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">The primary design goal of the TOE is reliable protection of customer&rsquo;s critical on-line assets. The IPS aspect of the TOE security policy may be configured based on the following three types of rules. The rules guide the following types of security checks:</span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-layout-grid-align: none;\"><strong><span style=\"mso-bidi-font-size: 12.0pt;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">&nbsp;</span></span></strong></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-layout-grid-align: none;\"><strong><span style=\"mso-bidi-font-size: 12.0pt;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">Firewall Rules &mdash; </span></span></strong><span style=\"mso-bidi-font-size: 12.0pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">Provide classic firewall blocking for traffic, based on IP addresses,<span style=\"mso-spacerun: yes;\">&nbsp; </span><br /><span style=\"mso-spacerun: yes;\">&nbsp;&nbsp; </span><span style=\"mso-spacerun: yes;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span style=\"mso-tab-count: 1;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Layer 4 ports, and segments (port pairs).</span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-layout-grid-align: none;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\"><strong><span style=\"mso-bidi-font-size: 12.0pt;\">IPS</span></strong><strong><span style=\"mso-bidi-font-size: 12.0pt;\"> Rules &mdash; </span></strong><span style=\"mso-bidi-font-size: 12.0pt;\">Provide the following types of checks:</span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt 1in; mso-layout-grid-align: none;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\"><strong><span style=\"mso-bidi-font-size: 12.0pt;\">&bull; </span></strong><span style=\"mso-bidi-font-size: 12.0pt;\">Protocol validation</span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt 1in; mso-layout-grid-align: none;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\"><strong><span style=\"mso-bidi-font-size: 12.0pt;\">&bull; </span></strong><span style=\"mso-bidi-font-size: 12.0pt;\">Attack Signatures</span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt 1in; mso-layout-grid-align: none;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\"><strong><span style=\"mso-bidi-font-size: 12.0pt;\">&bull; </span></strong><span style=\"mso-bidi-font-size: 12.0pt;\">Acceptable use of network applications</span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-layout-grid-align: none;\"><strong><span style=\"mso-bidi-font-size: 12.0pt;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">Rate Based Rules &mdash; </span></span></strong><span style=\"mso-bidi-font-size: 12.0pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">Protect customer&rsquo;s resources from overuse by legitimate users, as well as <br /><span style=\"mso-spacerun: yes;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>abusive denial-of-service attackers. Provide limits for:</span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt 1in; mso-layout-grid-align: none;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\"><strong><span style=\"mso-bidi-font-size: 12.0pt;\">&bull; </span></strong><span style=\"mso-bidi-font-size: 12.0pt;\">Client requests</span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt 1in; mso-layout-grid-align: none;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\"><strong><span style=\"mso-bidi-font-size: 12.0pt;\">&bull; </span></strong><span style=\"mso-bidi-font-size: 12.0pt;\">Connections for both clients and servers</span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt 1in; mso-layout-grid-align: none;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\"><strong><span style=\"mso-bidi-font-size: 12.0pt;\">&bull; </span></strong><span style=\"mso-bidi-font-size: 12.0pt;\">SYN Flood controls</span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt 1in; mso-layout-grid-align: none;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\"><strong><span style=\"mso-bidi-font-size: 12.0pt;\">&bull; </span></strong><span style=\"mso-bidi-font-size: 12.0pt;\">Application rate limiting</span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">&nbsp;</span></p>","evaluation_configuration":null,"security_evaluation_summary":"<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) processes and procedures.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Top Layer Networks IPS 5500 E Version 5.21 on Models IPS 5500-150E, IPS 5500-500E, and IPS 5500-1000E were evaluated against the criteria contained in the Common Criteria for Information Technology Security Evaluation, Version 2.3. The evaluation methodology used by the evaluation team to conduct the evaluation was the Common Methodology for Information Technology Security Evaluation, Version 2.3. CygnaCom Solutions has determined that the product meets the security criteria in the Security Target, which specifies an assurance level of EAL4. The evaluation was completed in February 2009. </span></span></p>","environmental_strengths":"<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">The following security functions are in the scope of the evaluation:</span></span></p>\r\n<h2 style=\"margin: 12pt 0in 3pt;\"><a name=\"_Toc220835730\"></a><a name=\"_Toc185651527\"><span style=\"mso-bookmark: _Toc220835730;\"><span style=\"font-size: 