{"product_id":10436,"v_id":10436,"product_name":"Bit9 Parity Version 6.0","certification_status":"Not Certified","certification_date":"2011-02-23T00:02:00Z","tech_type":"System Access Control","vendor_id":{"name":"Bit9, Inc.","website":"www.bit9.com"},"vendor_poc":"Brian Hazzard","vendor_phone":"617-393-7400","vendor_email":"bhazzard@bit9.com","assigned_lab":{"cctl_name":"Booz Allen Hamilton Common Criteria Testing Laboratory"},"product_description":"<p>Bit9, Inc. Parity&trade; Version 6.0.1 is a policy-driven whitelisting solution for restricting the execution of applications and devices that runs on Windows PCs.&nbsp; Whitelisting technology allows end-users to install and run legitimate software and devices while providing IT groups with a way to prohibit anything unauthorized or known to be malicious from executing. The end result is granular control of Windows computers, dramatically improving security, preventing software drift, and managing the flow of information to portable storage devices.</p>\r\n<p>Parity&rsquo;s management capabilities track portable executable (PE) and script files and monitor their prevalence and execution. Unidentified files that have just appeared on the network receive a pending status. A file keeps its pending status until it becomes approved or banned. A pending file also can be acknowledged, which removes it from the list of new pending files but does not change its underlying pending status. Once a file is approved, it is allowed to execute on all systems but continues to be tracked.</p>\r\n<p>After a network is under Parity control, Administrators approve new applications or patches using the approval methods that best suit their organization&rsquo;s software rollout procedures. Parity features several automatic approval methods (trusted directory, trusted publisher, trusted user, and trusted updaters) that make it easy to approve new software without having to do it file-by-file.</p>","evaluation_configuration":"<p>The TOE was evaluated on the following platforms:</p>\r\n<p><strong>Parity Application Server v6.0.1</strong></p>\r\n<p>The items below are to address the recommendations for the differences in Parity Client Loads. Items with a (1) are for less than 300 Parity Clients, items with a (2) are for 300 to 50000 Parity Clients, and items without a number apply to both.</p>\r\n<ul>\r\n<li>Processor</li>\r\n</ul>\r\n<p style=\"padding-left: 60px;\">(1)&nbsp;&nbsp; Dual Core Server Class</p>\r\n<p style=\"padding-left: 60px;\">(2)&nbsp;&nbsp; Dual Core or Dual Processor Server Class</p>\r\n<ul>\r\n<li>Disk space</li>\r\n</ul>\r\n<p style=\"padding-left: 60px;\">(1)&nbsp;&nbsp; 40 GB</p>\r\n<p style=\"padding-left: 60px;\">(2)&nbsp;&nbsp; 2 drives: 40GB for Parity, 72GB for SQL</p>\r\n<ul>\r\n<li>RAM</li>\r\n</ul>\r\n<p style=\"padding-left: 60px;\">(1)&nbsp;&nbsp; 2-4 GB</p>\r\n<p style=\"padding-left: 60px;\">(2)&nbsp;&nbsp; 4 GB</p>\r\n<ul>\r\n<li>Network</li>\r\n</ul>\r\n<p style=\"padding-left: 60px;\">(1)&nbsp; 1 GB NIC</p>\r\n<p style=\"padding-left: 60px;\">(2)&nbsp; &nbsp;1 GB NIC</p>\r\n<ul>\r\n<li>IP address \r\n<ul>\r\n<li>Fixed IP address or (preferably) a fully qualified DNS name. Computers running the Parity Client recognize the server by either its fixed IP address or DNS-name lookup</li>\r\n</ul>\r\n</li>\r\n</ul>\r\n<ul>\r\n<li>Operating System \r\n<ul>\r\n<li>Microsoft Windows Server 2003 - SP2 32-bit, with Microsoft Internet Information Services (IIS) version 6.0, with latest patches.</li>\r\n<li>Microsoft Windows Server 2008 SP2 32-bit or 64-bit, with Microsoft Internet Information Services (IIS) version 7.0, with any patches.</li>\r\n<li>For both Server 2003 and 2008, install .NET 3.5, with latest patches.</li>\r\n</ul>\r\n</li>\r\n</ul>\r\n<ul>\r\n<li>SQL Server \r\n<ul>\r\n<li>SQL Server 2005 Express SP2 for &lt;300 Client computers</li>\r\n<li>SQL Server 2005 SP2 or above Standard/Enterprise OR SQL Server 2008 SP1 or above for &gt;300 Client Computers</li>\r\n</ul>\r\n</li>\r\n</ul>\r\n<p>&nbsp;</p>\r\n<p><strong>Parity Application v6.0.1 Server Virtualization</strong></p>\r\n<p class=\"Default\">To run VMware ESX Server v.4.0+ to create a virtualized environment for Parity:</p>\r\n<ul>\r\n<li>memory meeting the configurations must be allocated as &lsquo;reserved&rsquo; </li>\r\n<li>minimum dual virtual processors are required for all configurations </li>\r\n</ul>\r\n<p>The hardware requirements for the machine hosting the virtual environment should allow the virtual environment to be capable of the same level of performance as a hardware based installation.