{"product_id":10441,"v_id":10441,"product_name":"AirTight Networks SpectraGuard Enterprise, Version 6.5","certification_status":"Not Certified","certification_date":"2012-06-11T00:00:00Z","tech_type":"Wireless LAN, Wireless Monitoring","vendor_id":{"name":"AirTight Networks, Inc.","website":"http://www.airtightnetworks.com"},"vendor_poc":"Hemant Chaskar","vendor_phone":"650-996-3410","vendor_email":"hemant.chaskar@airtightnetworks.com","assigned_lab":{"cctl_name":"CygnaCom Solutions, Inc"},"product_description":"<p>The Target of Evaluation (TOE) is wireless intrusion prevention system (WIPS). It consists of SpectraGuard Enterprise Server component (also referred as &ldquo;Server&rdquo;), SpectraGuard Enterprise Management Console component (also referred as &ldquo;Console&rdquo;), and SpectraGuard Enterprise Sensor component (also referred as &ldquo;Sensor&rdquo;).</p>\r\n<p>&nbsp;</p>\r\n<p>The Sensors are geographically dispersed to provide full radio coverage of the enterprise premises to be protected against unauthorized wireless activity. These premises typically include enterprise wired local area network that may or may not have managed WiFi extension (managed WiFi access points (APs)) of its own. The Sensors are connected to the Ethernet ports of the wired local area network within the premises to provide full coverage of the local area network subnets. The Sensor application software version 6.5 is embedded in the SpectraGuard Enterprise Sensor appliance SS-300-AT-C-10. The Sensors can be operated with external antennas or with internal antennas. The SS-300-AT-C-10 Sensor with software version 6.2 is FIPS 140-2 Level 2 certified (Certificate #1609). Vendor asserts that there is no change in cryptographic modules in the Sensor from version 6.2 to version 6.5.&nbsp;</p>\r\n<p>&nbsp;</p>\r\n<p>The Sensor appliance SS-300-AT-C-10 also includes following third party software to support the Sensor application:</p>\r\n<ul>\r\n<li>Linux      version 2.6.15 operating system. This      is basic Linux kernel and not any specific distribution such as Redhat,      CentOS, etc.</li>\r\n<li>OpenSSL      library version 1.2 to perform cryptography functions</li>\r\n<li>Dropbear      SSH version 0.52 to support secure remote login access to the Sensor for      troubleshooting</li>\r\n</ul>\r\n<p>&nbsp;</p>\r\n<p>The Server is also connected to the local area network. The Server application software version 6.5 is embedded in the SpectraGuard Enterprise Server appliance SA-350. The Server application SE-SW-VM version 6.5 can also be run on VMware ESX, ESXi and vSphere &nbsp;virtual machines version 4.0 and above. The Server application is FIPS 140-2 Level 1 certified (Certificate #1649).</p>\r\n<p>The Server appliance SA-350 and the VMware software SE-SW-VM also include following third party software to support the Server application:</p>\r\n<ul>\r\n<li>Linux      operating system: Centos version 5.2 with kernel version 2.6.18-92</li>\r\n<li>OpenSSL      library version 1.2 to perform cryptography functions</li>\r\n<li>OpenSSH      version 5.3p1 to support secure remote login access to the Server for      troubleshooting</li>\r\n<li>Tomcat      web server version 6.0.14</li>\r\n<li>PostgreSQL      database version 8.1.11</li>\r\n<li>SNMP      client: NET-SNMP version 5.4.2.1</li>\r\n<li>Syslog      client: syslogd version 1.4.1</li>\r\n<li>Email      client: libESMTP version 1.0.4</li>\r\n<li>LDAP      client: OpenLDAP client version      2.4.21</li>\r\n<li>RADIUS      client: FreeRADIUS C library version 1.1.6 and Java library TinyRadius      version 1.0</li>\r\n</ul>\r\n<p>&nbsp;</p>\r\n<p>The Console provide graphical user interface (GUI) into the TOE for management of security functions. It runs as Java applet in Internet Explorer web browser on Microsoft Windows machine. There is no need to install any software to run the Console. The Console applet is received from the Server when the Server is accessed from within web browser and is removed from the browser when the web browser is closed.</p>\r\n<p>&nbsp;</p>\r\n<p>The following third party software is required to support the Console:</p>\r\n<ul>\r\n<li>Microsoft      Windows 2000, Windows XP, or Windows 7 OS</li>\r\n</ul>\r\n<ul>\r\n<li>Internet      Explorer (IE) web browser version 5.5 or higher </li>\r\n<li>Java      Runtime Environment (JRE) version 1.6u13 or higher</li>\r\n<li>Text      editor which understands TSV (tab separated values) file format, for      example, Microsoft Excel, WordPad, Notepad etc.