10pt; font-style: normal; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-style: italic;\">Security Audit</span></span></a><span style=\"font-size: 10pt; font-style: normal; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-style: italic;\"> </span></h2>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-layout-grid-align: none;\"><span style=\"mso-bidi-font-size: 12.0pt; mso-fareast-font-family: 'MS Mincho'; mso-fareast-language: KO;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">During the process of receiving and transmitting traffic, the TOE performs many checks and other operations. Some of these operations, system events and user-related management interface tasks, produce event messages. The IPS Unit contains a message managing system that makes these messages available to administrators based on the message controls established. These messages are collected as audit records in Alert logs and Event Log files. The TOE may also be configured to send messages to remote Syslog and SNMP servers. Only human users with authorized administrator or monitor privileges have the capability to view the audit data stored on the TOE.</span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-layout-grid-align: none;\"><span style=\"mso-bidi-font-size: 12.0pt; mso-fareast-font-family: 'MS Mincho'; mso-fareast-language: KO;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">&nbsp;</span></span></p>\r\n<h2 style=\"margin: 12pt 0in 3pt;\"><a name=\"_Toc220835731\"></a><a name=\"_Toc185651528\"><span style=\"mso-bookmark: _Toc220835731;\"><span style=\"font-size: 10pt; font-style: normal; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-style: italic;\">User </span></span></a><span style=\"mso-bookmark: _Toc220835731;\"><span style=\"mso-bookmark: _Toc185651528;\"><span style=\"font-size: 10pt; font-style: normal; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-style: italic;\">Data</span></span></span><span style=\"mso-bookmark: _Toc220835731;\"><span style=\"mso-bookmark: _Toc185651528;\"><span style=\"font-size: 10pt; font-style: normal; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-style: italic;\"> Protection</span></span></span><span style=\"font-size: 10pt; font-style: normal; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-style: italic;\"></span></h2>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-layout-grid-align: none;\"><span style=\"mso-bidi-font-size: 12.0pt; mso-fareast-font-family: 'MS Mincho'; mso-fareast-language: KO;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">The TOE performs user data protection through the rate based security policy, the firewall filtering security policy and the intrusion prevention security policy. The TOE identifies external IT entities and remote administrator systems by their presumed IP addresses. Only legitimate external IT entities are granted access to pass information through the TOE and only authorized administrator systems are granted access to pass information <span style=\"mso-spacerun: yes;\">&nbsp;</span>to the TOE.</span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-layout-grid-align: none;\"><span style=\"mso-bidi-font-size: 12.0pt; mso-fareast-font-family: 'MS Mincho'; mso-fareast-language: KO;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">&nbsp;</span></span></p>\r\n<h2 style=\"margin: 12pt 0in 3pt;\"><a name=\"_Toc220835732\"></a><a name=\"_Toc185651529\"><span style=\"mso-bookmark: _Toc220835732;\"><span style=\"font-size: 10pt; font-style: normal; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-style: italic;\">Identification </span></span></a><span style=\"mso-bookmark: _Toc220835732;\"><span style=\"mso-bookmark: _Toc185651529;\"><span style=\"font-size: 10pt; font-style: normal; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-style: italic;\">and</span></span></span><span style=\"mso-bookmark: _Toc220835732;\"><span style=\"mso-bookmark: _Toc185651529;\"><span style=\"font-size: 10pt; font-style: normal; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-style: italic;\"> Authentication</span></span></span><span style=\"font-size: 10pt; font-style: normal; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-style: italic;\"></span></h2>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-layout-grid-align: none;\"><span style=\"mso-bidi-font-size: 12.0pt; mso-fareast-font-family: 'MS Mincho'; mso-fareast-language: KO;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">The TOE provides a password based authentication mechanism to administrators and monitors. </span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-layout-grid-align: none;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\"><span style=\"mso-bidi-font-size: 12.0pt; mso-fareast-font-family: 'MS Mincho'; mso-fareast-language: KO;\">The TOE communicates with the remote web browser </span>of the administrator using the HTTPS protocol in order to encrypt the user id and password authentication data and all configuration information to maintain secrecy from an attacker<span style=\"mso-bidi-font-size: 12.0pt;\">. IT Entities are identified by their presumed IP addresses. Access to security functions and data is prohibited until a user is identified and authenticated.