{"product_id":10333,"v_id":10333,"product_name":"LogLogic v4.6.1 Open Log Management Platform","certification_status":"Not Certified","certification_date":"2009-07-09T00:07:00Z","tech_type":"Wireless Monitoring","vendor_id":{"name":"LogLogic, Inc.","website":"http://www.loglogic.com"},"vendor_poc":"Chima Njaka","vendor_phone":"888.347.3883","vendor_email":"chima@loglogic.com","assigned_lab":{"cctl_name":"Arca CCTL"},"product_description":"<p class=\"MsoBodyText\" style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-size: 10.0pt;\"><span style=\"font-size: x-small;\">The TOE is the LogLogic v4.6.1 Open Log Management Platform on the LX and ST families of appliances.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE is compliant with the Intrusion Detection System (IDS) Analyzer protection profile and provides administrative alerts, flexible reporting, and searching on the analyzed data and long term storage of unaltered event logs.</span></span></p>\r\n<p class=\"MsoBodyText\" style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-size: 10.0pt;\"><span style=\"font-size: x-small;\">Log data is collected by the TOE from networked third-party sources such as firewalls, VPN concentrators, servers, routers and switches, storage devices, and applications (commercial and custom developed).<span style=\"mso-spacerun: yes;\">&nbsp; </span>When administrator-defined alerts are triggered, the TOE sends alert notifications to the administrative interface or to other servers via SNMP, SMTP or syslog.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The Analyzer data is stored in a database for viewing, searching, and reporting, and in raw unaltered form on the file system for searching and long-term storage.<span style=\"mso-spacerun: yes;\">&nbsp; </span></span></span></p>\r\n<p class=\"MsoBodyText\" style=\"margin: 0in 0in 6pt;\"><a name=\"_Toc481500866\"></a><a name=\"_Toc472746148\"></a><a name=\"_Toc449772300\"><span style=\"mso-bookmark: _Toc472746148;\"><span style=\"mso-bookmark: _Toc481500866;\"><span style=\"font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-size: 10.0pt;\"><span style=\"font-size: x-small;\">The </span></span></span></span></a><span style=\"font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-size: 10.0pt;\"><span style=\"font-size: x-small;\">LogLogic v4.6.1 TOE is composed of two families of physically distinct components.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The LX series of appliances normalizes event log data, stores it in a database, and provides analysis, alerting, and reporting through metalog creation.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The LX appliance provides searching and flexible reporting via built-in customizable report templates.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The ST series of appliances archives unaltered logs for long-term retention.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The LX and ST appliances communicate with each other over an encrypted and mutually authenticated TCP tunnel providing for the secure transfer of logs or archiving.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Adding additional appliances scales the solution as the monitored network and log data volume grow.<span style=\"mso-spacerun: yes;\">&nbsp; </span></span></span></p>\r\n<p class=\"MsoBodyText\" style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-size: 10.0pt;\"><span style=\"font-size: x-small;\"><span style=\"mso-spacerun: yes;\">&nbsp; </span></span></span></p>\r\n<p class=\"MsoBodyText\" style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-size: 10.0pt;\"><span style=\"font-size: x-small;\">The full list of excluded functionality is provided in the Security Target as well as in the Validation Report.</span></span></p>","evaluation_configuration":"<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"font-size: 10pt;\"><span style=\"font-family: Times New Roman;\">The following conditions must be met for the TOE to be deployed in the evaluated configuration:</span></span></p>\r\n<ol style=\"margin-top: 0in;\" type=\"1\">\r\n<li class=\"MsoNormal\" style=\"margin: 0in 0in 6pt; mso-list: l0 level1 lfo1; tab-stops: list .5in;\"><span style=\"font-size: 10pt;\"><span style=\"font-family: Times New Roman;\">At least one LogLogic LX Appliance (There can be more than one LX deployed in the evaluated configuration) and </span></span></li>\r\n<li class=\"MsoNormal\" style=\"margin: 0in 0in 6pt; mso-list: l0 level1 lfo1; tab-stops: list .5in;\"><span style=\"font-size: 10pt;\"><span style=\"font-family: Times New Roman;\">At least one LogLogic ST Appliance (There can be more than one ST deployed in the evaluated configuration.) </span></span></li>\r\n<li class=\"MsoNormal\" style=\"margin: 0in 0in 6pt; mso-list: l0 level1 lfo1; tab-stops: list .5in;\"><span style=\"font-size: 10pt;\"><span style=\"font-family: Times New Roman;\">When configured to support HA, the TOE consists of a minimum of three network appliances such that at least one ST or LX is part of a HA pair, and the models of the HA pair must have at least 3 network interfaces. </span></span></li>\r\n</ol>","security_evaluation_summary":"<p class=\"MsoBodyText\" style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-size: 10.0pt;\"><span style=\"font-size: x-small;\">The evaluation of the LogLogic v4.6.1 Open Log Management Platform was performed by the Arca Common Criteria Testing Laboratory (CCTL) in the United States and was completed during May 2009.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The evaluation team determined the product conforms to Common Criteria Version 3.1 Revision 2, Part 2 extended and Part 3 conformant, and meets the requirements for Evaluation Assurance Level (EAL) 2 augmented with ALC_FLR.2. </span></span></p>\r\n<p class=\"MsoBodyText\" style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-size: 10.0pt;\"><span style=\"font-size: x-small;\">For this evaluation, it was appropriate for the Security Target to claim compliance with the external standard for RSA, AES, TDES, and Blowfish for the definition of the encryption algorithm. There are many ways of determining compliance with a standard. <span style=\"mso-spacerun: yes;\">&nbsp;</span>LogLogic v4.6.1 Open Log Management platform has chosen to make a developer claim of compliance. This means that there has been no independent verification (by either the evaluators or a third party standards body, such as a FIPS laboratory) that the implementation of the cryptographic algorithms actually meets the claimed standards. Potential users of this product should confirm that the cryptographic capabilities are suitable to meet the user's requirements.</span></span></p>","environmental_strengths":"<p class=\"MsoBodyText\" style=\"margin: 0in 0in 6pt;\"><span style=\"font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-size: 10.0pt;\"><span style=\"font-size: x-small;\">The LogLogic v4.6.1 Open Log Management Platform is a commercial product that analyzes event logs for network anomalies or security policy breaches and provides Traffic Flow Control (for network traffic sent to the appliances, traffic does not pass through the appliances), Secure Communications (secure communication channels for remote administration, and inter-appliance communication), and High Availability function as well as more standard functions of Auditing, Identification and Authentication, Security Management, and Self-Protection.<span style=\"mso-spacerun: yes;\">&nbsp; </span>To securely provide these functions, the deployed LogLogic appliances must be appropriately protected from physical attacks. </span></span></p>","features":[]}