</li>\r\n<li>Card      reader software if optional certificate based authentication is used. </li>\r\n</ul>\r\n<p>&nbsp;</p>\r\n<p>The Sensors scan WiFi radio channels to collect wireless activity information in their vicinity and report this information to the Server. They also scan traffic on the local area network subnets to which they are connected through the Ethernet ports and report the scanned information to the Server. The Server performs analysis of the information reported by Sensors to identify and respond to unauthorized WiFi activity. The Server notifies events related to the unauthorized WiFi activity to administrator, generates compliance reports (DoD, SOX, GLBA, PCI, HIPAA, MITS etc.), and triggers countermeasures to block (prevent) the unauthorized wireless activity.</p>\r\n<p>&nbsp;</p>\r\n<p>To accomplish its function, the TOE operates in &ldquo;overlay&rdquo; fashion, i.e., Sensors are not inline the wireless connections or the wired connections. Rather, they rely on broadcast nature of the wireless medium to collect wireless scan data. They also rely on broadcast subset of traffic in the wired network to collect wire-side scan data.</p>\r\n<p>&nbsp;</p>\r\n<p>The TOE does not provide any traffic forwarding functionality between the wired and wireless media (like the WiFi APs do).</p>","evaluation_configuration":"<p>The evaluated configuration includes the following:</p>\r\n<ul>\r\n<li>SpectraGuard Enterprise      Server version 6.5</li>\r\n<li>SpectraGuard Enterprise      Management Console version 6.5</li>\r\n<li>SpectraGuard Enterprise      Sensor version 6.5</li>\r\n</ul>\r\n<p>&nbsp;</p>\r\n<p>The Test Configuration will consist of SpectraGuard Enterprise Server appliance SA-350 including Server software version 6.5 and SpectraGuard Enterprise Sensor appliance SS-300-AT-C-10 including Sensor software version 6.5. The SpectraGuard Enterprise Management Console will be accessed using Internet Explorer (IE) version 9.0 using JRE version 1.6u30 on Windows 7 computer.&nbsp;</p>\r\n<p>&nbsp;</p>\r\n<p>Another Test Configuration will consist of SpectraGuard Enterprise Server software SE-SW-VM version 6.5 running on VMware ESXi version 4.0 and SpectraGuard Enterprise Sensor appliance SS-300-AT-C-10 including Sensor software version 6.5. It suffices to test one virtual machine environment, as others are equivalent and interoperable with it. The SpectraGuard Enterprise Management Console will be accessed using Internet Explorer (IE) version 9.0 using JRE version 1.6u30 on Windows 7 computer.</p>\r\n<p><em>&nbsp;</em></p>\r\n<p>The Sensor appliance SS-300-AT-C-10 includes two WiFi radio modules. Any of these radio modules can be tuned via software to monitor any WiFi channel. In the SS-300-AT-C-10 Sensor appliance, the first radio module is tuned to rotate on one subset of WiFi channels (in 2.4 GHz band) and the second radio module is tuned to rotate on the other subset of WiFi channels (in 5 GHz band).</p>","security_evaluation_summary":"<p>The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) processes and procedures. The TOE was evaluated against the criteria contained in the Common Criteria for Information Technology Security Evaluation, Version 3.1 R3.</p>\r\n<p>&nbsp;</p>\r\n<p>The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 R2.</p>\r\n<p>&nbsp;</p>\r\n<p>CygnaCom Solutions has determined that the product meets the security criteria in the Security Target, which specifies an assurance level of Evaluation Assurance Level (EAL) 2 augmented with ALC_FLR.2.</p>\r\n<p>&nbsp;</p>\r\n<p>A team of validators, on behalf of the CCEVS Validation Body, monitored the evaluation. The evaluation was completed in May 2012.</p>","environmental_strengths":"<p>The following security functions are in the scope of the evaluation:</p>\r\n<p>&nbsp;</p>\r\n<h4>Security Audit</h4>\r\n<p>The TOE is able to audit the use of the administration/management functions. This function records attempts to access the system itself, such as successful and failed authentication, as well as the actions taken by TOE users once they are authenticated.</p>\r\n<p>&nbsp;</p>\r\n<p>The audit data is protected by the access control mechanisms of the database and OS of the TOE components and by the TOE management Console interface. Only Superuser has access to the audit records. The Superuser can download the audit records for viewing. At the time of downloading, sorting and filtering criteria can be specified for the audit records.</p>\r\n<p>&nbsp;</p>\r\n<p>The audit records are stored in the TOE for configurable number of days. Once any record becomes older than the configured lifetime, it is automatically deleted. The TOE does not place any limit on the size of the audit trail, the only limit comes from the size of the disk. When the occupied disk size approaches the capacity, the TOE generates early warning.&nbsp;</p>\r\n<p>&nbsp;</p>\r\n<p>Security Audit relies on the Operational Environment with a properly configured text editor (such as Microsoft Excel, WordPad etc.) application to support viewing of the downloaded audit logs. It also depends on the Operational Environment to provide secure communication path between the TOE Server and management Console.