</p>\r\n<p>&nbsp;</p>\r\n<p><strong>Parity Client v6.0.1</strong></p>\r\n<p>The items below are to address the recommendations for all Parity Clients.</p>\r\n<ul>\r\n<li>Processor \r\n<ul>\r\n<li>Dual Intel Pentium 4 650MHz (or equivalent processor)</li>\r\n</ul>\r\n</li>\r\n</ul>\r\n<ul>\r\n<li>CPU \r\n<ul>\r\n<li>650 MHz </li>\r\n</ul>\r\n</li>\r\n</ul>\r\n<ul>\r\n<li>RAM \r\n<ul>\r\n<li>2-4 Any configuration that enables standard desktop applications to run with good performance, preferably at least 768M.Network</li>\r\n</ul>\r\n</li>\r\n</ul>\r\n<ul>\r\n<li>Disk Space \r\n<ul>\r\n<li>Approximately 65 MB, depending on the number of applications installed on the system</li>\r\n</ul>\r\n</li>\r\n</ul>\r\n<ul>\r\n<li>Operating System </li>\r\n<li>\r\n<ul>\r\n<li>Windows XP 32?bit, SP2 &amp; SP3</li>\r\n<li>Windows 2003 Server 32?bit &amp; 64-bit &amp; R2, SP1 </li>\r\n<li>Windows Vista 32?bit &amp; 64-bit, SP1 &amp; SP2 </li>\r\n<li>Windows 2008 Server 32-bit &amp; 64-bit, Windows 2008 Server R2 64-bit</li>\r\n<li>Windows 7 32-bit &amp; 64-bit</li>\r\n</ul>\r\n</li>\r\n</ul>\r\n<p>Note: The &lsquo;Evaluated Configuration for Bit9 Parity 6.0.1&rsquo; document must be referenced to place the product within the CC evaluated configuration.</p>","security_evaluation_summary":"<p>The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) processes and procedures. Bit9 Parity was evaluated against the criteria contained in the Common Criteria for Information Technology Security Evaluation, Version 3.1 Revision 3. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 Revision 3. It has been determined that the product meets the security criteria in the Security Target, which specifies an assurance level of EAL2 augmented with ALC_FLR.1 and ASE_TSS.2. Validators, on behalf of the CCEVS Validation Body, monitored the evaluation. The evaluation was completed in February 2011.</p>","environmental_strengths":"<p><strong><em>User Data Protection</em></strong></p>\r\n<p>The primary purpose of the TOE is to enforce access control policies against distributed Windows PCs. Subjects who access these PCs are known as Client Users. These access control policies are centrally defined on the Parity Server and distributed to systems in an enterprise. The policies are subsequently enforced by an instance of the Parity Client which resides on each system. The effect of applying these access control policies is known as &ldquo;enterprise whitelisting&rdquo;. Whitelisting marks various specific files, processes, registry values, and removable media devices as authorized to be modified. The specific notion of enterprise whitelisting refers to the fact that individual users and computers in an enterprise can have different policies enforced upon them based on organizationally maintained Active Directory information.</p>\r\n<p>Policies also contain a value called a SecCon, which is short for &ldquo;security condition&rdquo;. The SecCon value of a policy determines what actions to take when an operation is performed on a system which is not whitelisted. For example, under the most restrictive setting, actions which are not whitelisted are forbidden outright. Another setting warns the subject that they are performing an action which has not been approved and gives them an option to proceed or abort using a dialog box.</p>\r\n<p>The Parity Server, which is where policies are defined and distributed, maintains its own role-based access control policy. Subjects which can access the Parity Server are called Console Users and can be assigned one of three specific roles: Administrator, PowerUser, and ReadOnly. Each of these roles confers a fixed set of privileges on the subject. This ensures that only trusted subjects are able to configure the TOE&rsquo;s behavior.