</span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-layout-grid-align: none;\"><span style=\"mso-bidi-font-size: 12.0pt; mso-fareast-font-family: 'MS Mincho'; mso-fareast-language: KO;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">&nbsp;</span></span></p>\r\n<h2 style=\"margin: 12pt 0in 3pt;\"><a name=\"_Toc220835733\"></a><a name=\"_Toc185651530\"><span style=\"mso-bookmark: _Toc220835733;\"><span style=\"font-size: 10pt; font-style: normal; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-style: italic;\">Security Management</span></span></a><span style=\"font-size: 10pt; font-style: normal; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-style: italic;\"></span></h2>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-layout-grid-align: none;\"><span style=\"mso-bidi-font-size: 12.0pt; mso-fareast-language: KO;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">The TOE maintains administrator and monitor user management roles.</span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-layout-grid-align: none;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\"><span style=\"mso-bidi-font-size: 12.0pt; mso-fareast-language: KO;\">The TOE allows only</span><span style=\"mso-fareast-language: KO;\"> authorized users with appropriate privileges </span><span style=\"mso-bidi-font-size: 12.0pt; mso-fareast-language: KO;\">to administer</span><span style=\"mso-fareast-language: KO;\"> and manage the TOE.</span><span style=\"mso-bidi-font-size: 12.0pt; mso-fareast-language: KO;\"> </span><span style=\"mso-fareast-language: KO;\">An administrative user can connect </span><span style=\"mso-bidi-font-size: 12.0pt; mso-fareast-language: KO;\">through an encrypted web interface using SSL for secrecy. Only authorized administrators may </span><span style=\"mso-fareast-language: KO;\">modify</span><span style=\"mso-bidi-font-size: 12.0pt; mso-fareast-language: KO;\"> the TSF, data related to the TSF, security attributes, and authentication data.</span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-layout-grid-align: none;\"><span style=\"mso-bidi-font-size: 12.0pt; mso-fareast-font-family: 'MS Mincho'; mso-fareast-language: KO;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">&nbsp;</span></span></p>\r\n<h2 style=\"margin: 12pt 0in 3pt;\"><a name=\"_Toc220835734\"></a><a name=\"_Toc185651531\"><span style=\"mso-bookmark: _Toc220835734;\"><span style=\"font-size: 10pt; font-style: normal; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-style: italic;\">Protection of TOE Security Functions</span></span></a><span style=\"font-size: 10pt; font-style: normal; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-style: italic;\"></span></h2>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-layout-grid-align: none;\"><span style=\"mso-bidi-font-size: 12.0pt; mso-fareast-font-family: 'MS Mincho'; mso-fareast-language: KO;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">The TOE transfers all packets arriving at the interfaces of the TOE only after processing based on the traffic attributes. </span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-layout-grid-align: none;\"><span style=\"mso-bidi-font-size: 12.0pt; mso-fareast-font-family: 'MS Mincho'; mso-fareast-language: KO;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">The TOE restricts management access to its interfaces through the use of physically separate management interfaces, and further by requiring users to log into the TOE using its GUI. HTTPS is used to protect the connection between the web browser in the IT Environment and the appliance. The TOE relies on Top Layer appliance hardware in general to ensure the TSP is enforced and to provide for domain separation. The TOE hardware appliance includes its own hardware clock, which provides reliable time stamps for use in audit and collected data records.</span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-layout-grid-align: none;\"><span style=\"mso-bidi-font-size: 12.0pt; mso-fareast-font-family: 'MS Mincho'; mso-fareast-language: KO;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">&nbsp;</span></span></p>\r\n<h2 style=\"margin: 12pt 0in 3pt;\"><a name=\"_Toc220835735\"></a><a name=\"_Toc185651532\"><span style=\"mso-bookmark: _Toc220835735;\"><span style=\"font-size: 10pt; font-style: normal; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-style: italic;\">Trusted </span></span></a><span style=\"mso-bookmark: _Toc220835735;\"><span style=\"mso-bookmark: _Toc185651532;\"><span style=\"font-size: 10pt; font-style: normal; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-style: italic;\">Path</span></span></span><span style=\"mso-bookmark: _Toc220835735;\"><span style=\"mso-bookmark: _Toc185651532;\"><span style=\"font-size: 10pt; font-style: normal; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-style: italic;\"> /Channel</span></span></span><span style=\"font-size: 10pt; font-style: normal; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-style: italic;\">s </span></h2>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; mso-layout-grid-align: none;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">The TOE, in conjunction with the IT environment, protects the TSF data from unauthorized disclosure or modification of TSF data when it is being transmitted between the IPS Unit and the management GUI on the remote management station.<span style=\"mso-spacerun: yes;\">&nbsp; </span></span></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">&nbsp;</span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 6pt;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">&nbsp;</span></p>","features":[]}