{"product_id":10477,"v_id":10477,"product_name":"IBM Proventia GX 4.1 for GX4004, GX5008, GX5108, GX5208, GX6116 with SiteProtector 2.0 SP 8.1","certification_status":"Not Certified","certification_date":"2012-04-26T00:04:00Z","tech_type":"Wireless Monitoring","vendor_id":{"name":"IBM Corporation","website":"https://www.ibm.com"},"vendor_poc":"Scott Sinsel, Project Manager. Federal Certifications","vendor_phone":"404-348-9355","vendor_email":"ssinsel@us.ibm.com","assigned_lab":{"cctl_name":"COACT, Inc. Labs"},"product_description":"<p>The TOE is an automated real-time intrusion detection system (IDS) designed to monitor and protect IPv4 and IPv6 (simultaneously) network segments with Network Intrusion Protection System (NIPS) or passive mode (IDS) functionality.&nbsp; The TOE unobtrusively analyses and responds to activity across computer networks.&nbsp; The TOE is comprised of two components:</p>\r\n<p>The<strong> Proventia </strong><strong>GX Series Appliances</strong> TOE component (hereafter referred to as the appliance(s), GX, GX Series, GX Appliance(s), Sensor, Agent, or as stated) provides IDS security functionality. This component includes the Proventia GX appliance hardware, the appliance resident Red Hat operating system (OS) and the Proventia GX application software image.</p>\r\n<p>The<strong> SiteProtector Version 2.0 Service Pack 8.1 </strong>component of the TOE (hereafter referred to as SiteProtector or as stated) is a software product that runs on a Microsoft Windows-based workstation and enables administrators to monitor and manage the Sensor components of the TOE.&nbsp;</p>\r\n<p>The Proventia GX Series TOE component provides the IDS functionality; it monitors a network or networks and compares incoming packet or packets against known packets and packet patterns that indicate a potential security violation.&nbsp; If a match occurs, the Proventia GX Series will create an audit record.&nbsp; The SiteProtector Version 2.0 Service Pack 8.1 TOE component provides management, monitoring and configuration functions to administrators.&nbsp; The SiteProtector management workstation connects to the appliance via TLS session, and this workstation is only used by authorized administrators for the management of the appliance.&nbsp;</p>\r\n<p>The TOE conforms to the U.S. Government Protection Profile Intrusion Detection System System for Basic Robustness Environments, Version 1.7, July 25, 2007 (IDSPP).</p>","evaluation_configuration":null,"security_evaluation_summary":"<p>The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The evaluation demonstrated that the IBM Internet Security Systems GX Series Security Appliances Version 4.1 and SiteProtector Version 2.0 Service Pack 8.1 meets the security requirements contained in the Security Target.</p>\r\n<p>The criteria against which the IBM Internet Security Systems GX Series Security Appliances Version 4.1 and SiteProtector Version 2.0 Service Pack 8.1 was judged is described in the Common Criteria for Information Technology Security Evaluation, Version 3.1. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1. The COACT, Inc. CAFE Lab determined that the evaluation assurance level (EAL) for the IBM Internet Security Systems GX Series Security Appliances Version 4.1 and SiteProtector Version 2.0 Service Pack 8.1 is EAL 2+. The TOE, configured as specified in the installation guide, satisfies all of the security functional requirements stated in the Security Target.</p>\r\n<p>A Validator on behalf of the CCEVS Validation Body monitored the evaluation carried out by the COACT, Inc. CAFE Lab. The evaluation was completed in February 2012. Results of the evaluation and associated validation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report.</p>","environmental_strengths":"<p>The TOE&rsquo;s Security Functions are:</p>\r\n<p><strong>Security Audit Function - </strong>The TOE provides an audit feature for actions related to operator authentication attempts and administrator actions. Audit data is protected from unauthorized viewing, and viewing can be customized.</p>\r\n<p><strong>Identification and Authentication Function - </strong>The TOE requires operators to be successfully authenticated before any actions can be performed. User accounts must be defined in Windows (in the IT Environment).&nbsp; SiteProtector collects userid and password information through a GUI and passes that information to Windows to authenticate the user.&nbsp; If Windows indicates that the user is authenticated, SiteProtector looks up that userid in its database to determine the permissions associated with the user.&nbsp; If Windows indicates that the user is not authenticated, SiteProtector terminates the session.</p>\r\n<p><strong>Security Management Function</strong> - The TOE provides administrators with the capabilities to configure, monitor and manage the TOE to fulfill the Security Objectives. Security Management principles relate to Security Audit and Traffic Analysis.</p>\r\n<p><strong>Traffic Analysis Function - </strong>The TOE collects information on traffic flowing from TOE ingress points to egress points and analyzes the data against rules defined by an administrator to determine whether the traffic should be allowed or should be dropped.</p>\r\n<p><strong>Protection of Management Function</strong> - The TOE protects the connection between the SiteProtector and appliance TOE components with a TLS tunnel.</p>","features":[]}