</p>\r\n<p><strong><em>Security Management</em></strong></p>\r\n<p>There are four default roles for the TOE:&nbsp; Administrators, PowerUsers, ReadOnly, and Client Users.&nbsp; Administrators, PowerUsers, and ReadOnly are all types of Console Users. The role given to a user determines what operations or management functions they can perform on the TOE.&nbsp; Restrictions can be set on Client Users based on policy; permissions for Console Users are static.</p>\r\n<p>The major security management functions of the TOE are the ability to review audit data and the ability to configure how the client access control policy is enforced. Policy data is propagated to clients and stored internally. The Parity Console, as a web-based application, requires the use of an environmental DNS server if it is to be identified by a qualified domain or host name as opposed to an IP address.</p>\r\n<p><strong><em>Identification and Authentication</em></strong></p>\r\n<p>The TOE supports two types of users: Console Users and Client Users.</p>\r\n<p>Console Users manage the TOE remotely through a Web Browser. They are identified and authenticated with username and password. This authentication data can be maintained within the TSF, or Active Directory integration can be used to allow an existing organizational user to access the TOE using credentials maintained by the Operational Environment. If the Operational Environment is used, username/password validation will be done with LDAP.</p>\r\n<p>Client Users access the TOE indirectly by using their own local machines upon which the Parity Client has been installed. Modifications to their machines are mediated by the TOE, but the TOE is invisible except for pop-up messages when an operation has been blocked. In the evaluated configuration, Client Users are identified by the user account they use to log in to their system, which is derived from Active Directory.</p>\r\n<p><strong><em>Security Audit</em></strong></p>\r\n<p>The TOE collects, aggregates, and reports on IT activity and generates alerts when file/device information changes. &ldquo;IT activity&rdquo; refers the content and behavior of systems that reside in the operational environment. Auditing functions are performed by the TOE by collecting the logs via agents and servers, using a database in the operational environment to store the logs over an established timeframe, and presenting the logs via reports and queries. In addition, the TOE generates audit reports for its own startup and shutdown and all user actions on the TOE.&nbsp; Authorized users are able to select the notification mechanism for all auditable events.&nbsp; The TOE monitors these for events and notifies (alerts) users when a predefined condition is met. Alerts can be sent via email, which requires mediation by an environmental SMTP server. The TOE relies on the host operating system to provide reliable timestamps for audit records.</p>\r\n<p><strong><em>Encrypted Communications</em></strong></p>\r\n<p>Remote users establish a session with the Parity Server using a web-based GUI that is secured via HTTPS. Cryptography for this is provided by the environmental web server and Operating System.&nbsp; This secured path is used for user authentication and management of the TOE by authorized users.&nbsp; The Operational Environment generates cryptographic keys during communication with remote users, the ODBC client, and Active Directory. This is accomplished by the TOE requesting that these environmental components use their native cryptographic facilities. All communications between the Parity Server and Parity Clients and between the Parity Server and the GSR are protected using imported certificates.</p>\r\n<p>The only cryptographic function provided by the TSF is the ability to hash files for the purpose of access control checking.</p>\r\n<p>The cryptography used in this product has not been FIPS-certified, nor has it been analyzed or tested to conform to cryptographic standards during this evaluation. All cryptography has only been asserted as tested by the vendor.</p>\r\n<p><strong><em>TOE Access</em></strong></p>\r\n<p>Before a session begins, a warning will be displayed alerting the Console User that unauthorized access to the TOE is prohibited.</p>","features":[]}