</p>\r\n<h4>Cryptographic Support</h4>\r\n<p>The TOE performs cryptographic functions for: a) Sensor-Server communication, b) Console-Server communication, c) SSH utility in Sensor and Server. The Sensor-Server communication protocol is proprietary and uses FIPS 140-2 approved algorithms for key generation, encryption and message integrity. The Console-Server communication follows TLS version 1.0 standard and the SSH utility follows SSH version 2 standard. The TOE supports FIPS and non-FIPS operation modes.</p>\r\n<p>&nbsp;</p>\r\n<h4>Identification and Authentication</h4>\r\n<p>The TOE requires all users to provide unique identification and authentication data before any access to the system is granted. User identification and authentication is done by the TOE though username/password authentication, optionally using an external authentication server. The TOE also supports client certificate-based authentication option, such as CAC authentication. For certificate-based authentication, TOE supports optional two-factor authentication with password in addition to client certificate.</p>\r\n<p>&nbsp;</p>\r\n<p>All authorized TOE users must have a user account with security attributes that control the user&rsquo;s access to TSF data and management functions. These security attributes include user name, password, role and location node identity for TOE users.</p>\r\n<p>&nbsp;</p>\r\n<p>The TOE enforces a password policy for users who authenticate via the TOE. The TOE will also prevent a user from accessing the system after a configurable number of failed login attempts.</p>\r\n<p>&nbsp;</p>\r\n<p>Identification and Authentication depends on the Operational Environment to provide an external authentication server if that feature is configured. It also depends on the Operational Environment to provide a secure communications path between the TOE and the external authentication server.</p>\r\n<h4>Security Management</h4>\r\n<p>The TOE provides a web-based (using HTTPS) management interface for all run-time TOE administration. The ability to manage various security attributes, system parameters and all TSF data is controlled and limited to those users who have been assigned the appropriate administrative role.</p>\r\n<p>&nbsp;</p>\r\n<p>Security Management relies on a management console in the Operational Environment with a properly configured Web Browser to support the web-based management interfaces.</p>\r\n<h4>TOE Access</h4>\r\n<p>The TOE will terminate a user&rsquo;s interactive session after a configurable inactivity time. Before establishing a user session, the will display an advisory warning message regarding unauthorized use of the TOE.</p>\r\n<h4>Protection of Security Functions</h4>\r\n<p>The TOE ensures that data transmitted between separate parts of the TOE are protected from disclosure or modification. This protection is ensured through strong encryption during both setup and the transition of data. The TOE Server is FIPS 140-2 Level 1 certified and the TOE Sensor is FIPS 140-2 Level 2 certified.</p>\r\n<h4>System Data Collection</h4>\r\n<p>The TOE detects WiFi threats and vulnerabilities. For this, it collects information from IEEE 802.11 protocol transmission frames detected on WiFi radio channels and IEEE 802.3 protocol traffic detected in the wired part (Ethernet) of the monitored network subnets. Sensors collect the above-mentioned data and send it to the Server.</p>\r\n<h4>System Data Analysis</h4>\r\n<p>The TOE performs various types of analyses such as signatures, anomaly, wired/wireless traffic correlation and devices configuration check, on the collected data to detect wireless threats and vulnerabilities. When threats/vulnerabilities are detected, the TOE generates alarms and (if optionally configured to do so) sends alarms by email, SNMP, syslog etc. to external servers in the operational environment.</p>\r\n<h4>System Data Review, Availability and Loss</h4>\r\n<p>TOE stores user action logs and events data in the database that is included in the TOE. User action logs can be downloaded by authorized administrator from Console as TSV (tab separated values) format file. Events are displayed in tabular form on Console. The user action logs and events are automatically deleted after administrator configured lifetime expires for them. Events are also automatically deleted when total number of events exceeds the administrator configured thresholds. When auto deletion happens, the most recent logs and events are always maintained. The TOE also proactively notifies the administrator via event if the disc occupancy reaches unsafe limits so that administrator can take appropriate action (e.g., backup) to free up the disc space. TOE also facilitates automatic periodic backup of database.</p>","features":[]}